Active Directory sync stalls when adding multiple OUs in HexnodeSolved

Participant
Discussion
3 weeks ago Sep 04, 2026

We’re expanding an iPhone rollout and ran into a strange AD sync issue. One IDP-synced user seemed to disappear from the device/user assignment, and the device showed limited actions until I temporarily changed the owner.

The user later showed back up under Manage > Users around the same time an Active Directory sync finally completed. Earlier, I had added multiple OUs at once, and the sync stayed stuck as “In progress.” After removing one of the OUs, the sync completed.

We still have several OUs to add. Is there a limit on the number of OUs, users, or groups Hexnode can sync from Active Directory? Also, what’s the best way to troubleshoot this when each sync change has to wait for the next interval?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Sep 04, 2026
Marked SolutionPending Review

Hi @sybylla,

There is no fixed limit on the number of users, groups, or OUs that can be synced into Hexnode from Active Directory.

When an AD sync remains stuck in progress after adding multiple OUs, it is usually related to one of the following:

  • A large directory payload being processed in a single sync cycle.
  • An object in one of the selected OUs that cannot be resolved properly.
  • A specific OU causing the connector sync process to stall or time out.

Since the user reappeared under Manage > Users once the sync completed, the user assignment issue was most likely caused by the incomplete AD sync rather than the iPhone itself. Changing the device owner can clear the immediate assignment error, but the underlying fix is to get the directory sync completed successfully.

Recommended approach:

  1. Add one OU at a time instead of adding several OUs together.
  2. Wait for the current sync cycle to complete.
  3. Check the sync status under Admin > Active Directory.
  4. Confirm that the expected users appear under Manage > Users.
  5. If a specific OU causes the sync to remain in progress, review the AD connector service log at <strong>C:\HexnodeMDM_AD\logs\service.log</strong> to identify whether the stall is caused by payload size or problematic directory objects.

This incremental approach helps isolate the OU that is affecting the sync.

Regards,
Sienna Carter
Hexnode UEM

Save