Skip to main content

Step 4: Review and Approve Your Initial Directory Sync

Understand how identity provider groups will map to Wunderite Segments before starting your first sync

Written by Philip MacDonald

The intended audience for this article is Technical Agent Admins with SSO.

Before your first Directory Sync, you must generate and approve a preview. The preview compares groups in your identity provider with segments in Wunderite without making changes.

After approval, your identity provider becomes the source of truth for users and segments. Users missing from your identity provider may be locked in Wunderite. Users removed from segments may lose assignments, and segments without a corresponding identity-provider group will be queued for deletion.

Generate and review a preview

  1. Open Team Security and select Generate Sync Preview.

  2. Wait while Wunderite retrieves the latest data from your identity provider. Preview generation may take several minutes for large directories.

  3. Review the identity-provider groups, Wunderite segments, user counts, and expected results.

  4. If anything looks incorrect, make the necessary changes in your identity provider and select Generate New Preview.

The new preview replaces the previous results. No changes are made in Wunderite until you approve and start the sync.

Understand the preview results

During the initial sync, groups and segments must have exactly matching names. Differences in spelling, spacing, or punctuation may cause Wunderite to treat them as separate records.

  • Default Segment required: The Wunderite Default Segment has no exact match in your identity provider. Create a group whose name exactly matches the Default Segment, then generate a new preview. This issue blocks approval.

  • Marked for deletion: A Wunderite segment has no exact match in your identity provider. Approving the sync will remove its users and queue the segment for deletion. To keep it, create a group with the exact same name in your identity provider.

  • Will be created: A group in your identity provider has no exact match in Wunderite. Approving the sync will create a new segment with the same name. If the group should match an existing segment, update its name in your identity provider.

  • Will be renamed: A group in your identity provider is already connected to a Wunderite segment, but their names differ. Approving the sync will rename the segment to match the group.

  • Will be synced: A group in your identity provider matches an existing Wunderite segment and will sync automatically.

Review user counts

The preview shows total users in your identity provider and Wunderite. It also displays a user count beneath each group and segment. Individual users and email differences are not shown.

Different counts indicate that users may be added to or removed from a segment. Review unexpected differences carefully because users who lose segment access may also lose associated assignments.

Approve and start the sync

When the preview has no blocking issues, its status changes to Ready to Approve & Sync. Select Approve & Sync to begin synchronizing users and segments.

If your identity provider data changed after the preview was generated, Wunderite will require a new preview before approval. When the Directory Sync finishes, active team administrators will receive an email.

Troubleshoot preview generation

  • Generating: Wunderite is still preparing the preview.

  • Interrupted: The preview did not arrive within the expected time. Select Generate New Preview to try again.

  • Failed: Wunderite encountered an error while generating the preview. Confirm your Directory Sync configuration and try again.

Did this answer your question?