Automatically enabled when you configure Mimecast permissions in your agent workflow.
What It Does
- Pick the client’s Mimecast account from the company link, or by name and mail domain
- Find a message by sender, recipient, subject, link or Message-ID, and read its delivery, spam and policy verdicts and its attachments’ scan results
- Read who clicked the links and what URL Protect decided, the attachment sandbox result, impersonation hits, the real target of a rewritten link, and whether the account has seen a file hash
- Read the held queue and the hold reason; release or reject a held email
- Block a sender for a recipient, block a URL for the whole account, and permit them
- Read and change policies: blocked senders, anti-spoofing and its bypass, greylisting, delivery routes, DNS authentication
- Remove a malicious email from every mailbox it reached
- Read and manage users, profile groups, domains, connectors, directory sync and DMARC Analyzer
- Read awareness training results and human risk scores (read-only)
How the agent handles a phishing ticket
The agent finds the account for the ticket’s company, searches Message Finder for the reported email, and reads its detail. It checks the link clicks, the attachment sandbox result and impersonation hits, decodes any rewritten Mimecast link in the ticket, and searches the account for the attachment’s hash. It writes the evidence and its verdict in an internal note. A block or a remediation follows your permissions below. Message Finder and the held queue answer for Cloud Gateway clients (mail routed through Mimecast). For a Cloud Integrated client, when the agent also has Microsoft Graph access, it reads the reported message through Graph; without it, the agent has Mimecast’s SIEM events only.Permission Groups
Access Profiles
Safety Controls
How to Configure
1
Connect Mimecast
Save your Mimecast API 2.0 credential in the Neo Dashboard under the Security integrations category. See Connecting Mimecast to Neo.
2
Configure permissions
In your agent workflow’s Integrations tab, choose an access profile or set each permission group by hand.
