Avigilon - Okta user syncing – Incident details


Find real-time updates and track historical changes to the status of key systems across the Avigilon Unity and Alta portfolios here, or subscribe for tailored notifications by portfolio to always stay up to date on the latest changes. To report an issue with your system, please contact support here.


All systems operational

Okta user syncing

Resolved
Degraded performance
Started 24 days agoLasted about 13 hours

Affected

Avigilon Alta Access (Formerly Openpath)

Degraded performance from 11:20 PM to 12:02 AM, Operational from 12:02 AM to 11:53 AM

Alta Access (Openpath) Control Center - US

Degraded performance from 11:20 PM to 12:02 AM, Operational from 12:02 AM to 11:53 AM

Alta Access (Openpath) Control Center - Rest of World

Degraded performance from 11:20 PM to 12:02 AM, Operational from 12:02 AM to 11:53 AM

Updates
  • Postmortem
    UTC
    Postmortem

    A newly released field-mapping feature introduced a step that reorganized the user records returned by the Okta API. In directories where an Okta user record contains two fields that share the same short name at different levels of the record, that step could not distinguish them and selected the wrong one. As a result, each user's unique identifier was replaced with a value that is identical for every user.

    Because every user then carried the same identifier, the sync could not match users to their existing accounts. Directory Sync marks any user it cannot account for as inactive; therefore, it deactivated the affected users.

    The defect only manifests against a specific Okta record structure that not all Okta configurations return. That structure was absent from our test environment. This combination made the root cause unusually difficult to trace and took the most time to diagnose during the incident. The affected record structure is valid and correct on the customer side; the defect was entirely in how our feature handled it.

  • Resolved
    UTC
    Resolved
    This incident has been resolved.
  • Monitoring
    UTC
    Monitoring

    We implemented a fix and are currently monitoring the result.
    Users will neither to either manually sync the idp or wait for the 15/60 minute auto synch in order to see the issue resolved.

  • Investigating
    UTC
    Investigating

    Some okta users may be temporarily disabled within their organization
    We are currently investigating this incident.