Okta LDAP interface supportability for Embedded Entitlements Manager (EEM)
search cancel

Okta LDAP interface supportability for Embedded Entitlements Manager (EEM)

book

Article ID: 450057

calendar_today

Updated On:

Products

Autosys Workload Automation

Issue/Introduction

Customers migrating from on-premise Active Directory (AD) to cloud-based identity providers may seek to use the Okta LDAP interface as the external user store for Embedded Entitlements Manager (EEM).
This article outlines the supportability and technical requirements for this configuration.

Question: Is the Okta LDAP interface a supported configuration for a backend directory provider in Embedded Entitlements Manager (EEM)?

Environment

  • AutoSys 12.x /24.x

  • Embedded Entitlements Manager (EEM) 12.x
  • Okta LDAP Interface

Resolution

The Okta LDAP interface is not part of the formally certified compatibility matrix for EEM.
However, because the interface is LDAPv3-compliant and supports LDAPS, integration is possible. Implementing this configuration requires addressing the following technical constraints:

  • Paging Limits: Okta enforces a strict limit of 1,000 entries per page. If a request exceeds this without pagination, it returns LDAP_SIZELIMIT_EXCEEDED.
    The page size in EEM’s LDAP configuration must be set to 1,000 or lower.
  • Rate Throttling: Okta restricts service accounts to 4 BIND requests per second. EEM can generate a high volume of logical BIND requests during peak hours, which may lead to login timeouts if the threshold is exceeded.
  • Schema Mapping: Okta utilizes unique Distinguished Name (DN) structures (e.g., [email protected],ou=users,dc=company,dc=okta,dc=com).
    EEM must be configured using the "Custom Mapped Directory" feature to map these attributes and recognize group memberships (specifically the memberOf attribute).
  • Multi-Factor Authentication (MFA): EEM cannot handle interactive MFA prompts.
    The EEM service account must be exempted from MFA policies in Okta to allow simple password BINDs.

Alternative Recommendation: 
For a fully supported and certified configuration, use a standard LDAP server such as Active Directory Lightweight Directory Services (AD LDS).
Okta Lifecycle Management can be configured to provision users and groups to the AD LDS instance, which EEM can then utilize as a standard LDAP user store without the constraints of the Okta LDAP interface.

Additional Information

For issues confirmed as product limitations, please refer to the enhancement request process.

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on the respective region.