This Knowledge Base article provides the app registrations and permissions that are required to ensure seamless integration between the Defend console and your email infrastructure.
During deployment, admins must agree to grant permissions to link to Microsoft 365 app registrations in the Defend console Settings page. Some new features may require a relink. You can do this from the Settings page in Defend.
For new installations, Defend uses a single app registration, KnowBe4 Collaboration Security, which replaces the separate User Analysis and Admin Features app registrations below. For older deployments, you can migrate to a single app registration within your settings page.
| App registration | Permissions | Justification |
|---|---|---|
| User analysis |
| Establishes an understanding of users and groups in an organization and analyses their historical email to improve efficacy. |
| Admin Features |
| Enables admins to view emails in the Defend portal and remediate dangerous phishing emails from inboxes. |
|
| Establishes an understanding of users and groups in an organization and analyzes their historical email to improve efficacy. Enables admins to view emails in the Defend portal and remediate dangerous phishing emails from inboxes. |
| KnowBe4 Collaboration Security |
|
|