Skip to main content

Connecting Vanta & CyberArk

J
Written by Jaquez Hodo
Updated this week

Vanta integrates with CyberArk to sync employee and group data, helping you automate onboarding and offboarding workflows. By pulling real-time identity information, Vanta ensures only current employees retain access to company systems. This simplifies access reviews and supports your compliance requirements.

Estimated setup time: Less than 15 minutes

How It Works

Vanta integrates with CyberArk to sync employee and group data, helping you monitor access and support automated onboarding and offboarding workflows. By pulling real-time identity information, Vanta helps ensure that only current employees retain access to company systems simplifying access reviews and supporting compliance requirements.

Please Note: Vanta connects to CyberArk through Merge.dev, a third-party integration platform. Merge securely pulls employees and groups from CyberArk into Vanta.

Use Cases

Connecting CyberArk to Vanta will enable you to:

  • Sync employees and groups from CyberArk into Vanta

  • Monitor and manage personnel access in real time

  • Ensure only active employees retain access to company systems

  • Simplify access reviews and compliance requirements

Requirements

  • CyberArk administrator account

  • Vanta administrator account

Install the Integration

Log in to the CyberArk Admin Portal via your organization’s tenant URL.

Switch to the Admin Portal view by clicking the grid symbol next to Identity User Portal and selecting Admin Portal.

Navigate to Core Services > Roles.

  • Select Add Role in the top left corner.

  • Name your role SCIM Client and click Save. You’ll be redirected to the new role’s settings page.

  • Under Administrative Rights, click Add, search for and select User Management, then click Save.

Please note: Select User Management, not Read Only User Management.

Navigate to Apps & Widgets > Web Apps.

  • Click Add Web Apps in the top right corner.

  • On the Custom tab, next to OAuth2 Client, click Add.

  • In the Add Web App screen, click Yes to add the application.

  • Click Close to return to the OAuth2 client configuration screen.

On the Settings page, complete the following field:

  • Application ID: Any value (for example, scim_oauth_client). This ID is required during the Vanta linking flow.

On the General Usage page, select:

  • Client ID Type: Check both Confidential and Must be OAuth Client.

On the Scope page, click Add and create a new scope:

  • Name: SCIMAPIScope

  • Allowed REST APIs: Add scim (exact text required).

Navigate to Core Services > Users.

  • Select Add User in the top right corner. Complete the following fields:

    • Login name: This value + @merge becomes your username and Client ID

    • Display name: Any value you choose

    • Password: This becomes your password and Client Secret

  • Check Is OAuth confidential client under Status. The email field will gray out, and Is Service User will auto-check

Return to Core Services > Roles and open the SCIM Client role.

  • Under Members, click Add, and add your newly created user. Select Save.

In Vanta, start the CyberArk linking flow by clicking CyberArk on the integrations page.

Enter the following:

  • The tenant URL you use to log into CyberArk

  • The Application ID you created

  • Your Client ID and Client Secret/Password

Please note: Employees will appear in Vanta within 30 minutes.

Permissions

Vanta accesses the following data from CyberArk:

Vanta will be able to view:

  • Data about your users

  • Data about your employees

Vanta will be able to do:

  • Vanta does not have write permission