✅ Feature availability: This integration is available for Vanta Government customers. Vanta Government customers currently see an earlier version of the connection flow; see Connecting from Vanta Government below.
Microsoft Entra connects to Vanta using OAuth, allowing Vanta to import your users, groups, directory roles, and the third-party applications consented in your tenant for access monitoring and vendor discovery.
Prerequisites
Works with all Microsoft Entra ID plans. Syncing sign-in activity and MFA registration data requires Microsoft Entra ID P1 or P2.
An account with the Global Administrator role in Microsoft Entra. Vanta reads your whole tenant, so only a Global Administrator can approve the connection.
During connection, Vanta requests the following read-only Microsoft Graph permissions:
User.Read.All(required): user profilesDirectory.Read.All(required): groups, group membership, directory roles, service principals, and app role assignmentsAuditLog.Read.All(optional): sign-in activity and MFA registration reports. If this permission isn't granted, the connection still succeeds and Vanta omits that data.
Only users with a primary domain email address populated in Entra will be imported to the Vanta People page.
If your organization uses Conditional Access for workload identities in Microsoft Entra (a premium feature that applies policies to service principals), ensure the Vanta enterprise app is excluded from any blocking policies before connecting. See Conditional Access policies below for details.
Explore the integrations page
When you navigate to the Microsoft Entra integration, you'll land on its listing page, which includes five tabs that cover what you need to know before (and after) you connect.
When you navigate to the Microsoft Entra integration, you'll land on its listing page, which includes five tabs that cover what you need to know before (and after) you connect.
Overview — Start here. A summary of what the integration does, its top capabilities, and the prerequisites you'll need in place before connecting. When you're ready, select Connect to begin setup.
API permissions — Exactly what access Vanta requests from Microsoft Entra: each permission's scope, whether it's read or write, and what data it covers, etc. Share this tab with your security team if they need to review access before you connect.
Resource types — Every resource type Vanta imports from Entra, down to the specific fields collected for each. Use this to understand exactly what data will show up in Vanta once connected.
Automated tests — How many tests connecting Entra unlocks and which frameworks and controls they map to (SOC 2, ISO 27001, etc.), plus the full list of tests by name. Useful for scoping compliance coverage ahead of an audit.
Security — How Vanta protects the data it collects — encryption, data retention, access controls, and infrastructure. Visit Vanta's Trust Center for the full picture.
When you're ready to connect, continue reading below to the setup guide.
Setup guide
In Vanta, go to the Integrations page and click Add integration. Search for Microsoft Entra. For help navigating the Integrations page, see this guide.
Click the integration tile and then click Connect.
In the setup wizard, click Connect again. You will be redirected to the Microsoft login page.
Sign in with your Global Administrator account. Microsoft shows the read-only access Vanta requests. Review it and click Accept.
You'll be redirected back to Vanta. Vanta validates that it can read users, groups, directory roles, and service principals in your tenant. If any of these can't be read (for example, due to insufficient permissions or a Conditional Access policy blocking the request), the connection attempt fails. Resolve the permission or policy issue (see Conditional Access policies), then try connecting again.
On the Set sync filters step, choose what Vanta syncs from Entra:
Leave Only sync selected users from Entra unchecked to sync your whole directory. You then choose which users appear on the People page and in audit scope from within Vanta.
Check Only sync selected users from Entra to decide in Entra which users Vanta syncs. Vanta imports only the users assigned to the Vanta O365 app in your directory. You can narrow this further with a scoping group after connecting. See Controlling Scope Through Microsoft Entra for the assignment steps.
⚠️ Before you enable this filter: assign users to the Vanta O365 app in Entra first. If you enable the filter before anyone is assigned to the app, your first sync will import no users. If you haven't set up app assignments yet, leave the box unchecked; you can turn the filter on any time after connecting.
Click Save. Setup completes, Vanta shows the connection confirmation, and your first sync begins using the filter choice you made.
If you have connected multiple identity providers, you will be prompted to indicate which identity provider takes precedence for users in the connected IdPs. See Integrating Multiple Identity Providers for more information.
💡Tip: You can change your sync filter choice any time after connecting:
Go to Settings (gear icon), then scroll to the Features section.
Click on Personnel.
Select the Setup tab.
Review the integrations connected in the Personnel source section.
Use the three dots button to manage the integration, or Configure scope to change how users are scoped.
Here you can click Add another source to add another integration via the dropdown menu or edit and manage the integration via the three dots button.
Configure the Scope
Establish which Microsoft Entra items should be marked in or out of scope for your audit. To learn more about controlling scope, see Controlling Scope Through Microsoft Entra.
You can configure scope later by selecting the three-dot menu and then selecting Configure scope on the connected Microsoft Entra card from the Integrations page.
What to do if some users are not showing up in the Scope configuration
It may be that once connected, you are not seeing some or all of the users you expect in the Scope configuration. This is likely because the email field for the user is not populated in Entra. Please refer to this article on how to remedy that.
Conditional Access policies
Vanta's Office 365 integration authenticates using app-only (client credentials) authentication. No user sign-in is involved during background syncs. This means standard Conditional Access policies that target user sign-ins (such as requiring compliant devices or trusted network locations) do not typically affect the Vanta integration.
However, if your organization uses Conditional Access for workload identities (a Microsoft Entra ID Premium feature that applies policies to service principals and applications), those policies can block Vanta's background API calls. When this happens, the integration credentials are automatically disabled in Vanta and the connection will stop syncing.
If your integration credentials are being unexpectedly disabled:
In the Microsoft Entra admin center, go to Protection > Conditional Access > Policies.
Review any policies scoped to workload identities (service principals or applications).
If a policy is blocking the Vanta enterprise app, add it as an exclusion under the policy's Target resources or Workload identities settings.
Save the policy and reconnect the integration in Vanta.
If you're unsure whether a Conditional Access policy is causing the issue, work with your Microsoft administrator to review active policies targeting workload identities in your tenant.
Connecting from Vanta Government
Vanta Government customers currently connect using the earlier flow:
On the Integrations page, click Connect on the integration card.
A modal asks whether to create personnel records from Office accounts. Toggle this on or off and click Continue.
Click Connect Office 365, sign in with your Global Administrator account, and click Accept.
After connecting, you can choose whether the integration populates the People page as users are added.





