No articles found for this topic.
No articles found for this topic.
Visit our pricing page for more information.
Some SCIM capabilities (like assigning roles or view-only licenses automatically) require Enterprise+.
SCIM (System for Cross-domain Identity Management) lets you automate how members are added to, updated in, and removed from your Asana organization by syncing directly from your identity provider (IdP). Instead of manually inviting members or updating their access one at a time, super admins can connect Asana to an IdP like Okta or Microsoft Entra ID and let user and group changes flow into Asana automatically.
This article is a starting point. Use it to understand what SCIM can do in Asana, confirm you're eligible, and find the right setup guide for what you're trying to accomplish.
When connected to a supported identity provider, SCIM can:
SCIM does not currently support:
Asana supports SCIM 2.0 provisioning with:
Basic provisioning (creating, updating, and deactivating members) is available on all four for organizations on an Enterprise, Enterprise+, or Legacy Enterprise plan. Automatic role assignment via SCIM requires Okta or Microsoft Entra ID and an Enterprise+ plan. Automatic View-only license provisioning via SCIM also requires Okta or Microsoft Entra ID, but is available on Enterprise or Enterprise+ — it doesn't require Enterprise+ specifically.
Note
SCIM is available for organization-wide plans. It is not available for divisions.
A note on terminology: Asana calls provisioned people "members." Your identity provider may use a different term for the same thing — Okta calls them "People," Microsoft Entra ID calls them "Users." The setup guides below use each provider's own terminology when describing steps in that provider's console.
|
Identity provider |
Basic provisioning |
View-only licensing |
Role mapping |
|---|---|---|---|
|
Okta |
✅ |
✅ |
✅ |
|
Microsoft Entra ID |
✅ |
✅ |
✅ |
|
Google Workspace |
Supported — no first-party walkthrough yet; contact support |
Not documented |
Not documented |
|
OneLogin |
✅ (configured in OneLogin's own console) |
Not documented |
Not documented |
|
I want to... |
Go to |
|---|---|
|
Automatically create, update, and deactivate members as they change in my IdP |
Basic setup: provisioning and deprovisioning users with SCIM |
|
Automatically assign Enterprise vs. View-only licenses as I provision members | |
|
Automatically assign Admin, Member, Guest, or custom roles as I provision members | |
|
Provision an add-on license (AI Teammates, Compliance management, etc.) | |
|
Set a licensing division for DIPO |
Most organizations start with basic setup, then layer on role or license automation once basic provisioning is confirmed working.
A few things apply no matter which IdP or which guide above you follow:

These cookies are strictly necessary to provide you with certain features. For example, these cookies allow you to access secure areas that require registration and set your privacy preferences. Because these cookies are essential to providing services to you, they cannot be disabled. You can set your browser to block or alert you about these cookies, but it may cause some parts of the site to not work.
Third party trackers collect information used for analytics and to personalize your experience with targeted ads. Under the Virginia Consumer Data Protection Act, you have the right to opt-out of the sale of your personal data to third parties. You also have the right to opt out of targeted advertising related processing. You may exercise your right to opt out of the sale of personal data and targeted advertising by using this toggle. If you opt out, we will not be able to offer you personalized ads and we will stop sharing your personal information with third parties. For more information please see our Privacy Statement.
These cookies allow us or our third-party analytics providers to collect information and statistics on use of our services by you and other visitors. This information helps us to improve our services and products for the benefit of you and others.
These cookies, provided by our third-party advertising partners, collect information about your browsing habits, as well as your preferences for various features and services. They also provide us with auditing, research, and reporting to know when advertising content has been displayed and how successful the content has been. This information allows us and our third-party advertising providers to display relevant advertising content.
These cookies provide enhanced functionality, providing chat support, allowing you to more easily complete forms, personalizing content to your preferences, and selecting your communications preferences. If you do not enable these cookies, or choose to disable them in the future, that could impact your ability to use certain features.