Okta Privileged Access CLI Commands Fail With Authorization Is Revoked Error
Last Updated:
Overview
Okta Privileged Access (OPA) command-line interface (CLI) commands fail when the client IP address changes after session authorization, while the session-IP binding feature remains active. Disabling the session-IP binding feature in the web console resolves the issue. Depending on the CLI command executed, Okta generates different error messages:
error: cannot list team servers: Authorization is revoked
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Privileged Access (OPA)
- Command-Line Interface (CLI)
Cause
The client IP address changes after Okta authorizes the client session, and the Enable Session-IP Binding for Authenticated Client Sessions option remains active. If the IP address of the client machine remains unchanged, a changing Virtual Private Network (VPN) gateway causes the IP address shift.
Solution
How does an administrator disable session-IP binding in the Okta Privileged Access web console?
Navigate to the system configuration settings in the web console and disable the session-IP binding feature. This page is only available to users with the “Resource Administrator” team role.
- Sign in to the OPA web console using an account with the Resource Administrator team role.
- Go to Resource Administration > System configuration > Client Session.
- Disable the Enable Session-IP Binding for Authenticated Client Sessions option.
