
AntoineV.11237 (Customer) asked a question.
Hello,
Anyone migrated from classic enfin to identity engine and suffer from slowness in the DSSO authentication flow?
Like we have:
- A prod classic engine tenant
- A preview identity engine tenant
Both are in EMEA.
A user that connects to the same app from Singapore or Tokyo connect in around 5 seconds on classic engine.
It's at least twice longer connecting with the identity engine preview tenant.
For EMEA users it's less visible, but still slower.
It's the same account, same laptop, same app, same routing to okta, same everything... except the Okta tenant.
I wonder if preview env performance is really shitty or if's it's related to the Okta authentication flow change (more redirections, more api calls...)
Thanks,
Antoine

Hi Antoine,
Thank you for your insight. You are correct that there is a different flow for ADSSO in OIE vs. Classic. Previously, Okta would authenticate and perform a profile update as one action. In OIE, Okta splits this into two actions. The ADSSO authentication occurs first, followed by a RealTimeSync to compare/update the user profile.
You also may be experiencing differences if your Orgs are configured with different or multiple domains. Please ensure that each region has at least one DC and one member server with the Okta AD Agent installed.
Take care,
Michael Hyde
Okta Support