Asana provides a comprehensive set of security controls to help organizations safeguard their data and ensure compliance with security policies.
Admins and super admins can manage various security settings to protect their organization. These controls include managing user access, setting permissions, and configuring advanced security measures.
Here’s an overview of the key security features available.
Google SSO allows members to sign in using their Google accounts, streamlining the login process while maintaining security.
SAML authentication provides integration with identity providers like Okta, Azure Active Directory, and OneLogin. Administrators can configure SAML to be:
When configuring SAML, you can set session timeout durations and mobile session timeout settings to control how long users stay logged in.
Two-factor authentication (2FA)
Two-factor authentication adds an extra layer of security by requiring a second form of identification. Available on all paid plans, 2FA can be:
This setting doesn't impact users who sign in with Google SSO or SAML, as these methods provide their own security layers.
Asana's default password strength requirements ensure that passwords are at least 8 characters and have a "fair" entropy score. For enhanced security, admins can increase the minimum length to up to 20 characters.
Password reset allows administrators to force a password reset for all members in the organization. This immediately signs out all users and requires them to create new passwords via email.
The Asana mobile app ensures data security with features like biometric authentication (fingerprint and facial recognition), and controlled app permissions. Admins can manage permissions to restrict screen captures, attachments, and limit copy and paste. These measures help protect your organization’s information on mobile platforms.
Control who can invite guests to your organization:
Manage which file attachment types are allowed in your organization. Administrators can disable specific attachment methods or restrict all file attachments if needed for security compliance.
Set default privacy levels for new teams and projects:
Control how project views and timelines can be shared:
By leveraging these security controls, organizations can effectively protect their data, maintain compliance with security policies, and provide a secure working environment for their teams.