Create setup tokens

Enrolling gateways into Okta Privileged Access requires setup tokens. You can use gateways to manage access to servers or to manage access to databases.

Prerequisites

  • You must be a member of the Okta Privileged Access resource administrator group or a delegated resource administrator.

Create a Okta Privileged Access gateway setup token

Gateway setup tokens are reusable and required to configure a gateway machine. Gateways are lightweight servers deployed in your environments that bridge the Okta control plane and your infrastructure.

A setup token grants one of two roles, and the role determines what the gateways enrolled with that token can do. Choose the role that matches the resources you want to manage:

  • Server access proxy: Choose this role to broker and record secure SSH and RDP sessions to Linux and Windows servers.
  • Infrastructure orchestrator: Choose this role to discover resources and manage the access lifecycle for databases and other infrastructure.
  1. On the Okta Privileged Access dashboard, go to Resource Administration > Gateways.
  2. Select Add setup token.
  3. On the dialog that appears do the following:
    1. Enter a token name.
    2. Select one of the following: Infrastructure orchestrator or Server access proxy.

    3. If you selected Server access proxy, complete the following:
      1. Select the Add label field, and then select an existing label or create a label. Labels must be a key-value pair (for example, environment:staging).
      2. Press the Tab or Enter key to finalize the label.
      3. Optional. Repeat this process to add other labels.
      4. Select Create.
      5. Copy the token, and then select Done. You need this token when you perform setup using the configuration options. See Configure the Okta Privileged Access gateway.
    4. If you selected Infrastructure orchestrator, complete the following:
      1. Select the Choose or add orchestration group field, and then select an orchestration group or enter a name to create one.
      2. Select Create.
      3. Copy the token, and then select Done. Use this token when setting up your new gateway machine. See Configure the gateway to support database integrations.

Edit server proxy labels

This task applies only to gateways enrolled for the Server access proxy role. You can edit a gateway to add new labels or remove an existing label.

  1. On the Okta Privileged Access dashboard, go to Resource Administration > Gateways.
  2. On the gateway that you want to edit, select Actions > Edit.
  3. Go to Labels and type in a name to select an existing label or to create one.
  4. To remove a label, select x on the label.
  5. Select Save.