Available on Asana Enterprise and Enterprise+ tiers, as well as legacy tier Legacy Enterprise.
Visit our pricing page for more information.
Admins can enforce two-factor authentication (2FA) for all domain members and guests, enhancing security. Enabling two-factor authentication means that Asana will ask for an additional code, in addition to email and password, when authenticating. This will be useful for guests without SAML/SSO as they don't usually have an email address that belongs to the admin's organization.
This feature is for security-conscious admins who want to add an additional layer of security for their users/domain. Enabling 2FA as required will require 2FA for both members and guests to log in to domains that may not be SSO/SAML required. For SSO/SAML required domains, this feature enforces two-factor authentication only for guests logging in.
Asana's two-factor authentication relies on time-based one-time passwords (TOTP). These one-time numeric passwords are supported by authenticator apps such as Authy, Duo, Microsoft Authenticator, and Google Authenticator using the TOTP standard. You can find more information about TOTP authentication codes at this link. 2FA will be enforced on users logging in on the web and through the mobile app.
Like what you see? Get started with a free Asana trial today. Try for free
Admins can activate 2FA from the Security tab in the admin console. You must also activate 2FA for your own account before you can require it for your organization.

Divisional admins will need to contact Asana support to enable 2FA as required for their organization. This will affect all users, including those outside the division.

Upon activation, users (full members and guests) in your organization will receive an email asking them to enable 2FA for their account.
Note
Asana will display a banner prompting users to set up 2FA for their account.

Users can go to their Settings to set up and enable 2FA from this email.
Note
If your organization is set up to require SSO or SAML then full members in your organization won’t be required to set up 2FA as they are already using a secure method to login to Asana. We will still enforce 2FA for any guests logging into Asana.

Users (members or guests) in your organization who don't set up 2FA within 7 days after it is required will be logged out and will need to set up 2FA before they can log in to Asana. Additionally, if users do not set up 2FA within 14 days, their passwords will be invalidated, and they will need to reset their password via the Forgot Password flow to log in again.
If 2FA is mandatory in an organization that a user belongs to, then the user will need to set up 2FA the next time they log in to Asana if they have an existing account in Asana. The instructions below show how this can be done.


Scan the barcode shown, add it to your authenticator app, and click Continue.

On the next screen, enter the 6-digit code shown inside the authenticator app for this newly added Asana account and click Continue.

The next screen will confirm that 2FA has been set up for your account. Asana will ask you for your email, password, and the authentication code from your app every time you log in.
If two-factor authentication is mandatory in an organization to which a user has been invited, they will need to set up 2FA during the Asana account creation process. The instructions below show how to do this.


The next step is to set up two-factor authentication for your account:

You will see this screen to confirm that 2FA has been set up. Click Continue to carry on setting up your Asana account.
Yes, mandatory 2FA is available for divisions on Asana Enterprise and Enterprise+, as well as legacy tier Legacy Enterprise. Division admins can request that 2FA be enabled by contacting Asana support. In this case, 2FA will be enabled for the entire domain (not just the division).
Users will receive an email asking them to set up 2FA after admins turn on 2FA. All users within the domain will be logged out after 7 days if they do not set up 2FA.
The second factor for authentication will come from 3rd party authenticator apps such as Duo, Authy, or Microsoft Authenticator that can be installed on the phone.
Admins can contact Asana's support team to get a list of users who still need to turn on 2FA in their domain.
No, users (and guests) in a domain who only use SSO/SAML to log in will not need to set up 2FA.
Users can change their 2FA device via their profile settings.
Users must provide 2FA when logging in on web, desktop, and the Asana mobile app.

These cookies are strictly necessary to provide you with certain features. For example, these cookies allow you to access secure areas that require registration and set your privacy preferences. Because these cookies are essential to providing services to you, they cannot be disabled. You can set your browser to block or alert you about these cookies, but it may cause some parts of the site to not work.
Third party trackers collect information used for analytics and to personalize your experience with targeted ads. Under the Virginia Consumer Data Protection Act, you have the right to opt-out of the sale of your personal data to third parties. You also have the right to opt out of targeted advertising related processing. You may exercise your right to opt out of the sale of personal data and targeted advertising by using this toggle. If you opt out, we will not be able to offer you personalized ads and we will stop sharing your personal information with third parties. For more information please see our Privacy Statement.
These cookies allow us or our third-party analytics providers to collect information and statistics on use of our services by you and other visitors. This information helps us to improve our services and products for the benefit of you and others.
These cookies, provided by our third-party advertising partners, collect information about your browsing habits, as well as your preferences for various features and services. They also provide us with auditing, research, and reporting to know when advertising content has been displayed and how successful the content has been. This information allows us and our third-party advertising providers to display relevant advertising content.
These cookies provide enhanced functionality, providing chat support, allowing you to more easily complete forms, personalizing content to your preferences, and selecting your communications preferences. If you do not enable these cookies, or choose to disable them in the future, that could impact your ability to use certain features.