In this article, you'll learn how to integrate Microsoft Entra ID Protection with Real-Time Coaching. Once you set up this integration, data from Microsoft Entra ID Protection will be available under the Coaching tab in your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories.
For general information about Real-Time Coaching, see our overview article. If you would like to learn how to integrate other Microsoft products with Real-Time Coaching, see the vendor integration guides in our Knowledge Base.
Prerequisites
The following Microsoft license is required to ensure a successful Microsoft Entra ID Protection integration:
- Microsoft Entra ID P2
For more information, see Microsoft's Entra Plans and Pricing Entra Plans and Pricing (link opens in new window).
Set Up the Integration in Microsoft Azure
Before you can set up this integration in Real-Time Coaching, you'll need to register the Real-Time Coaching application, add API permissions, create a client secret, and locate your domain and client ID in your Microsoft Azure portal. For more information, see the subsections below.
Register the Real-Time Coaching Application
First, you'll need to register the Real-Time Coaching application in your Microsoft Azure portal by following the steps below:
- Log in to your Microsoft Azure portal.
- Navigate to Microsoft Entra ID.
- From the sidebar on the left side of the page, select App registrations.
- Select + New registration and enter a name for your application, such as "knowbe4integrations".
- Select Register.
Add API Permissions
After you've registered the Real-Time Coaching application, you can add API permissions by following the steps below:
- Log in to your Microsoft Azure portal.
- Navigate to Microsoft Entra ID.
- From the sidebar on the left side of the page, select App registrations.
- Select the name of the application you registered earlier.
- From the sidebar on the left side of the page, select API permissions.
- Select + Add a permission.
- From the Microsoft APIs subtab, select Microsoft Graph.
- Select Application permissions.
- Select the IdentityRiskEvent drop-down menu and enable the IdentityRiskEvent.Read.All check box. Then, select the IdentityRiskyUser drop-down menu and enable the IdentityRiskyUser.Read.All check box.
- Select Add permissions.
- Select Grant admin consent for [your active directory name]. Once permission is granted, the triangle symbol on the right side of the page will change to a green check mark.
Create a Client Secret
After you've registered the Real-Time Coaching application and added your API permissions, you can create a client secret by following the steps below:
- Log in to your Microsoft Azure portal.
- Navigate to Microsoft Entra ID.
- From the sidebar on the left side of the page, select App registrations.
- Select the name of the application you registered earlier. An application overview page will display.
- From the sidebar on the left side of the page, select Certificates & secrets.
- Select + New client secret.
- Enter a description for the client secret and select an expiry window.
- Select Add. The client secret Value and Expires date will now display on the page.
- Copy and save the client secret Value and Expires date somewhere that you can easily access. You'll need these credentials to set up the integration in Real-Time Coaching.
Locate Your Domain and Client ID
Finally, you'll need to locate your primary domain and application (client) ID by following the steps below:
- Log in to your Microsoft Azure portal.
- Navigate to Microsoft Entra ID.
- In the sidebar on the left side of the page, navigate to Overview.
-
In the Tenant information section, copy and save the Primary domain somewhere that you can easily access. You'll need this value for the Domain field when you set up the integration in Real-Time Coaching.
- Return to your Microsoft Azure portal, then select App registrations.
- Select the name of the application you registered earlier. An application overview page will display.
-
In the Essentials section, copy and save the Application (client) ID somewhere that you can easily access. You'll need this value for the Client ID field when you set up the integration in Real-Time Coaching.
Set Up the Integration in Real-Time Coaching
Once you've set up the integration in your Microsoft Azure portal, you can set up the integration in Real-Time Coaching by following the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Microsoft Entra ID Protection vendor tile and select Configure.
- Enter the Domain and Client ID values, and the Client Secret and Token Expiration Date you saved earlier.
- To finish setting up the integration, select Authorize.
Map Your Users
After you've finished integrating Microsoft Entra ID Protection, we recommend mapping your users using mapping rules or by uploading a CSV file. For more information, see our user mapping article.
Manage Detection Rules
Once you've successfully authorized this integration, you can also manage Microsoft Entra ID Protection detection rules from Coaching > Detection Rules. For a full list of available system detection rules for this vendor, see our System Detection Rules by Vendor article.
Delete the Integration in Real-Time Coaching
If you want to delete the Microsoft Entra ID Protection integration from Real-Time Coaching, follow these steps:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Microsoft Entra ID Protection vendor tile and select Edit.
- Select Delete Integration near the bottom of the page.

