Appearance
Phin Security Setup Beta
Connect Phin Security to let Junto check active phishing simulations and training campaigns, summarize training completion, and review simulated-phishing results for your customers. The integration is read-only.
Prerequisites
- A Junto Admin or Owner account to manage the integration
- A Phin partner account with the Partner API integration enabled
- Your Phin Partner ID, Client ID, and Client secret, available through your Phin administrator or the portal's API settings
- Customer companies in Junto and Phin to map together
Junto supports one Phin configuration per organization. Each customer must be mapped before Junto can retrieve its Phin data.
Step 1: Configure in Junto
Go to Settings > Integrations > Phin Security.
Click Add configuration.
Enter the following values:
Field What to enter Partner ID The Phin partner ID associated with your credentials Client ID Your Phin API client ID Client secret Your Phin API client secret Base URL Keep the default, https://api.phinsec.ioClick Create. Junto validates the credentials and access to the partner before saving. The client ID and client secret are encrypted when stored.
Click Test connection on the configuration card. A successful test confirms connectivity and reports how many Phin companies were found.
Step 2: Map Companies
- Click Company mapping on the configuration card.
- For each Junto company, select the corresponding Phin Security company.
- Review the selections and click Save mappings.
Each Phin company can be mapped to only one Junto company. A company already selected for another customer is marked already mapped and cannot be selected again. To remove a mapping, return that row to Select Phin Security company... and save.
If the table has no Junto companies, import them from your PSA first. If Could not load mapping data appears, resolve the reported issue and click Retry.
What the Agent Can Do
| Capability | What Junto returns |
|---|---|
| Active campaigns | Currently running phishing and training campaigns, including campaign type, enrolled user count, and available schedule details |
| Training and phishing summary | User count, training assigned and completed, completion percentage, users up to date or behind on training, simulations sent, clicked and reported, and overall click percentage |
| Per-user review | Highlights users who may need additional training based on simulated-phishing results; a full per-user roster can also be requested |
All Phin tools are low-risk, read-only lookups. Junto cannot create campaigns, enroll users, send reminders, or change Phin settings.
Active Campaigns and Suspicious Emails
Junto can check whether a customer has an active phishing simulation when investigating a reported email. An active campaign does not confirm that a particular message belongs to the simulation. Verify the sender and other message evidence before treating the email as safe.
Shared campaigns run across the partner's customers, so they are less specific evidence that a particular customer is being tested.
Training and Phishing Reporting
The summary covers a rolling 12-month period. Phin's returned history does not include dated periods, so Junto cannot use it to compare quarters or establish a trend over time.
By default, Junto returns aggregate results and up to 10 users who clicked simulations. You can request up to 100 users in that list or ask for the full per-user roster. Review reported simulations alongside clicks: reporting a simulation is a positive security behavior.
Example requests:
- "Check whether Acme has an active Phin phishing campaign."
- "Summarize Acme's Phin training completion and phishing results for its QBR."
- "Show Acme's full per-user Phin training and phishing results."
Managing the Connection
- Update credentials: Click Edit, enter the new client ID or client secret, and click Update. Leave either credential field blank to keep its current value.
- Pause the integration: Click Edit, turn off Active, and click Update. The configuration remains saved.
- Change partners: Updating Partner ID clears all existing Phin company mappings. Reopen Company mapping and map the new partner's companies before using the integration.
- Remove the integration: Delete removes the configuration and its company mappings.
Troubleshooting
- Connection rejected: Verify the Partner ID, Client ID, and Client secret. Confirm the Partner API integration is enabled in Phin. Keep the Base URL set to
https://api.phinsec.io. - Authentication or permission error: Ask your Phin administrator to verify the credentials are valid and have access to the intended partner, then update them in Junto and test again.
- No active configuration: Edit the configuration and enable Active.
- Customer is not mapped: Open Company mapping, select the correct Phin company, and save.
- Mapped company no longer found: Reopen the mapping dialog and select a current company from the partner's inventory. Check whether the company was removed or moved to another partner in Phin.
- Expected Phin company is missing: Confirm that the company belongs to the configured partner and is accessible with the supplied credentials.