<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5KZ000010TEdL0AWOkta Classic EngineDirectoriesAnswered2025-06-30T16:06:20.000Z2025-06-25T12:28:32.000Z2025-06-30T16:06:20.000Z

BoxA.14415 (Customer) asked a question.

User's not fully updating via scheduled Active Directory Sync

We have found in the past 1-2 years that we have to manually do a full sync to keep our users up to date as far as being disabled or having applications removed. Our scheduled sync is set to run each hour and works for some users, but when we run a full sync each day we have 10-20 users that get disabled. If we wait for a few months we see over 2,000 users get removed after a full import. We see no errors or logs showing that the partial sync is not working (as it does create new users and has disabled some users).

I'm hoping that the feature request to trigger a full import via API (which has been accepted and is apparently on the roadmap) comes out soon, but nonetheless it seems like the AD agents or the partial import doesn't work anymore.

Any suggestions from anyone? Its more of an annoyance right now having to login and trigger a full import, but it is just one more thing that we manually have to do to get our one application up to date in Okta.


This question is closed.
Loading
User's not fully updating via scheduled Active Directory Sync