> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connecting Mimecast to Neo

> Create a Mimecast API 2.0 credential and save it in Neo

You connect Mimecast once at the MSP level, with a Client ID and a Client Secret from Mimecast API 2.0.

## 1. Create the credential in Mimecast

<Tabs>
  <Tab title="Every client (partner credential)">
    <Steps>
      <Step title="Open the Tenant API Gateway">
        Sign in to your own Mimecast account as a Super Administrator or Full Administrator and open **Multi Account Control** > **Tenant API Gateway**.
      </Step>

      <Step title="Create the credential">
        Click **Create API credential**, name it **Neo Agent**, and create it.
      </Step>

      <Step title="Copy the Client ID and Client Secret">
        Copy both values. Copy the Client Secret before you leave the page.
      </Step>
    </Steps>
  </Tab>

  <Tab title="One client">
    <Steps>
      <Step title="Open the Integrations Hub">
        Sign in to the client's Mimecast account as an administrator and open **Integrations** > **Integrations Hub**. On the **Mimecast API 2.0** tile, click **Configure New**.
      </Step>

      <Step title="Pick the products and role">
        Name the application **Neo Agent**. Under **Products**, select every product Neo should reach. Pick an **Application Role** that allows those products: see [What the credential needs](#what-the-credential-needs).
      </Step>

      <Step title="Copy the Client ID and Client Secret">
        Finish the wizard and copy both values. Copy the Client Secret before you leave the page.
      </Step>
    </Steps>
  </Tab>
</Tabs>

## What the credential needs

A partner credential acts with your partner administrator rights in each client's account. A credential for one client acts with its application role, which needs these permissions:

| For | Role permissions |
| - | - |
| Finding and judging email (read only) | Gateway: Tracking Read; Monitoring: URL Protection, Attachment Protection and Impersonation Protection Read; Account: Dashboard Read; Services: Threat Remediation Read; Security Events and Data Retrieval: Threat and Security Statistics Read |
| Releasing or rejecting held email | Account: Monitoring: Held Edit |
| Blocking or permitting senders | Gateway: Managed Senders Edit |
| Blocking or permitting URLs | Services: URL Protection Edit |
| Changing policies | Gateway: Policies Edit |
| Removing an email from every mailbox | Services: Threat Remediation Edit |

When the role lacks a permission, Mimecast refuses the call and the agent reports what Mimecast refused. Each endpoint's page in Mimecast's API documentation names the permission it needs.

<Warning>
  Do not delete or regenerate the credential in Mimecast after you connect it. Neo loses access until you save the new values here.
</Warning>

## 2. Add the credential in Neo

<Steps>
  <Step title="Open Integrations">
    In the Neo Dashboard, open [**Integrations** → **Mimecast**](https://dashboard.neoagent.io/integrations?open=mimecast), under Security.
  </Step>

  <Step title="Save the credential">
    Paste the Client ID and the Client Secret and click **Save settings**. Neo checks them against Mimecast before saving, so a wrong value is rejected straight away.
  </Step>
</Steps>

## 3. Turn Mimecast on per agent

<Steps>
  <Step title="Open the agent's integrations">
    Open the agent in the Neo Dashboard and go to its **Integrations** tab.
  </Step>

  <Step title="Pick an access profile">
    Under **Mimecast**, pick an access profile, or set each permission group by hand.

    | Profile | What it does |
    | - | - |
    | **Read Only** | Finds and judges email, reads the held queue and policies; changes nothing |
    | **Helpdesk** | Also rejects held email and blocks senders and URLs, each with technician approval |
    | **IT Admin** | Rejects, blocks and manages users, groups and DMARC Analyzer on its own; policy and account changes ask a technician |
    | **Full Automation** | Every supported write without approval, except releases, permits, policy changes, remediations and sending email |

    The groups are Messages & Tracking, Threat Intelligence, Held Messages, Sender & URL Lists, Policies, Remediation, Users & Groups, Account & Domains, DMARC Analyzer, and Awareness & Human Risk. See [Mimecast API](/agents/tools/security/mimecast-api).
  </Step>

  <Step title="Tell the agent what to do">
    Add an instruction, for example: "When a ticket reports a suspected phishing email, find it in Mimecast, judge whether it is malicious from Mimecast's results, and write the evidence and your verdict in an internal note."
  </Step>
</Steps>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.