> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Mimecast API

> Find a reported or held email in Mimecast, judge it from Mimecast's own scan results, release or reject held mail, block senders and URLs, and remove a malicious email from every mailbox

The Mimecast API tool gives Neo agents access to Mimecast API 2.0 for each client you manage in Mimecast. The common uses are a reported phishing email, where the agent finds the message, reads Mimecast's verdicts and writes the evidence in an internal note, and a wanted email that Mimecast held.

<Info>
  Automatically enabled when you configure Mimecast permissions in your agent workflow.
</Info>

## What It Does

* Pick the client's Mimecast account from the company link, or by name and mail domain
* Find a message by sender, recipient, subject, link or Message-ID, and read its delivery, spam and policy verdicts and its attachments' scan results
* Read who clicked the links and what URL Protect decided, the attachment sandbox result, impersonation hits, the real target of a rewritten link, and whether the account has seen a file hash
* Read the held queue and the hold reason; release or reject a held email
* Block a sender for a recipient, block a URL for the whole account, and permit them
* Read and change policies: blocked senders, anti-spoofing and its bypass, greylisting, delivery routes, DNS authentication
* Remove a malicious email from every mailbox it reached
* Read and manage users, profile groups, domains, connectors, directory sync and DMARC Analyzer
* Read awareness training results and human risk scores (read-only)

## How the agent handles a phishing ticket

The agent finds the account for the ticket's company, searches Message Finder for the reported email, and reads its detail. It checks the link clicks, the attachment sandbox result and impersonation hits, decodes any rewritten Mimecast link in the ticket, and searches the account for the attachment's hash. It writes the evidence and its verdict in an internal note. A block or a remediation follows your permissions below.

Message Finder and the held queue answer for Cloud Gateway clients (mail routed through Mimecast). For a Cloud Integrated client, when the agent also has Microsoft Graph access, it reads the reported message through Graph; without it, the agent has Mimecast's SIEM events only.

## Permission Groups

| Group | Access levels | Covers |
| - | - | - |
| Messages & Tracking | Disabled, Read Only, Read / Write | Message Finder, the archive, rejections, queues and the audit log; send an email from the account, tag archived messages |
| Threat Intelligence | Disabled, Read Only | Threat events, URL, attachment and impersonation protection logs, decoded links, hash search, the threat feed, SIEM events, reported emails |
| Held Messages | Disabled, Read Only, Read / Write | The held queue and its release log; release or reject a held email |
| Sender & URL Lists | Disabled, Read Only, Read / Write | Managed senders, managed URLs and Web Security block and allow lists |
| Policies | Disabled, Read Only, Read / Write | Gateway and Cloud Integrated policies |
| Remediation | Disabled, Read Only, Read / Write | Remediation incidents, removing an email from every mailbox, your own threat-intelligence block lists |
| Users & Groups | Disabled, Read Only, Read / Write | Internal users, aliases, delegates, profile groups and members, roles |
| Account & Domains | Disabled, Read Only, Read / Write | The account and your managed clients, domains, connectors, journaling, directory sync, configuration snapshots |
| DMARC Analyzer | Disabled, Read Only, Read / Write | DMARC Analyzer domains, sources, reports, DNS checks and tasks |
| Awareness & Human Risk | Disabled, Read Only | Awareness training results and human risk scores |

## Access Profiles

| Profile | What runs on its own | What asks a technician |
| - | - | - |
| **Read Only** | Every read | No write is allowed |
| **Helpdesk** | Every read | Rejecting held email, blocking senders and URLs, and removing list entries |
| **IT Admin** | Rejecting held email, blocks, users, groups, remediation block lists, DMARC Analyzer | Policies and account changes |
| **Full Automation** | Every write except those below | Only the writes below |

## Safety Controls

| Control | Behavior |
| - | - |
| **Releases** | Releasing a held email always asks a technician |
| **Permits** | Permitting a sender or a URL, and every Web Security list change, always asks a technician. A block follows the access profile |
| **Policies** | Every policy create, change or delete, the protection mode and a configuration restore always ask a technician |
| **Remediation** | Removing an email from every mailbox always asks a technician |
| **Sending email** | Sending an email from the client's Mimecast account always asks a technician |
| **Right account** | With a partner credential, every call names the client's account; Neo refuses a call that would reach your own Mimecast account instead |
| **Refused** | Neo does not delete or disable its own Mimecast API application, remove a client's directory sync, purge archived mail, fetch download links to messages or attachments, or register webhooks |

## How to Configure

<Steps>
  <Step title="Connect Mimecast">
    Save your Mimecast API 2.0 credential in the Neo Dashboard under the **Security** integrations category. See [Connecting Mimecast to Neo](/integrations/mimecast/connecting-to-neo).
  </Step>

  <Step title="Configure permissions">
    In your agent workflow's **Integrations** tab, choose an access profile or set each permission group by hand.
  </Step>
</Steps>

<Tip>
  Start with **Read Only**. Judging a reported email needs only reads in Mimecast; the note on the ticket is written with the PSA tools.
</Tip>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.