Skip to content

Vanta integration not deactivating user accounts when removed from Fleet via SCIM #45371

@allenhouchins

Description

@allenhouchins

Fleet versions 4.84.0

  • Discovered: 4.84.0
  • Reproduced: 4.84.0

Web browser and operating system: Any


💥  Actual behavior

We recently released a feature that will remove admin accounts in Fleet when they are deactivated in their IdP. When this happens, that admin account is not getting marked as deactivated/disabled in Vanta. The only way to get an account to get marked as deactivated/disabled is by manually disabling it in Fleet (the old way) or by going into the integration and marking the account as an exception (not ideal for compliance). The old way is no longer possible since the account is already removed from Fleet.

🛠️ Expected behavior

TODO

🧑‍💻  Steps to reproduce

These steps:

  • Have been confirmed to consistently lead to reproduction in multiple Fleet instances.
  • Describe the workflow that led to the error, but have not yet been reproduced in multiple Fleet instances.
  1. Set up the Vanta integration and confirm accounts are in sync
  2. Set up SSO and SCIM in an IdP
  3. Disable an account in the IdP and observe the account is no longer in Fleet but is still active in Vanta

🕯️ More info (optional)

N/A

Metadata

Metadata

Assignees

No one assigned

    Labels

    :productProduct Design department (shows up on 🦢 Drafting board)bugSomething isn't working as documented

    Type

    No type

    Projects

    Status

    📨 Inbox

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions