In this article, you will learn how to integrate Microsoft 365 and Microsoft Defender for Cloud Apps, formerly Microsoft Cloud App Security (MCAS), with Real-Time Coaching. Once the integration is complete, data from Microsoft will be available under the Coaching tab in your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories.
For more information about Real-Time Coaching, see our overview article. To integrate other Microsoft products with Real-Time Coaching, see our Setting Up Integrations articles.
Prerequisites
To ensure a successful integration with Real-Time Coaching, certain license bundles are required for each Microsoft product integration. For more information, see the subsections below.
Microsoft 365
One of the following Microsoft license bundles is required to ensure a successful Microsoft 365 integration:
- Microsoft 365 E5 with the Microsoft 365 E5 Security and Microsoft 365 E5 Compliance add-ons
- Microsoft Enterprise Mobility with the Microsoft 365 E5 Security add-on
- Microsoft Office 365 E5
For more information, see Microsoft’s Defender XDR licensing requirements.
Microsoft Defender for Cloud Apps
One of the following Microsoft license bundles is required to ensure a successful Microsoft Defender for Cloud Apps integration:
- Microsoft 365 E5 with the Microsoft E5 Security add-on
- Windows 11 Enterprise E5
For more information, see Microsoft’s Defender XDR licensing requirements.
Set Up the Integration in Microsoft Azure
Before you can set up the Real-Time Coaching integration, you'll need to register the Real-Time Coaching application, add API permissions, create a client secret, and locate your application ID and primary domain in your Microsoft Azure portal. For more information, see the subsections below.
Register the Real-Time Coaching Application
First, you'll need to register the Real-Time Coaching application in your Microsoft Azure portal. To register the application, follow the steps below:
- Log in to your Microsoft Azure portal.
- Navigate to Microsoft Entra ID.
- In the sidebar on the left side of the page, navigate to Manage > App registrations.
- Select + New registration. A Register an application page will display.
- In the Name field, enter your preferred name for the application, such as “CoachingAPIAccess”.
- Select Register.
Add API Permissions
After you have registered the Real-Time Coaching application, you can add API permissions by following the steps below:
- Log in to your Microsoft Azure portal.
- Navigate to Microsoft Entra ID.
- In the sidebar on the left side of the page, navigate to Manage > App registrations.
- Select the name of the application you registered earlier.
- From the sidebar on the left side of the page, select API permissions.
-
Select + Add a permission.
- From the Microsoft APIs subtab, select Microsoft Graph.
- Select Application permissions.
- Select the SecurityAlert drop-down menu, then enable the SecurityAlert.Read.All check box.
- Select Add permissions.
-
Select Grant admin consent for [your active directory name]. Once permission is granted, the triangle symbol on the right side of the page will change to a green check mark.
Create a Client Secret
After you have registered the Real-Time Coaching application and added API permissions, you can create a client secret. To create a client secret, follow the steps below:
- Log in to your Microsoft Azure portal.
- Navigate to Microsoft Entra ID.
- In the sidebar on the left side of the page, navigate to Manage > App registrations.
- Select the name of the application you registered earlier. An application overview page will display.
- From the sidebar on the left side of the page, select Certificates & secrets.
- In the Client secrets section, select + New client secret.
- In the Description field, enter a description for the client secret.
- In the Expires field, select an expiry window.
-
Select Add. The client secret Value and Expires date will now display in the Client secrets section.
- Copy and save the client secret Value and the Expires date somewhere that you can easily access. You'll need these credentials to set up the integration in Real-Time Coaching.
Locate Your Application (Client) ID and Primary Domain
Finally, you'll need to locate your Application (Client) ID and Primary Domain by following the steps below:
- Log in to your Microsoft Azure portal.
- Navigate to Microsoft Entra ID.
- In the sidebar on the left side of the page, navigate to Overview. An Overview page will display.
- In the Tenant Information section, copy and save the Primary domain somewhere that you can easily access. You'll need the domain to set up the integration in Real-Time Coaching.
- Return to your Microsoft Azure portal, then select App registrations.
- Select the name of the application you registered earlier. An application overview page will open.
- In the Essentials section, copy and save the Application (client) ID somewhere you can easily access it. You'll need the ID to set up the integration in Real-Time Coaching.
Set Up the Integration in Real-Time Coaching
Once you've set up the integration in your Microsoft Azure portal, you can set up the integration in Real-Time Coaching by following the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the vendor tile for the Microsoft application you want to set up. At the bottom of the vendor tile, select Configure.
- Enter the Application (Client) ID, Primary Domain, Client Secret Value, and Token Expiration Date you saved earlier.
- Select Connect.
Map Your Users
After you’ve finished integrating your Microsoft service, we recommend mapping your users using mapping rules or by uploading a CSV file. For more information, see our user mapping article.
Manage Detection Rules
Once you’ve successfully authorized this integration, you can also manage Microsoft detection rules from Coaching > Detection Rules. For a full list of available system detection rules for this vendor, see our System Detection Rules by Vendor article.
Delete the Integration in Real-Time Coaching
If you want to delete a Microsoft integration from Real-Time Coaching, follow these steps:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Microsoft vendor tile you want to delete and select Edit.
- Select Delete Integration near the bottom of the page.


