<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Privileged Access CLI Commands Fail With Authorization Is Revoked Error

Okta Classic Engine
Privileged Access
Okta Identity Engine

Overview

Okta Privileged Access (OPA) command-line interface (CLI) commands fail when the client IP address changes after session authorization, while the session-IP binding feature remains active. Disabling the session-IP binding feature in the web console resolves the issue. Depending on the CLI command executed, Okta generates different error messages:

 

error: cannot list team servers: Authorization is revoked

 

bulk target resolution: resolving name: Authorization is revoked
 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Privileged Access (OPA)
  • Command-Line Interface (CLI)

Cause

The client IP address changes after Okta authorizes the client session, and the Enable Session-IP Binding for Authenticated Client Sessions option remains active. If the IP address of the client machine remains unchanged, a changing Virtual Private Network (VPN) gateway causes the IP address shift.

Solution

How does an administrator disable session-IP binding in the Okta Privileged Access web console?

Navigate to the system configuration settings in the web console and disable the session-IP binding feature. This page is only available to users with the “Resource Administrator” team role.

  1. Sign in to the OPA web console using an account with the Resource Administrator team role.
  2. Go to Resource Administration > System configuration > Client Session.
  3. Disable the Enable Session-IP Binding for Authenticated Client Sessions option.

Enable Session-IP Binding for Authenticated Client Sessions

Loading
Okta Support - Okta Privileged Access CLI Commands Fail With Authorization Is Revoked Error