Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Asana is a cloud-based tool for project management. Your users can collaborate on projects and tasks across your organization and with partners. Asana holds critical data, which makes it a target for malicious actors.
Connect Asana to Defender for Cloud Apps to get better insights into user activity. You also get threat detection through machine learning anomaly detections.
This article explains how to connect Asana to Defender for Cloud Apps using the App Connector API, configure policies to monitor Asana activity, and automate governance actions.
Main threats include:
- Compromised accounts and insider threats
- Data leakage
- Insufficient security awareness
- Unmanaged bring your own device (BYOD)
Control Asana with policies
The following table lists the policy types you can use to monitor and control Asana activity.
| Type | Name |
|---|---|
| Built-in anomaly detection policy | Activity from anonymous IP addresses Activity from infrequent country Activity from suspicious IP addresses Impossible travel Activity performed by terminated user (requires Microsoft Entra ID as IdP) Multiple failed login attempts |
| Activity policy | Built a customized policy by using the Asana Audit Log activities |
For more information about creating policies, see Create a policy.
Automate governance controls
You can also automate Asana governance actions to fix detected threats. The following table lists the available actions:
| Type | Action |
|---|---|
| User governance | Notify user on alert (via Microsoft Entra ID) Require user to sign in again (via Microsoft Entra ID) Suspend user (via Microsoft Entra ID) |
For more information about remediating threats from apps, see Governing connected apps.
Connect Asana to Defender for Cloud Apps
Use the App Connector APIs to connect Microsoft Defender for Cloud Apps to your existing Asana account. The connection gives you visibility into and control over your organization's Asana use.
Prerequisites
Before you connect Asana, make sure you meet the following requirements:
- An Asana enterprise account.
- You must be signed-in as an admin to Asana.
Connect Asana
Collect the access token and workspace ID from Asana by completing the following steps.
Sign in to Asana with an admin account.
If you have an existing service account, you might need to select Reset and generate new token before continuing. Copy the service account token.
Copy the workspace ID from the URL and save it for future reference.
Configure Defender for Cloud Apps
After you collect the required Asana values, complete the connection in Microsoft Defender for Cloud Apps.
- In the Microsoft Defender portal, navigate to Settings > Cloud Apps > Connected apps > App Connectors.
- Select Connect an app and then select Asana.
- Enter an Instance name, and select Next.
- Enter the copied access token and workspace ID in API Key and workspace ID fields. Once entered select Submit.
- Defender for Cloud Apps will start to fetch Asana audit logs once the connection is successfully established.
Related content
- If you have any problems connecting the app, see Troubleshooting App Connectors.
- Detect cloud threats, compromised accounts, and malicious insiders
- Use the audit trail of activities for forensic investigations