In this article, you will learn how to integrate Cisco Secure Email, formerly Cisco Email Security Appliance (ESA), with Real-Time Coaching. Once you set up this integration, data from Cisco Secure Email will be available in the Coaching tab of your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories. For general information about Real-Time Coaching, see our overview article.
Set Up the Integration in Cisco Secure Email
Before you can set up this integration in Real-Time Coaching, you'll need to create an integration user role. Then, you'll need to create a user with this role. Finally, you'll need to locate your API domain.
Create a Secure Integration User Role
First, you'll need to create an integration user role in your Cisco account by following the steps below:
- Log in to your Cisco administrator account.
- Navigate to System Administration > User Roles.
- Select Add Email User Role….
- Fill out the fields on the Add Email User Role page. For more information about these fields, see below:
- Name: Enter “integration_role”.
- Email Reporting: Select the Access to data by Reporting Group option, then select All Reports from the drop-down menu.
- Message Tracking: Select the View Message Tracking option.
- Quarantines: Select the View Only Access option.
- Log Subscriptions: Select the Log Subscription Access option.
- Select Submit. Your new user role will display in the User Roles table.
- Select Commit Changes at the top-right corner of the page. A Commit Changes pop-up window will display.
- Optionally, enter a comment about the changes in the Comment (optional) field.
- Select Commit Changes again to create your new user role.
Create a Secure Email User
After you've created an integration role, you can create a user with this role in your Cisco account. You'll need this user's credentials later to complete the integration setup in Real-Time Coaching.
To create your Cisco Secure Email user, follow the steps below:
- Log in to your Cisco administrator account.
- Navigate to System Administration > Users.
- On the Users page, select Add User….
-
Fill out the fields on the Add Local User page. For more information about these fields, see the screenshot and list below:
-
User Name: Enter a username for the user. This username can only include lowercase letters, numbers, and dashes.
Note: Make sure to save this username somewhere you can access later. You'll need it to complete the integration setup in Real-Time Coaching. - Full Name: Enter a name for the user.
- User Role: Select the Custom Roles option and then select integration_role from the list.
- Confirm your Passphrase to make changes: Enter the password for the Cisco administrator account you are currently using.
-
Passphrase: Select either Generate a passphrase or Enter a passphrase of your choice. This will be the passphrase for the user’s account.
- Generate a passphrase: select Generate to generate the passphrase.
- Enter a passphrase of your choice: Create your own passphrase, then enter it in the Passphrase and Retype Passphrase fields.
Note:Make sure to save this passphrase somewhere you can access later. You'll need it to complete the integration setup in Real-Time Coaching.
-
- Select Submit. Your new user will display in the Users table.
- Select Commit Changes at the top-right corner of the page. A Commit Changes pop-up window will display.
- Optionally, enter a comment about the changes in the Comment (optional) field.
- Select Commit Changes again to create your new user.
Locate Your API Domain
To complete the integration in Cisco Secure Email, you'll also need to locate your API domain. This domain is displayed in the URL of your Cisco Secure Email account.
For example, in the image below, the API domain is “dh5802-sma1.iphmx.com”.
You'll need this API domain to complete the integration setup in Real-Time Coaching.
Set Up the Integration in Real-Time Coaching
Once you've created a user with an integration role in your Cisco account and located your API domain, you can set up the integration in Real-Time Coaching by following the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate Cisco Secure Email and select Configure.
- In the Username field, enter the username you created in Cisco Secure Email.
- In the Password field, enter the passphrase you generated or created in Cisco Secure Email.
- In the API Domain field, enter the API domain you located in Cisco Secure Email.
- Select Authorize.
Map Your Users
After you’ve finished integrating Cisco Secure Email, we recommend mapping your users using mapping rules or by uploading a CSV file. For more information, see our user mapping article.
Manage Detection Rules
Once you’ve successfully authorized this integration, you can also manage Cisco Secure Email detection rules from Coaching > Detection Rules. For a full list of available system detection rules for this vendor, see our System Detection Rules by Vendor article.
Delete the Integration in Real-Time Coaching
If you want to delete the Cisco Secure Email integration from Real-Time Coaching, follow these steps:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Cisco Secure Email vendor tile and select Edit.
- Select Delete Integration near the bottom of the page.

