You should be aware of the limitations to Directory Integration that affect the Directory Services Connector. These limitations apply to both the push method used here as well as the pull method used in the Control Console.
- You must run separate synchronizations for each Active Directory domain
- You cannot synchronize more than 65,000 addresses at one time
- For manual synchronization, you are limited to 35,000 addresses in the user interface, and 65,000 addresses when downloading and reviewing the results in a file
- You cannot limit the number of synchronization changes
- The Control Console limits group membership to 25,000. Group synchronizations fail if an Active Directory group contains more than 25,000 users.
- You cannot run a synchronization that includes only the addresses that have changed
- You must use Active Directory
- Directory Services Connector does not run on ePolicy Orchestrator version 4.6.0 and requires version 4.6.1 through 5.0.