Skip to main content

Connecting Vanta & Microsoft Entra (GCC High)

Lizzie avatar
Written by Lizzie
Updated yesterday

Automatically provision and deprovision users in Vanta using Microsoft Entra ID (Azure AD) in the GCC High environment. This integration enables continuous synchronization of users, groups, and vendor applications between Entra ID (GCC High) and Vanta.

How it works

The Microsoft Entra ID (GCC High) integration uses the Microsoft Graph API to synchronize users, groups, and vendor applications from your Entra ID (GCC High) tenant into Vanta.

The integration leverages OAuth 2.0 authentication with admin consent to securely access your Entra ID (GCC High) directory. Once connected:

  • New users are automatically provisioned in Vanta

  • Departing users are automatically deprovisioned

  • Groups and group memberships remain continuously synchronized

  • Vendor applications assigned through app roles are synced into Vanta

This connection enables rapid deployment of Vanta across your organization while ensuring your directory data remains aligned with your Entra ID (GCC High) environment.

Data syncs automatically on a recurring schedule to keep user, group, and vendor application information up to date.

Use cases

  • Provision Vanta access to all employees: Grant access to Vanta in just a few clicks and maintain continuous synchronization with your Entra ID (GCC High) directory.

  • Synchronize key employee attributes: Seamlessly sync employee details such as name, email, title, manager, MFA status, and login activity from Entra ID (GCC High) into Vanta.

  • Track third-party vendor applications: Automatically identify applications users access through app role assignments in Entra ID (GCC High), ensuring comprehensive visibility into your organization’s third-party tools.

  • Sync groups and group memberships: Maintain an up-to-date view of your organization’s access structure and group-based permissions.

  • Route procurement approvals to managers: Streamline approval workflows by automatically assigning procurement approval steps to an employee’s manager.

Requirements

To install and configure the Microsoft Entra ID (GCC High) integration, you must:

  • Be a Vanta Administrator

  • Be a Microsoft Entra ID (GCC High) administrator with permission to grant admin consent in your tenant

Connect the integration

  • Navigate to Vanta and then select All Integrations, then look for the Microsoft Entra (GCC High) integration under Identity providers

  • Select View Details and click Connect

  • You will be redirected to the Microsoft authorization flow. Sign in with your Entra ID GCC High admin account

  • Review and accept the permissions requested by Vanta.

  • You will be redirected back to Vanta. The integration is now connected.

Permissions

The Microsoft Entra ID (GCC High) integration provides read-only access to your directory. Vanta does not create, modify, or delete any data within your Entra ID (GCC High) tenant.

Data access scope

Vanta can access the following data:

  • Audit log data — Used to determine which users have multi-factor authentication (MFA) enabled

  • Directory data — Used to sync users, groups, group memberships, admin roles, and vendor applications

  • User and group profile photos — Displayed within Vanta

  • User profile attributes — Including name, email, title, manager, and login activity

Vanta does not update or write any data back to Entra ID (GCC High).

Related articles