In this article, you will learn how to integrate Gmail, Google Drive, and Google IAM with Real-Time Coaching. Once you set up this integration, data from Google will be available in the Coaching tab of your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories. For general information about Real-Time Coaching, see our product overview.
Set Up the Integration in Google Cloud
To set up an integration in your Google Cloud Platform, you'll first need to create a project and enable the required APIs. You'll also need to create a service account, then obtain a JSON file and a unique ID from it. For more information, see the article subsections below.
Create a Project
To create a project in your Google Cloud platform, follow the steps below:
- Log in to your Google Cloud platform. If this is your first time logging in to the Google Cloud platform, a Google Cloud pop-up window will appear. Review the terms of service, then select Agree and continue.
- Use the search bar near the top of the page to search for “IAM & Admin Create a Project”. From the drop-down menu, select Create a Project. A New Project page will open.
- In the Project name field, enter “KB4VendorIntegration”. The Organization and Location fields will automatically fill in.
- Select Create.
Enable APIs for Your Project
To enable APIs for the project you created earlier, follow the steps below:
- Log in to your Google Cloud platform.
- At the top of the page, select the drop-down arrow, then select KB4VendorIntegration as the current project.
- Use the search bar at the top of the page to search for “APIs & Services Library”. From the drop-down menu, select Library.
- Use the API Library search bar to search for “Admin SDK API”.
- Select Admin SDK API. An Admin SDK API page will display.
- Select Enable.
Create a Service Account
To create a service account in your Google Cloud platform, follow the steps below:
- Log in to your Google Cloud platform.
- At the top of the page, select the drop-down arrow, then select KB4VendorIntegration as the current project.
- Use the search bar at the top of the page to search for “IAM & Admin Service Accounts”. From the drop-down menu, select Service Accounts.
-
Select the + Create Service Account.
- In the Service account name field, enter a name for your new service account. We recommend “KB4[YourOrganization]GSuiteServiceAcc”, with “[YourOrganization]” being your organization’s name.
- In the Service account description field, enter “This is the service account for integration with KnowBe4”.
- Select Create And Continue.
- Select the Role drop-down menu, then select Basic > Viewer.
- Select Continue.
- Skip the Grant users access to this service account section, then select Done.
Obtain Your Service Account JSON File and Unique ID
After you have created your service account, you'll need to obtain your service account JSON file and unique ID by following the steps below:
- Log in to your Google Cloud platform.
- At the top of the page, select the drop-down arrow, then select KB4VendorIntegration as the current project.
- Use the search bar near the top of the page to search for “IAM & Admin Service Account”. From the drop-down menu below the search bar, select Service Accounts.
- In the Email column, select the name of the service account. The service account’s Details page will display.
- Locate the Unique ID field, then copy and save it to a place that you can easily access later. You'll need this ID to assign domain-wide delegation and scopes.
- Next, to obtain the JSON file, select the Keys tab near the top of the page.
- Select Add Key, then select Create new key from the drop-down menu. A Create private key pop-up window will display.
- In the Key type section, select JSON, then select Create. The JSON file will automatically download to your device, and the private key will be saved in the service account's Keys tab. You'll need this JSON file to set up the integration in Real-Time Coaching.
Set Up the Integration in Real-Time Coaching
Once you've set up the integration in your Google Cloud platform, you can set up the integration in Real-Time Coaching by following the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- In the Available Integrations section, locate the vendor tile for the Google integration you want to set up.
- At the bottom of the vendor tile, select Configure.
- In the Admin Email field, enter your Google Workspace admin email address.
- In the Credentials File field, select Browse, then select the JSON file you saved earlier.
- Select Connect.
Assign Domain-Wide Delegation and Scopes in Google Cloud
After you have set up the integration in your Google Cloud Platform and in Real-Time Coaching, you'll need to assign domain-wide delegation and scopes by following the steps below:
- Log in to admin.google.com using your admin account.
- Use the search bar near the top of the page to search for “Security Access and data control API controls”. From the drop-down menu, select API controls.
-
From the sidebar on the right side of the page, look for the Domain wide delegation section, then select Manage Domain Wide Delegation.
- Select Add new. An Add a new client window will display.
- In the Client ID field, enter the service account ID you saved earlier.
- In the OAuth scopes (comma-delimited) field, enter “https://www.googleapis.com/auth/admin.reports.audit.readonly”.
- Select Authorize.
Map Your Users
After you’ve finished integrating your Google Cloud Platform, we recommend mapping your users using mapping rules or by uploading a CSV file. For more information, see our user mapping article.
Manage Detection Rules
Once you’ve successfully authorized this integration, you can also manage Google detection rules from Coaching > Detection Rules. For a full list of available system detection rules for this vendor, see our System Detection Rules by Vendor article.
Delete the Integration in Real-Time Coaching
If you want to delete a Google integration from Real-Time Coaching, follow these steps:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Google vendor tile you want to delete and select Edit.
- Select Delete Integration near the bottom of the page.

