<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Advanced Server Access: Getting Labels from AD Joined Servers
Advanced Server Access
Okta Classic Engine
Okta Identity Engine
Overview

This article provides detailed instructions on setting up granular access for servers with labels when using AD-joined flow.

Applies To
  • Okta Advanced Server Access
  • Active Directory (AD)-Joined
  • Server Agent
Solution

There are two methods of doing this, and instructions for both are listed below.

  1. Using the server agent.
  1. Using AD join.
    1. Identify the attribute that needs to be added as a label. Attributes for a user can be seen by enabling Active Directory Users and Computers, selecting View > Advanced Features, and then selecting Attribute Editor for the machine. Here location attribute will be used as an example. 

Attributes

    1. Log in to ASA UI. Specify the selected attribute under the server sync job with a label that needs to be used in ASA. Here, the location will be referred to as a label test in ASA:

Query

    1. Once the job finishes, click on the server, and the label will be displayed as shown in the screenshot below:

Attribute shown

    1. Now the label can be assigned to the group to give granular access to selected users only (that is, only the users who have the location attribute set as "US" in AD can access the servers). Note that the label needs to be prefixed with "ad.", exactly matching the label key on the server details page.

Server Selector Tags
 

     

     

    Related References

    Loading
    Advanced Server Access: Getting Labels from AD Joined Servers