In This Article
For customers who use an automatic provisioning job via SCIM and plan to use SAML Group Mapping for licenses, we suggest having two different Asana applications in their IdP. Deploying two separate applications for Asana — one for Single Sign-On (SSO) and another for System for Cross-domain Identity Management (SCIM) — can help manage access and user identities in a large organization. By doing so, authentication mechanisms are isolated from provisioning mechanisms.
Note
Changing the group assignment from claimable to unclaimable will not deprovision users. Users must be deprovisioned via the Asana admin console and then be removed from the IdP security group.
When going from 1 application with both SSO and SCIM enabled to 2 applications, one for SSO and the other for SCIM, make sure to: