Okta

How to Configure SAML 2.0 for Asana


    Read this before you enable SAML

    Enabling SAML will affect all users who use this application, which means that users will not be able to sign-in through their regular log-in page. They will only be able to access the app through the Okta service.


    Contents


    Supported Features

    The Okta/Asana SAML integration currently supports the following features:

    For more information on the listed features, visit the Okta Glossary.


    Configuration Steps

  1. Login to Asana.

  2. Click Account (top right), then select [yourDomainName] Settings:

    asana_new1.png

  3. Go to the Administration tab and do the following:

    • Select Members must log in via SAML.

    • Sign-in page URL: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • X.509 Certificate: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.
    • Click Save.

    asana_new2.png

  4. Test that your Organization members are able to use their Okta credentials to log in to Asana.

  5. Optional: Once the setup is verified, uncheck the Members may also log in with email/password box to require all Organization Members (internal employees) to use SAML. If left checked, Organization Members will continue to be able to log in with either Okta or their existing authentication method.

    Note: Organization Guests (external contributors) will always use a non-SAML authentication method to log in to Asana.

    asana_new3.png

  6. Done!


Notes

For SP-initiated SSO

Go to https://app.asana.com/a/<domain>.

For example, if your domain is acme.com, use https://app.asana.com/a/acme.com.