In this article, you will learn how to integrate Microsoft Defender for Endpoint, formerly Microsoft Defender ATP, with Real-Time Coaching. Once you set up this integration, data from Microsoft Defender for Endpoint will be available in the Coaching tab of your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories.
For general information about Real-Time Coaching, see our overview article. If you would like to learn how to integrate other Microsoft products with Real-Time Coaching, see the vendor integration guides in our Knowledge Base.
Prerequisites
One of the following Microsoft license bundles is required to ensure a successful Microsoft Defender for Endpoint integration:
- Microsoft 365 E5 with the Microsoft 365 E5 Security add-on
- Windows 11 Enterprise E5
For more information, see Microsoft’s Defender XDR licensing requirements.
Set Up the Integration in Microsoft Azure
Before you can set up the Real-Time Coaching integration, you'll need to register the Real-Time Coaching application, add API permissions, create a client secret, and locate your application ID and primary domain in your Microsoft Azure portal. For more information, see the subsections below.
Register the Real-Time Coaching Application
First, you'll need to register the Real-Time Coaching application in your Microsoft Azure portal. To register the application, follow the steps below:
- Log in to your Microsoft Azure portal.
- Navigate to Microsoft Entra ID.
- In the sidebar on the left side of the page, navigate to Manage > App registrations.
- Select + New registration. A Register an application page will display.
- In the Name field, enter your preferred name for the application, such as “KB4-DefenderATPAPP”.
- Select Register.
Add API Permissions
After you have registered the Real-Time Coaching application, you can add API permissions by following the steps below:
- Log in to your Microsoft Azure portal.
- Navigate to Microsoft Entra ID.
- In the sidebar on the left side of the page, navigate to Manage > App registrations.
- Select the name of the application you registered earlier.
- From the sidebar on the left side of the page, select API permissions.
-
Select + Add a permission.
- In the APIs my Organization uses subtab, use the searchbar to search for “windowsdefender”, then select WindowsDefenderATP.
- Select Application permissions.
- Select the Alert drop-down menu, then enable the Alert.Read.All check box.
-
Select Grant admin consent for [your active directory name]. Once permission is granted, the triangle symbol on the right side of the page will change to a green check mark.
Create a Client Secret
After you have registered the Real-Time Coaching application and added API permissions, you can create a client secret. To create a client secret, follow the steps below:
- Log in to your Microsoft Azure portal.
- Navigate to Microsoft Entra ID.
- In the sidebar on the left side of the page, navigate to Manage > App registrations.
- Select the name of the application you registered earlier. An application overview page will display.
- From the sidebar on the left side of the page, select Certificates & secrets.
- In the Client secrets section, select + New client secret.
- In the Description field, enter a description for the client secret.
- In the Expires field, select an expiry window.
-
Select Add. The client secret Value and Expires date will now display in the Client secrets section.
- Copy and save the client secret Value and the Expires date somewhere that you can easily access. You'll need these credentials to set up the integration in Real-Time Coaching.
Locate Your Application (Client) ID and Primary Domain
Finally, you'll need to locate your Application (Client) ID and Primary Domain by following the steps below:
- Log in to your Microsoft Azure portal.
- Navigate to Microsoft Entra ID.
- In the sidebar on the left side of the page, navigate to Overview. An Overview page will display.
-
In the Tenant Information section, copy and save the Primary domain somewhere that you can easily access. You'll need the domain to set up the integration in Real-Time Coaching.
- Return to your Microsoft Azure portal, then select App registrations.
- Select the name of the application you registered earlier. An application overview page will open.
- In the Essentials section, copy and save the Application (client) ID somewhere you can easily access it. You'll need the ID to set up the integration in Real-Time Coaching.
Set Up the Integration in Real-Time Coaching
Once you've set up the integration in your Microsoft Azure portal, you can set up the integration in Real-Time Coaching by following the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Microsoft Defender for Endpoint vendor tile and select Configure.
- In the Tenant field, paste the primary domain you saved earlier.
- In the Client ID field, paste the application (client) ID you saved earlier.
- In the Client Secret field, enter the value you saved earlier.
- In the Token Expiration Date field, select the expiration date you saved earlier.
- Select Authorize.
Map Your Users
After you’ve finished integrating Microsoft Defender for Endpoint, we recommend mapping your users using mapping rules or by uploading a CSV file. For more information, see our user mapping article.
Manage Detection Rules
Once you’ve successfully authorized this integration, you can also manage Microsoft Defender for Endpoint detection rules from Coaching > Detection Rules. For a full list of available system detection rules for this vendor, see our System Detection Rules by Vendor article.
Delete the Integration in Real-Time Coaching
If you want to delete the Microsoft Defender for Endpoint integration from Real-Time Coaching, follow these steps:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Microsoft Defender for Endpoint vendor tile and select Edit.
- Select Delete Integration near the bottom of the page.



