<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Cannot Enroll a Windows Server in ASA/OPA via Enrollment Token

Advanced Server Access
Okta Classic Engine
Okta Identity Engine
Privileged Access

Overview

When admins create an enrollment token in C:\windows\system32\config\systemprofile\AppData\Local\ScaleFT,  the file does not go away, which means the server is not being enrolled. 

Applies To

  • Okta Advanced Server Access (ASA)
    • Also known as ScaleFT

Cause

The File name extensions option is unchecked, so the enrollment.token is just a text file at this point.

Solution

  1. Navigate to C:\windows\system32\config\systemprofile\AppData\Local\ScaleFT\.
    • The enrollment.token is still there and has not been processed.
  2. Within the ScaleFT directory, click on View in the navigation pane of File Explorer, then check the File name extensions.
    • This will display the enrollment.token to enrollment.token.txt
  3. Rename the file and remove ".txt", then press enter to confirm the changes. 
    • It should now just be enrollment.token.
  4. Wait a few minutes. Refresh File Explorer and verify that the enrollment.token file is no longer shown. Since it has been processed, the server should now show up in the ASA dashboard. 
Loading
Cannot Enroll a Windows Server in ASA/OPA via Enrollment Token | Okta Support