Okta Advanced Server Access and Privileged Access Authentication Token Expired Error
Last Updated:
Overview
An authentication token expiration error occurs in Okta Advanced Server Access (ASA) and Okta Privileged Access (OPA) due to client token inactivity. Re-enrolling the client resolves this issue. When running the login command, the login fails and generates the following error:
Authentication Token Expired.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Advanced Server Access (ASA)
- Okta Privileged Access (OPA)
Cause
The client token expires due to inactivity.
Solution
What steps re-enroll the client in Okta Advanced Server Access?
Re-enroll the Okta Advanced Server Access client by running the enrollment command, authenticating through the browser, and confirming the un-enrollment and re-enrollment prompts.
- Run the following command:
sft enroll --team <team_name>
- If a browser session opens, log in as directed and authorize the action to complete enrolling the client.
- If a prompt indicates that the client is already enrolled, enter Yes to continue.
- When a prompt to un-enroll the client appears, enter Yes.
- Log in again by running the following command:
sft login --team <team_name>
Re-enroll the Client in Okta Privileged Access Using the Dashboard
Re-enroll the Okta Privileged Access client by copying the enrollment command from the dashboard, authenticating through the browser, and confirming the un-enrollment and re-enrollment prompts.
- Log in to the Okta Privileged Access dashboard.
- Select Clients under Directory.
- Copy the specified command and run it on the client.
- If a browser session opens, log in as directed and authorize the action to complete enrolling the client.
- If a prompt indicates that the client is already enrolled, enter Yes to continue.
- When a prompt to un-enroll the client appears, enter Yes.
