<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y000063uEXaSAMOkta Classic EngineAdministrationAnswered2024-04-15T11:49:21.000Z2019-03-18T23:59:14.000Z2019-03-19T00:17:46.000Z

4lkjg (4lkjg) asked a question.

ldap groups not scanning

I can't seem to import ldap groups ... When I do an import I get - "I have 0 groups scanned!" even though I am the proud owner of ldap groups. Any thoughts as to what the issue could be?


  • VanH.30758 (Lytx, Inc.)

    So there's a few things to confirm:

    1) You will want to confirm that the groups you're modifying are set to synchronize through the Import. There's a chance that the groups are in an OU that does not synchronize.

     

    2) Could it just be a delayed import due to AD replication? We have 3 AD connectors in our environment. One of them in one of our satellite offices where the replication time varies quite a bit (can take upwards of 15-20 minutes). We had a recent issue that lasted for a good week (that appeared to resolve itself) where after a call to OKTA support, they pointed out that if you go to one of the servers that host your AD agent and go to the following default install path: C:\Program Files (x86)\Okta\Okta AD Agent\logs, you can see entries of which DC it's pinging for changes. While the call helped us single out that OKTA was only checking the DC in the satellite office (with the delay), we couldn't tell why. The temporary fix for us was to just make all our changes on that DC instead. The entry you want to look for contains the following, IIRC: "Sending query to search root: LDAP".

     

    Hopefully this info helps.

    Expand Post

Loading
ldap groups not scanning