Automatically provision and deprovision users in Vanta using Microsoft Entra ID (Azure AD) in the GCC High environment. This integration enables continuous synchronization of users, groups, and vendor applications between Entra ID (GCC High) and Vanta.
How it works
The Microsoft Entra ID (GCC High) integration uses the Microsoft Graph API to synchronize users, groups, and vendor applications from your Entra ID (GCC High) tenant into Vanta.
The integration leverages OAuth 2.0 authentication with admin consent to securely access your Entra ID (GCC High) directory. Once connected:
New users are automatically provisioned in Vanta
Departing users are automatically deprovisioned
Groups and group memberships remain continuously synchronized
Vendor applications assigned through app roles are synced into Vanta
This connection enables rapid deployment of Vanta across your organization while ensuring your directory data remains aligned with your Entra ID (GCC High) environment.
Data syncs automatically on a recurring schedule to keep user, group, and vendor application information up to date.
Use cases
Provision Vanta access to all employees: Grant access to Vanta in just a few clicks and maintain continuous synchronization with your Entra ID (GCC High) directory.
Synchronize key employee attributes: Seamlessly sync employee details such as name, email, title, manager, MFA status, and login activity from Entra ID (GCC High) into Vanta.
Track third-party vendor applications: Automatically identify applications users access through app role assignments in Entra ID (GCC High), ensuring comprehensive visibility into your organization’s third-party tools.
Sync groups and group memberships: Maintain an up-to-date view of your organization’s access structure and group-based permissions.
Route procurement approvals to managers: Streamline approval workflows by automatically assigning procurement approval steps to an employee’s manager.
Requirements
To install and configure the Microsoft Entra ID (GCC High) integration, you must:
Be a Vanta Administrator
Be a Microsoft Entra ID (GCC High) administrator with permission to grant admin consent in your tenant
Connect the integration
Navigate to Vanta and then select All Integrations, then look for the Microsoft Entra (GCC High) integration under Identity providers
Select View Details and click Connect
You will be redirected to the Microsoft authorization flow. Sign in with your Entra ID GCC High admin account
Review and accept the permissions requested by Vanta.
You will be redirected back to Vanta. The integration is now connected.
Permissions
The Microsoft Entra ID (GCC High) integration provides read-only access to your directory. Vanta does not create, modify, or delete any data within your Entra ID (GCC High) tenant.
Data access scope
Vanta can access the following data:
Audit log data — Used to determine which users have multi-factor authentication (MFA) enabled
Directory data — Used to sync users, groups, group memberships, admin roles, and vendor applications
User and group profile photos — Displayed within Vanta
User profile attributes — Including name, email, title, manager, and login activity
Vanta does not update or write any data back to Entra ID (GCC High).
