<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008s4PdICAUOkta Classic EngineAuthenticationAnswered2023-09-01T17:04:13.000Z2023-02-28T14:29:19.000Z2023-03-02T17:18:13.000Z

AntoineV.11237 (Customer) asked a question.

Identity Engine DSSO Slow compared to classic engine

Hello,

Anyone migrated from classic enfin to identity engine and suffer from slowness in the DSSO authentication flow?

Like we have:

  • A prod classic engine tenant
  • A preview identity engine tenant

Both are in EMEA.

A user that connects to the same app from Singapore or Tokyo connect in around 5 seconds on classic engine.

It's at least twice longer connecting with the identity engine preview tenant.

For EMEA users it's less visible, but still slower.

It's the same account, same laptop, same app, same routing to okta, same everything... except the Okta tenant.

I wonder if preview env performance is really shitty or if's it's related to the Okta authentication flow change (more redirections, more api calls...)

Thanks,

Antoine


  • Hi Antoine,

     

    Thank you for your insight. You are correct that there is a different flow for ADSSO in OIE vs. Classic. Previously, Okta would authenticate and perform a profile update as one action. In OIE, Okta splits this into two actions. The ADSSO authentication occurs first, followed by a RealTimeSync to compare/update the user profile. 

     

    You also may be experiencing differences if your Orgs are configured with different or multiple domains. Please ensure that each region has at least one DC and one member server with the Okta AD Agent installed.

     

    Take care,

     

    Michael Hyde

    Okta Support

    Expand Post
This question is closed.
Loading
Identity Engine DSSO Slow compared to classic engine