Okta troubleshooting
Setup and permissions
Verify that single sign-on is configured and you are signed in as a super admin. Re-enter your Okta domain and try again.
Confirm the Glean Connector app has the okta.users.read scope and the Read-only Administrator role assigned.
These fields may require custom field mapping. Configure the appropriate Okta profile attribute mappings in the Glean admin console.
Verify the Glean Connector app has the okta.apps.read scope granted. App crawls run daily by default.
Verify that the Glean Connector app has:
okta.groups.readscope- Native groups enabled
- Completed an identity crawl
The role picker includes native OktaGroup_* groups. Legacy App_* pseudo-groups and other Okta group types are not included.
Crawling and freshness
Okta rate limits vary by plan. Glean retries automatically with backoff. If persistent, contact Glean Support to adjust crawl batch sizes.
User crawls run every 3 hours by default. Check the crawl status in the Glean admin console to confirm crawls are completing successfully. For crawl schedules and restrictions, see Crawl.