Connect & Integrate KnowBe4 [Early Preview]
Last updated: September 15, 2026
Introduction
This guide explains how to connect YeshID to your KnowBe4 Security Awareness Training (KSAT) console. The connection uses KnowBe4’s SCIM interface, so YeshID can create, update, and archive KnowBe4 users as part of your onboarding and offboarding workflows instead of you managing them by hand or through CSV uploads.
Important: Once SCIM is active in KnowBe4, KnowBe4 treats the users it has received over SCIM as the complete list. Any active console user that YeshID has not sent is archived on KnowBe4’s next sync. Read the section Before you turn off Test Mode before you enable provisioning for real.
What YeshID can do with KnowBe4
Once connected, YeshID can:
Import your KnowBe4 users, and keep them up to date
Create users, including job title, department, and manager
Update user attributes
Deactivate (archive) users
Import groups and add users to groups
Deactivating a user in YeshID archives them in KnowBe4. Archived users keep their training history and phishing results and are restored automatically if YeshID sends them again.
Prerequisites
You are a KnowBe4 admin on a Silver plan or higher.
You have admin access in YeshID to add and connect applications.
The people you want in KnowBe4 exist in YeshID, with the email address KnowBe4 should use as their username. KnowBe4 does not support email aliases over SCIM.
If you want manager, job title, or department in KnowBe4, those values are set on the person in YeshID. Manager and title sync from your directory; department comes from a person custom field named Department.
Steps
1. Turn on user provisioning in KnowBe4
Sign in to your KSAT console.
Click your email address in the top-right corner and select Account Settings.
Go to User Management ▸ User Provisioning.
Select Enable User Provisioning (User Syncing).
Make sure Test Mode is selected. Leave it on until you have finished the steps in this guide.
Select SCIM.
Click Generate SCIM Token and copy the token. KnowBe4 shows it only once.
Copy the Tenant URL.
Click Save Changes.
2. Add KnowBe4 in YeshID
In YeshID, go to the Connect & Integrate page.
Find KnowBe4 in the application catalog.
Choose the SCIM setup option.
3. Enter your Tenant URL and token
Paste the Tenant URL into the Tenant URL field. It looks like
https://us.scim.knowbe4.com/v2and varies by region.Paste the SCIM token into the Bearer Token field.
Select Bearer if you are prompted for an authentication type.
Select Save.
YeshID tests the connection and runs an import. If your KnowBe4 users were created in the console or by CSV, the import returns no users. That is expected: KnowBe4 only lists users over SCIM once they have been sent over SCIM.
4. Push your existing KnowBe4 users from YeshID
This step is what prevents KnowBe4 from archiving your current users.
In YeshID, open the KnowBe4 application and go to Accounts.
Add every person who should be in KnowBe4. Each one is sent to KnowBe4 as a SCIM create. Being listed in YeshID is not enough; the create has to happen.
If some KnowBe4 users will not be managed through YeshID, such as contractors or shared mailboxes, mark them exempt in KnowBe4 instead: upload a CSV to KnowBe4 with Provisioning Managed set to
falsefor those users.
5. Check the Test Mode report
In your KSAT console, go to Users ▸ Provisioning.
Open the most recent sync report. With Test Mode on, it shows what KnowBe4 would do without doing it.
Confirm Archived is zero, or lists only the users you expect. Created or Restored should cover everyone you pushed.
If the report shows unexpected archives, add the missing people in YeshID or exempt them in KnowBe4, then check again. Do not continue until the report is clean.
6. Turn off Test Mode
In your KSAT console, go to Account Settings ▸ User Management ▸ User Provisioning.
Clear the Test Mode check box and click Save Changes.
Click Force Sync Now.
Return to Users ▸ Provisioning and confirm the report matches what you saw in step 5.
From this point KnowBe4 applies every change YeshID sends. Any edits made directly in the KnowBe4 console are overwritten by YeshID’s data on the next sync.
Sending manager, title, and department
YeshID sends job title, department, and manager to KnowBe4 on every create and update:
Job title comes from the person’s title in YeshID.
Department comes from a person custom field named Department. If your organization does not have that field, KnowBe4 leaves department empty.
Manager comes from the person’s manager in YeshID. KnowBe4 requires the manager to already exist in KnowBe4, so push managers before their reports, or push everyone at once and let the Update User action fill in the links.
To keep these values current after the first push, turn on the Update User action on the KnowBe4 integration in YeshID. It runs whenever a person’s record changes.
FAQ and troubleshooting
YeshID says the user was created, but I don’t see them in the KnowBe4 console. Test Mode is on, or KnowBe4’s sync has not run yet. In Test Mode KnowBe4 accepts the user and writes a report but does not change the console. KnowBe4 also skips a sync if another one ran within the last 15 minutes. Check Users ▸ Provisioning for the report, and use Force Sync Now to trigger a sync.
All of my KnowBe4 users were archived after I connected YeshID. KnowBe4 archives any active console user it has not received over SCIM. This happens on the first sync after Test Mode is turned off if your existing users were never pushed from YeshID. To recover, turn Test Mode back on, push every current user from YeshID as described in step 4, confirm the report shows zero archives, then turn Test Mode off again. Archived users are restored with their history intact.
Users I restored by hand keep getting archived. Every create or deactivate from YeshID triggers a KnowBe4 sync, and each sync re-applies the SCIM list. Restoring someone in the console does not add them to that list. Push them from YeshID instead.
Manager is not showing in KnowBe4. Check three things: the person has a manager set in YeshID, the manager has already been pushed to KnowBe4, and the Update User action is enabled. If all three are true, open the Test Mode report for the sync and look at the Changed section for that user.
I get “401 Unauthorized”. The SCIM token is wrong, was regenerated, or was revoked in KnowBe4. Generate a new token in Account Settings ▸ User Management ▸ User Provisioning and paste it into YeshID again.
Does the sync report show what YeshID sent? Yes. Each report lists created, changed, archived, and restored users, and the Sync and Error Details link downloads the full detail as JSON. KnowBe4 keeps the last 30 reports.
Can I use KnowBe4’s Active Directory Integration at the same time? No. KnowBe4 allows one provisioning source. Switching between ADI and SCIM overwrites user data once Test Mode is off.