<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Configure a User With Sudo Privileges to Run Any Command as a Privileged User Using Sudo Entitlements in Okta Advanced Server Access

Advanced Server Access
Okta Classic Engine
Okta Identity Engine

Overview

Configure a user with sudo privileges to run any command as a privileged user using sudo entitlements in Okta Advanced Server Access (ASA). Achieve this by configuring a sudo entitlement with the RAW option and assigning it to the appropriate group. Alternatively, assign admin privileges to the users through group assignments without configuring entitlements.

 

NOTE: It is recommended to use specific commands or directories through sudo entitlements since the "ALL" option has the potential to allow users to become root.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Advanced Server Access (ASA)
  • Sudo Entitlements

Solution

How is a user configured with sudo privileges to run any command as a privileged user?

Configure the sudo entitlement with the RAW option, assign the entitlement to the target group, and authenticate to the managed host by following these steps:

  1. Configure the sudo entitlement with the RAW option and ALL as the sub-option.
    Update Sudo Entitlement
  2. Navigate to Projects, click Groups, and select the group to which the entitlement should be added.
    Projects
  3. Navigate to the Group Entitlements section and click Add Sudo Entitlement Binding.
    Group Entitlements
  4. Authenticate to the ASA-managed host via Secure Shell (SSH) using the sft ssh command and run the following command:
    sudo -ui <sudo user>

 

Related References

Loading
Configure a User With Sudo Privileges to Run Any Command as a Privileged User Using Sudo Entitlements in Okta Advanced Server Access | Okta Support