Skip to main content

Connecting Vanta & Entra (Office 365)

✅ Feature availability: This integration is now available for Vanta Government customers.

Entra (Office 365) connects to Vanta using OAuth, allowing Vanta to import employees into Vanta seamlessly.

Prerequisites

  • 'Global Administrator' role in Microsoft Office365​

    • Global Administrator permissions are needed to fetch users. Only your users' primary domain email addresses will be imported to populate the Vanta People page.

  • If your organization uses Conditional Access for workload identities in Microsoft Entra (a premium feature that applies policies to service principals), ensure the Vanta Office 365 enterprise app is excluded from any blocking policies before connecting. See Conditional Access policies below for details.

Connecting Vanta & Entra (Office 365)

  • To connect, go to the Integrations page and search for Entra (Office 365). For help navigating the Integrations page, see Integrations Page.

  • Click Connect.

  • A pop-up modal will appear with additional details verifying your permissions if required.

  • When you are ready to connect, select Connect Office 365.

Screenshot 2024-06-14 at 3.50.15 PM.png

  • You will be redirected to the Microsoft login page. Log in to the account with 'Global Administrator' permissions. Vanta will request read-only permissions to access the specified resources for your organization.

  • Select Accept

Screenshot 2024-06-14 at 3.51.10 PM.png

  • Once Accepted, you'll be redirected back to Vanta.

  • You will be presented with the option to choose whether to have Office populate the people page when users are added.

Screenshot 2024-06-14 at 3.50.03 PM.png

💡Tip: If you want to adjust this setting after connection:

  • Go to Settings (gear icon), then scroll to the Features section.

  • Click on Personnel.

  • Select the Setup tab.

  • Review the integrations connected in the Personnel source section.

  • Here you can click Add another source to add another integration via the dropdown menu or edit and manage the integration via the three dots button.

  • If you have connected multiple identity providers, you will be prompted to Indicate which identity provider takes precedence for users in the connected IdPs.

Configure the Scope

Screenshot 2023-11-01 at 4.37.35 pm.png

  • You can configure scopes later by clicking Configure scope on the connected Entra (Office 365) card from the integrations page.

What to do if some users are not showing up in the Scope configuration

It may be that once connected, you are not seeing some or all of the users you expect to see in the Scope configuration. If that's the case, it is likely that this is due to the email field for this user not being populated in Entra. Please refer to this article on how to remedy that.

Conditional Access policies

Vanta's Office 365 integration authenticates using app-only (client credentials) authentication. No user sign-in is involved during background syncs. This means standard Conditional Access policies that target user sign-ins (such as requiring compliant devices or trusted network locations) do not typically affect the Vanta integration.

However, if your organization uses Conditional Access for workload identities (a Microsoft Entra ID Premium feature that applies policies to service principals and applications), those policies can block Vanta's background API calls. When this happens, the integration credentials are automatically disabled in Vanta and the connection will stop syncing.

If your integration credentials are being unexpectedly disabled:

  1. In the Microsoft Entra admin center, go to Protection > Conditional Access > Policies.

  2. Review any policies scoped to workload identities (service principals or applications).

  3. If a policy is blocking the Vanta enterprise app, add it as an exclusion under the policy's Target resources or Workload identities settings.

  4. Save the policy and reconnect the integration in Vanta.

If you're unsure whether a Conditional Access policy is causing the issue, work with your Microsoft administrator to review active policies targeting workload identities in your tenant.