You can configure high availability for directory sync by associating the directory with multiple Directory Sync service instances and then setting up a Sync Services list for the directory. The Directory Sync service instances in the Sync Services list are arranged in failover order. The Workspace ONE Access service uses the first Directory Sync service in the list to sync users and groups for the directory. If the first Directory Sync service is unavailable, it uses the next one in the list, and so on.
Each directory has its own Sync Services list.
As a best practice, set up your deployment in a way that the same Directory Sync service instance does not sync multiple directories at the same time. You can use the following strategies.
- Use a different set of Directory Sync service instances for different directories.
- If you use the same set of Directory Sync service instances in the same failover order, schedule the sync at different times for each directory.
- If you use the same set of Directory Sync service instances for multiple directories, set a different failover order for each directory so that sync does not fall back to the same instance.
Prerequisites
- You have installed and configured additional Directory Sync service instances. See Installing Workspace ONE Access Connector for information.
Procedure
Results
The list of Directory Sync service instances is saved and is applied from the next sync onwards.
You can view which Directory Sync service instances were used for each sync run in the Sync Log tab of the directory page.