注意
無法透過 SCIM 指派超級管理員角色。若要指定超級管理員,請在完成超級管理員驗證後使用 Asana 系統管理主控台。SCIM 僅可指派系統管理員和成員角色。
連結 Asana 網域後,請前往「佈建」標籤頁。
展開「Mappings」(對應),並在其下方點選「Provision Microsoft Entra ID Users」(佈建 Microsoft Entra ID 使用者)
捲動至「屬性對應」頁面底部,勾選「顯示進階選項」。這將顯示另外幾個選項。點選「編輯 Asana 的屬性清單」。
若您無法使用此功能,請確認您已依照開始之前中的步驟,在完全啟用架構的情況下開啟 Microsoft Entra ID。
在「編輯屬性清單」頁面上,新增名為rbacRoles的新使用者屬性,類型為字串。儲存屬性清單。
返回「屬性對應」頁面,點選「新增新對應」。
將對應類型設定為運算式
將「運算式」設定為
Join(",",
IIF(Instr(Join("", AssertiveAppRoleAssignmentsComplex([appRoleAssignments])), "\"value\":\"admin\"", , )>"0", "1234567890", ""),
IIF(Instr(Join("", AssertiveAppRoleAssignmentsComplex([appRoleAssignments])), "\"value\":\"custom_role\"", , )>"0", "1234567890", ""),
IIF(Instr(Join("", AssertiveAppRoleAssignmentsComplex([appRoleAssignments])), "\"value\":\"member\"", , )>"0", "1234567890", "")
)在此運算式中,您要設定角色名稱,並從 Asana 取得相應的自訂角色 ID 以取代數字集。角色 ID 必須參數化 - ID (數字) 是用於示範的預留位置,必須由您自己的 Asana 自訂 ID 取代。
重要提醒- 運算式中角色的順序將決定角色指派的優先順序。頂端的角色將具有較高的優先順序。稍後,如果使用者屬於多個角色群組,他們將獲得此處定義的最高優先順序角色。
跳過預設值欄位
將目標屬性設定為rbacRoles ,這是我們剛剛建立的屬性
將「使用此屬性比對物件」設定為「否」
將「套用此對應」設為「始終」
前往「管理角色」頁面,點選每個角色右側的下拉式選單,然後點選「複製自訂 ID」。針對您計劃使用 SCIM 指派的每個標準角色 (例如 Asana 成員或系統管理員),以及您建立的任何自訂角色,重複此流程。超級管理員角色僅可在 Asana 系統管理主控台中指派,而不能透過 SCIM 指派。
結果應該是這樣:
點選OK (確定) 並儲存。
前往左側導覽窗格中「管理」下的「使用者和群組」。在此畫面上點選應用程式註冊。
我們會建立與您設定的角色相符的應用程式角色。按一下「建立應用程式角色」。
注意
在此處建立的每個應用程式角色中設定的值必須與上述「運算式」中設定的命名相符。該值不能有空格。使用底線取代空格。
成員
系統管理員
自訂角色:建立更多自訂應用程式角色,以便與您設定的所有自訂角色相符
點選套用以儲存應用程式角色。
新增您網域中的所有其他角色。
結果將如下所示:
現在,為每個 Asana 角色建立一個 Entra 群組
現在,我們會將角色指派給群組。前往 Enterprise 應用程式> Asana 應用程式>管理>使用者和群組:
按一下「新增使用者/群組」,並將每個群組與其相應的角色關聯:
結果將如下所示:
現在設定已完成,您可以將使用者新增至其相應的群組,以便指派角色。在下一個佈建週期執行時,此設定將為使用者指派相應的角色 (或者,您可以依需求進行佈建),您將在 Asana 中看到此變更。
注意
若您是首次佈建使用者,並希望透過 Entra ID 群組指派授權和角色,請依序進行:首先將使用者佈建到授權或角色群組之一,然後在使用者成功佈建後,您可以將另一個授權或角色群組指派給使用者。否則,Entra 只會指派一個屬性,而不會將另一個屬性讀取為使用者的「更新」。
注意
This article has been AI-translated.
Send translation feedback.

These cookies are strictly necessary to provide you with certain features. For example, these cookies allow you to access secure areas that require registration and set your privacy preferences. Because these cookies are essential to providing services to you, they cannot be disabled. You can set your browser to block or alert you about these cookies, but it may cause some parts of the site to not work.
Third party trackers collect information used for analytics and to personalize your experience with targeted ads. Under the Virginia Consumer Data Protection Act, you have the right to opt-out of the sale of your personal data to third parties. You also have the right to opt out of targeted advertising related processing. You may exercise your right to opt out of the sale of personal data and targeted advertising by using this toggle. If you opt out, we will not be able to offer you personalized ads and we will stop sharing your personal information with third parties. For more information please see our Privacy Statement.
These cookies allow us or our third-party analytics providers to collect information and statistics on use of our services by you and other visitors. This information helps us to improve our services and products for the benefit of you and others.
These cookies, provided by our third-party advertising partners, collect information about your browsing habits, as well as your preferences for various features and services. They also provide us with auditing, research, and reporting to know when advertising content has been displayed and how successful the content has been. This information allows us and our third-party advertising providers to display relevant advertising content.
These cookies provide enhanced functionality, providing chat support, allowing you to more easily complete forms, personalizing content to your preferences, and selecting your communications preferences. If you do not enable these cookies, or choose to disable them in the future, that could impact your ability to use certain features.