Limits and Best Practices
- Secure Access supports provisioning a maximum of 1000 groups from Okta. Any groups beyond this number that are in scope are not provisioned. Secure Access does not restrict the number of users that you can provision from Okta. For more information, see Limitations and Range Limits.
- To ensure that all users are provisioned, assign the Everyone group to the Cisco User Management Connector app. You can push other additional groups for group-based Secure Access rule enforcement.
- Okta does not support nested groups.
- If you previously imported groups from the on-premises AD and push the same groups from Okta, the groups from Okta do not overwrite the groups imported from the on-premises AD. You must reassign any group-based Secure Access policy rules to the groups imported from Okta.
- Provisioning large numbers of users and groups to Secure Access may take several hours.
- After the initial provisioning of users and groups, it can take up to one hour for subsequent changes to users and groups to reflect in Secure Access.
- Concurrent synchronization of the same users and groups from the on-premises AD and the Cisco User Management Connector app is not supported and leads to inconsistent policy enforcement.
- For IP-to-user mapping deployments, you must use an on-premises AD Connector. Okta does not store the private IP to AD user mappings.