Super admins can use SAML Group Mapping to designate users who can consume a license based on the security group value passed via SAML. This allows you to have users consume a license during sign-in while other users will not, and their usage of Asana will be restricted to submitting internal form responses. Users who cannot consume a license will be routed to your internal ticketing system to request access to Asana.
This functionality allows non-licensed users to submit private form responses without claiming a license. If you plan on using Asana for Request Tracking or Ticketing, you should set up SAML Group Mapping accordingly.
The SAML group attribute must be configured in your identity provider (IdP). The group claim must be named “group” or “groups” (e.g., Azure documentation, Okta documentation). Once you have configured your SAML configuration to include the group claim in your IdP, you can set up SAML group mapping in Asana.
1. Sign in to the Asana admin console
2. In the navigation menu, click on Security, then SAML
3. Navigate to the SAML group mapping tab
4. Click Add Group Claim.
5. Enter the correct information for:
6. Click Save
For Azure customers: Limit the groups returned in the claim to only “Group assigned to the application.” Make sure to customize the group name to be “groups” (documentation).
Yes. There are two modifications needed:
Here is a schematic of the configuration. Please note that if you have provisioning jobs enabled, we suggest a different configuration (more details here).
No. License consumption via SAML Group Mapping is only effective for new users during authentication. New users are users that have never used Asana or have used Asana but have been deprovisioned. SCIM is the right scalable option to automatically provision/deprovision. SAML Group Mapping should not be used to manage user and license lifecycle.
Please read this article for more information.
Verify that the SAML payload you’ve pasted contains the group claim used to enforce SAML Group Mapping for license. The group claim should have the custom name: “group” or “groups.” SAML Group Mapping will not work if the group claim is not recognized by Asana.
Verify that testing users are new users. New users are users who have never used Asana or who have used Asana but have been deprovisioned.
This URL must be a valid link to your internal intake form, which allows your users to request access to Asana. It can be an Asana org-only form.
No. Users who log in via SAML and are eligible to consume a license will consume a full license. Users with View Only Licenses should be set in the Asana admin console.
No. License consumption only happens in the home organization of a given user. Guests do not consume licenses in the organizations where they are a guest.