LDAP integration known limitations

The following table lists the known limitations with Okta LDAPLightweight Directory Access Protocol (LDAP) is a lightweight client-server protocol for accessing directory services, specifically X.500-based directory services. LDAP runs over TCP/IP or other connection oriented transfer services. integrations.

Feature Comments
Supported Directories

The Okta LDAP agentA software agent is a lightweight program that runs as a service outside of Okta. It is typically installed behind a firewall and allows Okta to tunnel communication between an on-premises service and Okta's cloud service. Okta employs several agent types: Active Directory, LDAP, RADIUS, RSA, Active Directory Password Sync, and IWA. For example, users can install multiple Active Directory agents to ensure that the integration is robust and highly available across geographic locations. is supported with all LDAP v3 servers (RFC 4510 compliant). It has been tested with the following:

  • Object Lifecycle Management
  • Group Management
  • Password Management

Notable features not supported by the LDAP Agent:

Note: The Okta LDAP agent is not recommended for large LDAP migrations.


The following operations are supported on all LDAP directories:

  • Full Import
  • User provisioning

The following operations are only supported on specified directories:

  • Incremental Imports
  • Set Password
  • Change Password
  • The LDAP agent automatically detects user schema based on the user objectClass specified
  • Supports structural classes, auxiliary classes for users