Enroll an Okta Advanced Server Access or Okta Privileged Access (OPA) Server to a New Team or Project
Last Updated:
Overview
Re-enroll an Okta Advanced Server Access (ASA) or Okta Privileged Access (OPA) server agent to a new team or project by deleting the server from the Admin Console, clearing the local agent state directory, and providing a new enrollment token. This process is used when moving a server between Okta Advanced Server Access and Okta Privileged Access, or between different teams and projects.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Advanced Server Access (ASA)
- Okta Privileged Access (OPA)
- ScaleFT Server Tools
Solution
How does an administrator enroll a server to a new team or project?
Delete the server from the Okta Advanced Server Access Admin Console to remove the server agent association:
- Delete the server from the Admin Console.
NOTE: The users remain on the server after removal. Remove the groups from the project or manually remove the managed users and groups from the server.
The Windows server agent requires re-enrollment.
Remove the ScaleFT folder, restart the service, and add the new enrollment token as follows.
- Remove the following folder:
C:\Windows\System32\config\systemprofile\AppData\Local\ScaleFT
- Open Windows Services, locate ScaleFT Server Tools, and restart the service.
- Validate that the system recreated the folder.
- Add the new
enrollment.tokento re-enroll the server.
How is the Linux server agent re-enrolled?
Remove the sftd directory, restart the service, and add the new enrollment token by following these steps.
- Remove the folder by running the following command:
sudo rm -rf /var/lib/sftd
- Restart the service to recreate the folder by running the following command:
sudo systemctl restart sftd
- Add the new
enrollment.tokento re-enroll the server.
