LDAP synchronization never completes - Too many users added to cache
Platform notice: Server and Data Center only. This article only applies to Atlassian products on the Server and Data Center platforms.
Support for Server* products ended on February 15th 2024. If you are running a Server product, you can visit the Atlassian Server end of support announcement to review your migration options.
*Except Fisheye and Crucible
Problem
LDAP appears to synchronize without end. In Administration > User Directories
, it can be seen that more users are being added to the LDAP cache than anticipated.
For example, an instance that anticipates 400 users:
Synchronising for 1655s…
Last synchronised at 2/23/16 10:53 AM (took 2s).
Adding 34,556 users to the cache.
Cause
This will happen when only the base DN information is provided and filter settings are too broad or the default settings have not been modified.
Resolution
Ensure that user and group DN settings are configured so filtering narrows down how many users are synced/added to cache.
For reference, use these resources that discuss creating LDAP filters:
Restricting LDAP Scope for User and Group Search
How to write LDAP search filters