Team V,
Please, in the future, limit your entries to one question per thread. And also let us know what version of CAPAM you are asking your questions about.
Please see the following documentation for the setup and use of LDAP groups: Import LDAP Groups - CA Privileged Access Manager - 3.0.2 - CA Technologies Documentation
LDAP is configured on Config/3rd Party/LDAP page where the AD server info is input and the Update Interval (minutes): input is located. The update interval is when the refresh of that domain will take place. So what we suggest is to set it for 1440 which is what we consider the default (24hrs). How large the group is and traffic on the network and servers will determine how long the group refresh takes. If you have multiple domains, you would need to make sure that they do not kick off at the same time as this can cause a slowdown of CAPAM. To do that, you would need to update the refresh minutes after the amount of time that the first group finishes refreshing so there is no overlap. If you have more domains, then you would need to do the same for all of them so that none of them overlap.
If you get the message "ldap operation is in progress" then that is what is happening, the group is in the middle of refreshing and will not refresh again until it is finished.
For the question about your refresh problem, in pre 2.8.4 there may be a problem with the refresh being broekn by a temporary network outage that was fixed in 2.8.4. See the notes in our documentation: Resolved Issues in 2.8.4 - CA Privileged Access Manager - 2.8.4 - CA Technologies Documentation
The license uses licenses depending on what Access Targets (uses Access licenses) and what Target Accounts (uses Password licenses) are created.
I hope this helps!
Regards, Anthony