Skip to main content

Controlling Scope Through Microsoft Entra

Vanta's Microsoft Entra integration enables you to control which employees are automatically marked in and out of scope in Vanta by managing Vanta O365 app assignments within Microsoft Entra.

Be sure to consult with Support and your auditor to validate the set of accounts that should and should not be managed by Vanta.


Prerequisites

  • Works with all Microsoft Entra ID plans. Assigning a group (rather than individual users) to the Vanta O365 app requires Microsoft Entra ID P1 or P2.

  • At least the Cloud Application Administrator role in Microsoft Entra to manage app assignments. (Connecting the integration itself requires Global Administrator; managing assignments afterward does not.)

  • Users to be synced must be User Type Member; User Type Guest will not sync.


Two ways to enable Entra-controlled scoping

You can turn on Entra-controlled scoping at two points:

  • During setup: when connecting Microsoft Entra, the Set sync filters step includes the checkbox Only sync selected users from Entra. Checking it means Vanta imports only the users assigned to the Vanta O365 app.

  • After connecting: from the Integrations page, select Configure Scope on the Microsoft Entra integration and enable the IdP scoping toggle (see Enable the feature in Vanta below).

⚠️ Note: Assign users to the Vanta O365 app before enabling scoping. If you enable the filter during setup before anyone is assigned to the app, your first sync will import no users. If in doubt, leave the setup checkbox unchecked, complete the assignment steps below, then enable scoping afterward.


Configure Entra app assignments

  • Search for Vanta O365 and select it. If more than one result appears, select the most recent.

  • Select Users and groups, then select Add user/group.

  • On the Add Assignment pane, choose the users (or group) you want Vanta to import, then select Assign.


Validate account assignments

  • Verify that the list of employees and groups assigned to the Vanta app reflects your desired scoping preferences.

  • Vanta recommends creating an automated provisioning process to assign the Vanta app to new employees, or at least ensuring that you have a documented process.


Enable the feature in Vanta

If you didn't enable scoping during setup:

  • Open the Integrations page and find the Microsoft Entra integration.

  • Select the three-dot menu.

  • Select Configure Scope.

  • Enable the Control scope with Office toggle.

  • Once this feature is enabled, all user scope is managed through Microsoft Entra, and the scoping toggle in Vanta is disabled. Vanta updates the scope status for IdP accounts on the next data fetch.


Using Entra groups for Vanta Workspaces

Please note, the steps below only apply to customers who are utilizing Vanta's Workspaces feature. If you do not have workspaces, this article section does not apply to you. If you are using Vanta Workspaces, you can create groups to scope in different sets of users for each Workspace.

  • Sign in to the Microsoft Entra admin center and go to Entra ID > Enterprise apps > All applications.

  • Open Vanta O365 and view the employees listed in Users and groups. To use the group scoping feature, the employees must first be assigned to the Vanta app.

  • Go to Entra ID > Groups and click New group to create the group you will use to scope users in and out of Vanta. The group name must include Vanta as a standalone word, capitalized. It does not need to start with Vanta. For example, Vanta Employees, Acme Corp Vanta, and Vanta-Contractors are all valid. Names where Vanta is joined to other characters, such as VantaEmployees or Vanta_Employees, will not be recognized.

  • Assign the group to the subset of employees in the Vanta O365 app that you want to scope in.

Once you finish creating the group, you can enable IdP scoping in Vanta. When you toggle IdP scoping, you'll have the option to select which group to scope by.

Once this feature is enabled, all user scope is managed through the selected Entra group, and the scoping toggle in Vanta is disabled. Vanta updates the scope status for IdP accounts on the next data fetch.

⚠️ Note: When Entra-controlled scoping is enabled, accounts who are removed from the Vanta application in Microsoft Entra will be marked as out of scope in Vanta, which may potentially also mark associated personnel as out of scope.

If your offboarding process removes accounts from the Vanta application assignment manually before deactivating or deleting the accounts, those accounts and associated personnel will no longer be visible in Vanta for audit review. To ensure terminated employees remain visible for compliance purposes, consider:

  • Keeping accounts belonging to terminated personnel assigned to the Vanta application in Microsoft Entra until audit evidence has been collected, and do not remove application assignment BEFORE deactivating or deleting the accounts.

  • Disabling Entra-controlled scoping and managing scope directly in Vanta (see How do I Mark Resources Out of Scope?).