Skip to main content
The Mimecast API tool gives Neo agents access to Mimecast API 2.0 for each client you manage in Mimecast. The common uses are a reported phishing email, where the agent finds the message, reads Mimecast’s verdicts and writes the evidence in an internal note, and a wanted email that Mimecast held.
Automatically enabled when you configure Mimecast permissions in your agent workflow.

What It Does

  • Pick the client’s Mimecast account from the company link, or by name and mail domain
  • Find a message by sender, recipient, subject, link or Message-ID, and read its delivery, spam and policy verdicts and its attachments’ scan results
  • Read who clicked the links and what URL Protect decided, the attachment sandbox result, impersonation hits, the real target of a rewritten link, and whether the account has seen a file hash
  • Read the held queue and the hold reason; release or reject a held email
  • Block a sender for a recipient, block a URL for the whole account, and permit them
  • Read and change policies: blocked senders, anti-spoofing and its bypass, greylisting, delivery routes, DNS authentication
  • Remove a malicious email from every mailbox it reached
  • Read and manage users, profile groups, domains, connectors, directory sync and DMARC Analyzer
  • Read awareness training results and human risk scores (read-only)

How the agent handles a phishing ticket

The agent finds the account for the ticket’s company, searches Message Finder for the reported email, and reads its detail. It checks the link clicks, the attachment sandbox result and impersonation hits, decodes any rewritten Mimecast link in the ticket, and searches the account for the attachment’s hash. It writes the evidence and its verdict in an internal note. A block or a remediation follows your permissions below. Message Finder and the held queue answer for Cloud Gateway clients (mail routed through Mimecast). For a Cloud Integrated client, when the agent also has Microsoft Graph access, it reads the reported message through Graph; without it, the agent has Mimecast’s SIEM events only.

Permission Groups

Access Profiles

Safety Controls

How to Configure

1

Connect Mimecast

Save your Mimecast API 2.0 credential in the Neo Dashboard under the Security integrations category. See Connecting Mimecast to Neo.
2

Configure permissions

In your agent workflow’s Integrations tab, choose an access profile or set each permission group by hand.
Start with Read Only. Judging a reported email needs only reads in Mimecast; the note on the ticket is written with the PSA tools.