Configure a User With Sudo Privileges to Run Any Command as a Privileged User Using Sudo Entitlements in Okta Advanced Server Access
Last Updated:
Overview
Configure a user with sudo privileges to run any command as a privileged user using sudo entitlements in Okta Advanced Server Access (ASA). Achieve this by configuring a sudo entitlement with the RAW option and assigning it to the appropriate group. Alternatively, assign admin privileges to the users through group assignments without configuring entitlements.
NOTE: It is recommended to use specific commands or directories through sudo entitlements since the "ALL" option has the potential to allow users to become root.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Advanced Server Access (ASA)
- Sudo Entitlements
Solution
How is a user configured with sudo privileges to run any command as a privileged user?
Configure the sudo entitlement with the RAW option, assign the entitlement to the target group, and authenticate to the managed host by following these steps:
- Configure the sudo entitlement with the RAW option and ALL as the sub-option.
- Navigate to Projects, click Groups, and select the group to which the entitlement should be added.
- Navigate to the Group Entitlements section and click Add Sudo Entitlement Binding.
- Authenticate to the ASA-managed host via Secure Shell (SSH) using the
sft sshcommand and run the following command:sudo -ui <sudo user>
