Vanta - SSO configuration

Vanta - SSO configuration

Idea
This documentation has been tested and approved by Kelvin Zero's team
Quote
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Vanta using MPAS. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization.
Warning
To set up Multi-Pass with  Vanta, ensure you meet the following requirements:
- Vanta admin rights
- MPAS Admin rights
- Make sure that all users intended to use SSO in Vanta are registered in your IdP and have the necessary permissions to access Vanta.
Important: Custom elements in URLs (like realm names) are case sensitive. Make sure to match the exact casing from your environment.



Vanta - SSO configuration





Step 1 - Vanta Configuration

  1. Log into Vanta as an Administrator.
  2. Go to Settings, Select Login and Security
  3. Manually configure SAML.
  4. Copy the three URLs provided by Vanta
    1. SP Entity ID
    2. ACS URL
    3. SP Metadata URL
  5. Open the SP Metadata URL and save as XML (e.g., VantaMetadata.xml).
Vanta SAML Values
SP FieldValue
SP Entity IDhttps://vanta.com/sso/<TENANT_ID>/saml/metadata
Assertion Consumer Service (ACS) URLhttps://vanta.com/sso/<TENANT_ID>/saml/acs
SP Metadata URLhttps://vanta.com/sso/<TENANT_ID>/saml/metadata

Complete Vanta with IdP info (after Step 2)

  1. Return to Settings, Login and Security and Manually configure SAML.
  2. Under Identity Provider Configuration, click Edit configuration.
  3. Paste the Tenant XML Data URL from Multi-Pass into the URL field.
FieldValue
Tenant XML Data URL (IdP Metadata)https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/descriptor

Step 2 - Multi-Pass Configuration

Create the application from Vanta metadata

  1. Open Multi-Pass Dashboard
  2. Select your tenant
  1. Go to Integrations, click on Applications
  2. Choose SAML under Custom Integrations.
  1. Click Upload File and upload VantaMetadata.xml.
  1. Verify all fields are correctly populated
SAML — Form values (Multi-Pass) 
FieldValue
Client ID (= SP Entity ID)https://vanta.com/sso/<TENANT_ID>/saml/metadata
NameVanta
DescriptionSSO integration
Assertion Consumer Service (ACS) URLhttps://vanta.com/sso/<TENANT_ID>/saml/acs
NameID Policy Formatemail
  1. Click Download under Tenant XML data and save locally (its URL will be used in Vanta).
  2. then click Add Integration.
  3. Open Advanced Console (right panel)
  1. Click on clients and use the search bar to look for Vanta
  2. Find the Vanta client and verify the sections below.

General settings
FieldValue
Client IDhttps://vanta.com/sso/<TENANT_ID>/saml/metadata
NameVanta
DescriptionSSO integration
Always Display in UION
Access settings
FieldValue
Home URL (IdP-initiated)https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/Vanta
Valid Redirect URIs (ACS)https://vanta.com/sso/<TENANT_ID>/saml/acs
IDP-Initiated SSO URL NameVanta
SAML Capabilities
SettingValue
Force Name ID FormatON
Force POST BindingON
Include AuthnStatementON
Signature & Encryption
SettingValue
Sign DocumentsOFF
Sign AssertionsON

Step 3 — Testing (optional)

  1. In Vanta, create a test user.
  2. In Multi-Pass, create a test user with the same email.
  3. Attempt sign-in to Vanta via SSO and verify success.
    • Related Articles

    • SAML SSO Integration Guide

      This guide provides an overview of how to configure SAML Single Sign-On (SSO) between Multi-Pass and a third-party Service Provider (SP). Multi-Pass acts as the Identity Provider (IdP) in this federation model. Multi-Pass is working on SCIM support ...
    • Notion - SSO configuration

      Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a ...
    • Dynatrace - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Dynatrace using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • Addigy - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Addigy using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • ZoomInfo - SSO configuration

      Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a ...