Loading

Topics

Available on Asana Enterprise+. Visit our pricing page for more information.

IP Allowlisting enhances your organization's security by restricting access to your Asana organization from only specified IP addresses or ranges. This ensures that only users connecting from approved networks can access your Asana organization.

Key features

Super admin configuration: Only super admins can enable or modify IP allowlisting settings. To activate this feature, the super admin must include their own IP address in the allowlist.
Customizable IP ranges: Define specific IP addresses in IPv4 or IPv6 format, or include any ranges in CIDR notation.
User-level restrictions: Apply IP restrictions to all users, only organization members, or only guests.

Configuring IP allowlist

To  enhance your organization's security by restricting access to approved IP addresses, follow these steps:

  1. Navigate to the admin console
  2. Under the Security section, click IP allowlist

Next, define your allowlist settings by entering a description and the IP address or IP address range.

Allowlist settings

After that, set which kinds of users you want the allowlist to apply to. Choose from Members and guests, only members, or only guests.

You must also ensure your own IP address is added to the list of approved IP addresses. Click Add IP address to add a new one, or a new range.

Finally, ensure you have checked the Enable allowlist checkbox which will start enforcing access based on the entered IP addresses or ranges.

Enable IP allowlist

Now, when a user on a non-approved IP tries to access your organization, they will be unable to. They will instead be asked to join on an approved network and will be shown the below image.

Access denied

Managing API access

IP restrictions do not apply to API requests. Asana's App Management and Integrations feature provides administrators with robust tools to control and monitor third-party applications connected to their organization's Asana environment. This includes capabilities such as viewing connected apps, setting global app permissions, blocking or approving specific apps, and managing personal access tokens.

Frequently asked questions

Can I use IP allowlisting without being a super admin?

No. Only super admins can configure or modify IP allowlisting settings.

What happens if two super admins are editing the IP allowlist at the same time?

Each super admin’s update will be reflected simultaneously. To avoid conflicts, it’s best to only have one super admin editing the settings at a time.

What happens if a user's IP isn't on the allowlist?

They will be denied access to Asana until their IP is added to the allowlist.

Can I specify IP ranges instead of individual IP addresses?

Yes. Asana supports both individual IP addresses and CIDR-formatted IP ranges (e.g., 192.168.1.0/24).

Can I apply IP restrictions only to guests or members?

Yes. You can scope restrictions to all users, only members, or only guests.

What if I forget to include my own IP when setting up the allowlist?

The system requires the super admin's current IP to be included to save or enable the settings.

Does IP allowlisting affect API or SCIM access?

No. API and SCIM requests are exempt from IP restrictions. To manage API access, use Asana's App Controls and Permissions features via the admin console.

Will integrations or third-party apps be affected by IP allowlisting?

Not directly. Since API calls aren't restricted by IP allowlisting, integrations will continue to function. However, it's recommended to manage app access through App Controls via the admin console.

 

Loading
Enhance Asana Security with IP Allowlisting