The intended audience for this article is Agents
When Directory Sync is configured, Wunderite provides a table to show any issues detected. When an issue is detected, the administrator will be notified and an indicator on the Directory Sync Health table will show that the Directory Sync needs attention. The table displays issues, the affected groups, how to resolve the issue, and the action to be taken. Once an issue is resolved, it will no longer display on the table.
View Directory Sync Health
To view the Directory Sync Health table, complete the following steps:
Log in to Wunderite as an Administrator.
In the side navigation, click
Team.In the menu that appears, click
Team Security.Scroll down to
Directory Sync Health.
Resolve Directory Sync Issues
The following list details common issues that appear on the Directory Sync Health table and how to resolve them:
Identity provider deleted segments: This error means that an identity provider group which mapped to a segment in Wunderite was removed from the identity provider. To resolve the issue, the corresponding segment should be removed from Wunderite, or the deleted group in the identity provider should be restored.
Identity provider deleted the default segment: This error means that the group in the identity provider that mapped to the default segment in Wunderite has been removed from the identity provider. To resolve the issue, the default group in the identity provider must be restored because the default segment cannot be deleted in Wunderite.
Users cannot access Wunderite because segments are disabled: This error occurs when segments are disabled in Wunderite, but users have been added to segment-based groups in the identity provider. To resolve this issue, either remove the affected users from the groups in the identity provider or contact Wunderite Customer Success to enable Wunderite segments.
SSO email conflict: This error occurs when an email address being provisioned or updated is already in use by a Wunderite user outside the teams linked to your SSO organization. Please contact Wunderite Customer Success to resolve the email conflict.
Running a Manual Sync Between the Identity Provider and WorkOS
Syncs automatically occur as data or configurations change, but if required, a sync can also be triggered manually from the identity provider. See the following instructions for manually triggering a sync from some commonly used identity providers.
Okta
To manually sync groups:
Log in to Okta.
Navigate to
Applicationsin the left-hand menu.From the dropdown menu, select
Applications.Select the app used to connect to WorkOS for Wunderite.
From the tab navigation, select
Push Groups.Select a group that has data to update and click
Active.From the dropdown menu, select
Push now.
To manually sync users:
Log in to Okta.
Navigate to
Dashboardin the lefthand menu.Select
Tasks.Retry any user push related tasks as listed.
Entra
To manually trigger a sync in Entra, use the Provision on Demand capabilities as outlined in Provisioning on Demand.

