No articles found for this topic.
No articles found for this topic.
Beyond creating and updating members, SCIM can automatically assign Asana roles — Admin, Member, Guest, or a custom role — based on group membership or attributes in your identity provider. This article covers setup for Okta and Microsoft Entra ID; role mapping via SCIM isn't currently documented for Google Workspace or OneLogin.
custom_role_1, not custom role 1).Leaving Attribute Type as Group lets you manage roles on a group basis. Choose Personal if you'd rather manage roles per-member only.
Only select one role per group.
Asana supports one role per member. If a member is assigned to Okta groups mapping to more than one role, Asana uses whichever role group is highest in priority order.
If you also use Okta groups to manage Asana licenses (Enterprise vs. View-only — see Advanced setup: provisioning View-only licenses with SCIM), place license groups above role groups in this same priority list (for example: Enterprise, then View Only, then Admin, then Member).
Join(",",
IIF(Instr(Join("", AppRoleAssignmentsComplex([appRoleAssignments])), "\"value\":\"admin\"", , )>"0", "<asana_role_id>", ""),
IIF(Instr(Join("", AppRoleAssignmentsComplex([appRoleAssignments])), "\"value\":\"custom_role\"", , )>"0", "<asana_role_id>", ""),
IIF(Instr(Join("", AppRoleAssignmentsComplex([appRoleAssignments])), "\"value\":\"member\"", , )>"0", "<asana_role_id>", "")
)
To get each <asana_role_id>: in Asana, go to Manage roles, use the dropdown next to each role, and select Copy custom ID. Do this for every standard role (Member, Admin, Guest) and every custom role you plan to assign via SCIM. Super Admin is excluded — it's assigned only in the Asana admin console.
Click OK, then Save.
The order of roles in the expression sets assignment priority. Roles listed first have higher priority — if a member belongs to multiple mapped groups, they get the highest-priority role listed. For example, a member in both a Member group and an Admin group receives the Admin role in Asana.
Role names can't contain spaces — use an underscore instead.
|
Role |
Display name |
Value |
Description |
|---|---|---|---|
|
Member |
Asana Members |
|
Asana member role |
|
Admin |
Asana Admin |
|
Asana admin role |
|
Custom role |
Asana |
|
Asana custom role #1 |
Check Enable this app role for each, and click Apply.
Values set here must exactly match the naming used in the Expression mapping above — no spaces, underscores in their place.
Sequencing warning for first-time provisioning: if you're assigning both a license and a role via Entra groups at the same time for a member being provisioned for the first time, do it sequentially — assign one (license or role) first, confirm the member is successfully provisioned, then assign the other. If you assign both at once, Entra will only register one of the two as an "update" for that member.
If you're also provisioning View-only vs. Enterprise licenses via SCIM (see Advanced setup: provisioning View-only licenses with SCIM), you're managing two attributes — license and role — in the same IdP, and in Okta's case, through the same priority-ordered group list. Here's what the end state looks like once both are set up correctly.
In Okta, both license groups and role groups live in the same Applications > Asana > Assignments priority list. License groups must rank above role groups, and within each category, rank higher-permission groups above lower-permission ones. For an organization with Enterprise/View-only licensing and Admin/Member roles, the final priority order should read, top to bottom:
A member in the Enterprise and Admin groups gets an Enterprise license and the Admin role. A member in only the View-only and Member groups gets a View-only license and the Member role, and so on — the highest-ranked group in each category wins if there's any overlap within that category.
In Microsoft Entra ID, license (userType) and role (rbacRoles) are two independent attribute mappings, each driven by its own set of app roles and Entra groups — they don't share a single priority list the way Okta's groups do. The one place they interact is during first-time provisioning: if you're assigning both a license and a role to a member for the first time, do it sequentially (assign one, confirm it applied, then assign the other) per the sequencing warning above, rather than assigning both Entra groups at once.
Role mapping via SCIM is currently documented only for Okta and Microsoft Entra ID — not Google Workspace or OneLogin.

These cookies are strictly necessary to provide you with certain features. For example, these cookies allow you to access secure areas that require registration and set your privacy preferences. Because these cookies are essential to providing services to you, they cannot be disabled. You can set your browser to block or alert you about these cookies, but it may cause some parts of the site to not work.
Third party trackers collect information used for analytics and to personalize your experience with targeted ads. Under the Virginia Consumer Data Protection Act, you have the right to opt-out of the sale of your personal data to third parties. You also have the right to opt out of targeted advertising related processing. You may exercise your right to opt out of the sale of personal data and targeted advertising by using this toggle. If you opt out, we will not be able to offer you personalized ads and we will stop sharing your personal information with third parties. For more information please see our Privacy Statement.
These cookies allow us or our third-party analytics providers to collect information and statistics on use of our services by you and other visitors. This information helps us to improve our services and products for the benefit of you and others.
These cookies, provided by our third-party advertising partners, collect information about your browsing habits, as well as your preferences for various features and services. They also provide us with auditing, research, and reporting to know when advertising content has been displayed and how successful the content has been. This information allows us and our third-party advertising providers to display relevant advertising content.
These cookies provide enhanced functionality, providing chat support, allowing you to more easily complete forms, personalizing content to your preferences, and selecting your communications preferences. If you do not enable these cookies, or choose to disable them in the future, that could impact your ability to use certain features.