Skip to main content

Controlling Scope Through Entra (Office 365)

Vanta's Entra (Office 365) integration enables you to control which employees should be automatically marked in and out of scope in Vanta by creating and managing the Vanta O365 app assignments within Microsoft Entra.

Be sure to consult with Support and your auditor to validate the set of accounts that should and should not be managed by Vanta.

Prerequisites

Configure Office

  • Login to Azure and navigate to the Enterprise applications page to find the "Vanta O365 Integration" app:

  • Search for Vanta O365. If you have multiple, choose the one that is the most recent and click on it:

  • You will be taken to the App Overview page. Click Users and Groups.

  • Click Add user/group.

  • Select the employees or group you want to assign the Vanta O365 app.

Validate account assignments

  • Verify that the list of employees and groups that are assigned to the Vanta app reflects your desired scoping preferences.

  • Vanta recommends creating an automated provisioning process to assign the Vanta app to new employees or at least ensuring that you have developed a process.

Enable the feature in Vanta

  • Open the Integrations page and find the Entra (Office 365) integration

  • Select Configure Scope

  • Enable the IdP scoping toggle

  • Once this feature is enabled, all user scope will be managed through Microsoft Entra ID, and the scoping toggle in Vanta will be disabled. Vanta will update the scope status for IdP accounts on the next data fetch.

Using Office for Vanta Workspaces

Please note, the steps below only apply to customers who are utilizing Vanta's Workspaces feature. If you do not have workspaces, this article section does not apply to you. If you are using Vanta Workspaces, you can create groups to scope in different sets of users for each Workspace.

  • Login to Azure and navigate to Enterprise applications.

  • Click on Vanta O365 Integration and view the employees listed in Users and groups. To use the group scoping feature, the employees must first be assigned to the Vanta app.

  • Then, navigate to Azure Active Directory > Groups in the sidebar.

  • Click New group to create a group that you will use to scope users in and out of Vanta. The group name must include Vanta as a standalone word, capitalized. It does not need to start with Vanta. For example, Vanta Employees, Acme Corp Vanta, and Vanta-Contractors are all valid. Names where Vanta is joined to other characters, such as VantaEmployees or Vanta_Employees, will not be recognized.

  • Assign the group to the subset of employees and groups in the Vanta O365 Integration app that you want to scope in.

Once you finish creating the group, you can enable IdP scoping in Vanta. When you toggle IdP scoping, you’ll have the option to select what group to scope by.

Once this feature is enabled, all user scope will be managed through the selected Azure group, and the scoping toggle in Vanta will be disabled. Vanta will update the scope status for IdP accounts on the next data fetch.

⚠️ Note: When Control scope with Office is enabled, accounts who are removed from the Vanta application in Entra (Office 365) will be marked as out of scope in Vanta, which may potentially also mark associated personnel as out of scope.

If your offboarding process removes accounts from the Vanta application assignment manually before deactivating or deleting the accounts, those accounts and associated personnel will no longer be visible in Vanta for audit review. To ensure terminated employees remain visible for compliance purposes, consider:

  • Keeping accounts belonging to terminated personnel assigned to the Vanta application in Entra (Office 365) until audit evidence has been collected, and do not remove application assignment BEFORE deactivating or deleting the accounts.

  • Disabling Control scope with Office and managing scope directly in Vanta and managing scope directly in Vanta (see How do I Mark Resources Out of Scope?).