Expand my Community achievements bar.

SOLVED

LDAP user node sync limit

Avatar

Level 5

Please share if any sync issue / limitation on number of users that can be synced from LDAP into AEM ,  profile sync possibly for personalization 

Alternatively also thinking about loading custom client context querying the LDAP after OOTB authentication without any user sync to restrict large number user node creation and later LDAP sync up / stale issues

Possible end user profiles more than 10K end user & their attributes

From my POV , not syncing the profile and loading custom client context would be a better option , Please share your thoughts?

1 Accepted Solution

Avatar

Correct answer by
Level 10

I do not believe there is information that talks about user limit in the AEM docs:

https://docs.adobe.com/docs/en/aem/6-0/administer/security/ldap-config.html

If you think there is missing information, please open a ticket against these AEM LDAP docs. 

View solution in original post

5 Replies

Avatar

Level 10

It depends on what is the purpose of Users which we are syncing. If we are using it for authentication, then syncing would be better !

Avatar

Level 10

From talking with AEM people - there is no limit in OAK (AEM 6.x) with LDAP users. 

Avatar

Level 5

Additionally 

In case of OOTB LDAP authentication , the actual authentication happens against the LDAP and not against AEM even if profiles are cached in AEM via sync

Assuming the OOTB AEM- LDAP takes care of users getting blocked in LDAP and hence blocked into site as auauthentication happens with LDAP every time not the AEM profile cache which is synced earler

And this profile sync is for personalization using LDAP OU possibly  , 

Do we have any reference count in the public docs to validate this syncing might not be issue even for use base more that 5K or 10K

Avatar

Correct answer by
Level 10

I do not believe there is information that talks about user limit in the AEM docs:

https://docs.adobe.com/docs/en/aem/6-0/administer/security/ldap-config.html

If you think there is missing information, please open a ticket against these AEM LDAP docs. 

Avatar

Level 5

Thanks Mac - Also have additional request - which I have dropped a separate message