Skip to main content

Platform compatibility

Data flow: one-wayPrimo pushes to the Vanta API. Vanta sends nothing back, so no Vanta data appears in the dashboard.
This article covers what Primo sends, how the sync behaves, and how to connect or reconnect the integration. What Vanta does with the data once it arrives is documented by Vanta. For Primo’s own device compliance monitoring, which is unrelated to this integration, see Compliance overview.

Prerequisites

  • A Primo MDM plan. The Identity & Access Management module is not required.
  • A Vanta administrator account. Administrator level is required to authorize the integration.

Connect Vanta

1

Open the integration

Go to Settings > Integrations, then open Vanta in the Compliance section.
2

Authorize the connection

You are redirected to Vanta. Authorize the connection there.
3

Grant access

Vanta then asks you to grant access. Confirm, and you are returned to the integration page, which now shows Disconnect.

What Primo sends

Primo sends three types of resources.
  • Primo admin accounts — administrators only. Employees who are not administrators are not included.
  • macOS devices
  • Windows devices

Admin account fields

  • Display name and full name
  • Email address
  • Creation date
  • Authentication methodSSO or password
  • Multi-factor authentication (MFA) — whether MFA is enabled, and the methods in use: OTP, SMS, or disabled
  • Permission level

Device fields

macOS and Windows devices are sent with the same fields, except where the Notes column says otherwise.

How the computed fields are derived

Some fields come from the MDM controls targeting the device rather than from the device itself. A control that does not target the device has no effect on the values sent for it.
  • MDM management state — Sent as managed when the device is enrolled and active in the MDM: automatic enrollment, company-owned device enrollment, or manual enrollment. Every other state — enrollment disabled, pending, or unknown — is sent as unmanaged. This is unrelated to whether the device is company-owned.
  • Automatic updates — Sent as enabled when an OS update control carrying an update deadline targets the device. This follows the control targeting each device, not a company-wide setting. See Enforce OS updates.
  • Screen lock policy — Derived from the password policy MDM controls on macOS and Windows. Without the Password and screenlock control configured, no policy is sent.
  • Minimum password length — Taken from the password policy control targeting the device. When no password policy control targets it, the field is left out of the push rather than filled with a default.

What Primo does not send

The integration covers admin accounts and devices. Everything below stays in Primo.
  • Employees who are not Primo administrators. The integration carries no personnel directory and no onboarding, mobility, or offboarding events.
  • SaaS application accounts and access rights.
  • Endpoint protection data. SentinelOne and ThreatDown data is present in Primo but is not sent. The device fields above cover whether a malware protection control targets a macOS device, not the data those tools collect.
  • Firewall status.
  • Linux devices, and iPhone, iPad, and Android devices. The Vanta API accepts macOS and Windows only.
  • Devices absent from the agent inventory. Without the agent installed, a device is never sent.

How the sync runs

  • Primo pushes once an hour.
  • Every push contains the complete current state of your fleet, not the changes since the last push.
  • Because each push is a full state, an interruption fixes itself. If Vanta stops accepting data for a while, the next hourly push resends the whole fleet and brings Vanta up to date. There is nothing to reconnect and nothing for you to do.
There is no manual resync action, and the dashboard does not show a last-sync date.

Disconnect or reconnect

The integration page shows one action, depending on the state of the connection.
  • Disconnect — shown while the connection is active. Disconnecting stops the hourly push.
  • Reconnect — shown once the connection has been interrupted. Reconnecting takes you back through the same two Vanta prompts and restores the authorization.

Troubleshooting

Vanta stopped receiving data, but the fleet is managed in Primo
  • Open Settings > Integrations > Vanta. If the page offers Reconnect, the authorization was interrupted.
  • Disconnect, then reconnect. That restores the authorization.
A device is missing in Vanta
  • Check its platform. Linux, iPhone, iPad, and Android devices are never sent.
  • Check that the agent is installed. Devices absent from the agent inventory are not sent.
  • Wait for the next hourly push before looking further. Each push resends the whole fleet.
A device has no owner in Vanta
  • Assign an owner to the device in Primo. The owner email address is omitted from the push when the device has no owner.