Customers migrating from on-premise Active Directory (AD) to cloud-based identity providers may seek to use the Okta LDAP interface as the external user store for Embedded Entitlements Manager (EEM).
This article outlines the supportability and technical requirements for this configuration.
Question: Is the Okta LDAP interface a supported configuration for a backend directory provider in Embedded Entitlements Manager (EEM)?
The Okta LDAP interface is not part of the formally certified compatibility matrix for EEM.
However, because the interface is LDAPv3-compliant and supports LDAPS, integration is possible. Implementing this configuration requires addressing the following technical constraints:
LDAP_SIZELIMIT_EXCEEDED. [email protected],ou=users,dc=company,dc=okta,dc=com). memberOf attribute).Alternative Recommendation:
For a fully supported and certified configuration, use a standard LDAP server such as Active Directory Lightweight Directory Services (AD LDS).
Okta Lifecycle Management can be configured to provision users and groups to the AD LDS instance, which EEM can then utilize as a standard LDAP user store without the constraints of the Okta LDAP interface.
For issues confirmed as product limitations, please refer to the enhancement request process.
To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on the respective region.