In this article, you'll learn how to integrate Sophos endpoint security with Real-Time Coaching. Once the integration is complete, data from Sophos will be available under the Coaching tab of your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories. For general information about Real-Time Coaching, see our overview article.
Set Up the Integration in Sophos
To set up the Sophos integration with Real-Time Coaching, you'll first need to create Sophos API credentials by following the steps below:
- Log in to your Sophos console.
- From the left sidebar, navigate to Global Settings > API Credentials Management.
- Select Add Credential. An Add credential window will display
- In the Credential name field, enter a name for your integration, such as "KnowBe4 Integration".
- In the Description field, enter a description for your integration, such as "KnowBe4 Sophos Integration".
- In the Role drop-down menu, select Service Principal ReadOnly.
- Select Add. An API credential summary page will load.
- Copy and save your Client ID and Client Secret in a place you can easily access. You'll need these credentials to set up the integration in Real-Time Coaching.
Set Up the Integration in Real-Time Coaching
Once you've copied your API credentials from your Sophos account, you can set up the integration in Real-Time Coaching by following the steps below.
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Sophos vendor tile and select Configure > Direct Integration.
- Enter the Client ID and Client Secret that you saved earlier.
- Select Connect.
Map Your Users
Once Sophos is integrated, you can map your users with mapping rules or by uploading a CSV file. We recommend using mapping rules. For more information about user mapping, see our user mapping article.
Manage Detection Rules
Once you've successfully authorized this integration, you can also manage Sophos detection rules from Coaching > Detection Rules. For a full list of available system detection rules for this vendor, see our System Detection Rules by Vendor article.
Delete the Integration in Real-Time Coaching
If you want to delete the Sophos integration from Real-Time Coaching, follow these steps:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Sophos vendor tile and select Edit.
- Select Delete Integration near the bottom of the page.