Advanced Server Access user and group attributes
End of sale announcement
Effective May 1, 2026, Okta will no longer sell or renew Advanced Server Access. Existing customers must migrate to Okta Privileged Access within one year of their next scheduled renewal date to maintain service.
Read the FAQ and learn more about Okta Privileged Access.
Advanced Server Access attributes are configurable metadata that allow teams to specify various characteristics of users and groups. Attributes allow teams to customize how Advanced Server Access synchronizes users and groups to enrolled servers. This means teams can systematically manage infrastructure identity using Okta as the single source of truth. Additionally, teams can import existing configurations from systems outside of Okta into Advanced Server Access by using custom attribute mappings.
By default, Advanced Server Access defines specific values at the team level and applies them to all users and groups. Teams can modify these default values from the Advanced Server Access application panel within Okta.
In some cases, teams may need to modify the attributes for specific projects. Teams can set project-level attributes that override the team-level settings for a user or group assigned to the project. The team-level settings are used on any projects that haven't explicitly modified the attributes. Project-level overrides are configured from the Advanced Server Access dashboard.
Default attributes
By default, Advanced Server Access assigns values for the following attributes:
| Type | Attributes |
|---|---|
| User Attributes |
|
| Group Attributes |
|
