
ze1z9 (ze1z9) asked a question.
Hi,
I've added several OUs to our AD and now would like to have Okta to import those so I can choose to snychronize them. Unfortunately It neither happen within an hour after I created them (synchronize is set to hourly) nor by restarting the AD Agent nor by running a Full Import of the Directory. Is there a trick to see the new OUs?
Regards
Bernd

I have to be honest here - the AD import process is one of the most frustrating issues I have with our Okta environment. I haven't encountered this exact scenario myself, but I often have both delta and full imports fail to pull in newly-created user accounts and groups, and it can be very frustrating at times (the amount of time it takes seems to be directly inverse to how quickly I need it to be imported). I really wish I had the ability to perform an on-demand import of a specific object AND point that task at a specific domain controller.
Imports from Active Directory can be impacted by the complexity of your environment. Consider how many domain controllers you have, how many sites (AD sites), which domain controller you were connected to when you created the new object versus which one the Okta AD agent is connected to during an import, and the AD replication delays between all of those things. By default, Active Directory replication within an AD site boundary is 5 minutes, and site-to-site is 15 minutes.
Sometimes it also seems like Okta enforces a minimum window between imports. I often retry an import when one fails to pull in an object I'm waiting for, and often I get the hated "0 Users. 0 Groups" response WAY too quickly. After several years, I've learned to expect these things and try my best to be patient. The back-end processes have greatly improved in the last four years, so I'm hopeful that they'll keep improving.