No articles found for this topic.
No articles found for this topic.
Visit our pricing page for more information.
Note
Any attribute data synced to Asana via SCIM is available to all downstream Asana features, including AI features like Asana Intelligence (Dash). If you do not want a specific attribute surfaced in these features, remove or unmap it from your SCIM configuration in your identity provider, such as Okta or Microsoft Entra ID, before it syncs to Asana.
Every SCIM integration — regardless of identity provider — authenticates using an Asana Service Account token. Set this up once before following any of the IdP-specific steps below.
Note
Keep this token secure. Anyone with the token can provision and deprovision members in your organization.
Super admins can easily provision and deprovision users in Asana from Okta. The integration relies on the SCIM protocol and supports:
Not currently supported: reactivating members, and deleting Asana teams from Okta.
Before you enable deactivation, read this: deactivating a member in Okta doesn't just pause their Asana access — it deletes their account in Asana, the same as removing them from the Asana UI. There's no separate "deactivated but recoverable" state. Similarly, overriding a member's username at the application level in Okta will delete the Asana account tied to their previous username, if that account was active. Keep both in mind before you enable Deactivate Users in Step 3 below or apply a username override.
Log in to Okta and add Asana's integration app to your org from the App Integration Catalog under Applications.



In Asana: generate a Service Account token as described above and copy it.
In Okta:

Note
We recommend you enable Create Users, Update User Attributes, and Deactivate Users.


You can push new Okta groups into Asana as teams, or link Okta groups to existing Asana teams.
Deleting a team in Asana isn't supported from Okta. Use the Teams tab in the Asana Admin Console instead.

On the Asana app's Provisioning tab, under Asana Attribute Mappings, choose Create or Create and Update for each attribute you want to sync. Supported attributes:
|
Attribute |
Type |
Notes |
|---|---|---|
|
userName |
String |
Required. Must be a unique email address matching your Asana organization's domain. |
|
name.formatted |
String |
The member's full name. Use this — |
|
emails.value |
String |
Member's email address. |
|
emails.primary |
Boolean |
Marks the primary email. Only one email may be marked primary. |
|
title |
String |
The member's job title. |
|
department |
String |
The member's department. |
|
preferredLanguage |
String |
Only applied when the member is first created. Later updates to this field in Okta aren't reflected for existing members. |
|
active |
Boolean |
Whether the member's account is active in Asana. |
If you want to stop syncing a specific attribute, remove or unmap it in Okta — Asana doesn't provide a separate exclude control. Removing a mapping stops future syncs; it doesn't delete data that's already synced.
To pick up new attributes or capabilities on an integration you already have running:

Asana's Microsoft Entra ID integration is configured primarily through Microsoft's own provisioning tutorial, since the setup lives entirely in the Entra admin center. Complete these Asana-specific steps first, then follow Microsoft's walkthrough for the Entra-side configuration.
Because this configuration happens in the Entra admin center, refer to Microsoft's tutorial for up-to-date screenshots and navigation — Asana's attribute-mapping and Service Account requirements above stay the same regardless of Microsoft's UI changes.
If you use Google Workspace as your identity provider and want to set up SCIM provisioning with Asana, contact your account executive or Asana support for current setup guidance.
Asana's OneLogin integration is configured directly in OneLogin. Follow OneLogin's SCIM provisioning setup guide for Asana for step-by-step instructions.
If you're configuring SCIM with an identity provider that isn't natively integrated with Asana, see Asana's developer documentation on supported SCIM attributes for the full list of accepted attributes.
When a member is deprovisioned from Asana via SCIM or the API using a Service Account token, Asana automatically creates a "Previously assigned tasks" project containing their public tasks. You can configure who owns that project:
This customization only applies when a member is removed via SCIM or the API with a Service Account token — not when removed manually through the Asana UI. For more on what happens when a member is removed, see User deprovisioning.

These cookies are strictly necessary to provide you with certain features. For example, these cookies allow you to access secure areas that require registration and set your privacy preferences. Because these cookies are essential to providing services to you, they cannot be disabled. You can set your browser to block or alert you about these cookies, but it may cause some parts of the site to not work.
Third party trackers collect information used for analytics and to personalize your experience with targeted ads. Under the Virginia Consumer Data Protection Act, you have the right to opt-out of the sale of your personal data to third parties. You also have the right to opt out of targeted advertising related processing. You may exercise your right to opt out of the sale of personal data and targeted advertising by using this toggle. If you opt out, we will not be able to offer you personalized ads and we will stop sharing your personal information with third parties. For more information please see our Privacy Statement.
These cookies allow us or our third-party analytics providers to collect information and statistics on use of our services by you and other visitors. This information helps us to improve our services and products for the benefit of you and others.
These cookies, provided by our third-party advertising partners, collect information about your browsing habits, as well as your preferences for various features and services. They also provide us with auditing, research, and reporting to know when advertising content has been displayed and how successful the content has been. This information allows us and our third-party advertising providers to display relevant advertising content.
These cookies provide enhanced functionality, providing chat support, allowing you to more easily complete forms, personalizing content to your preferences, and selecting your communications preferences. If you do not enable these cookies, or choose to disable them in the future, that could impact your ability to use certain features.