> For the complete documentation index, see [llms.txt](https://docs.dropzone.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.dropzone.ai/integrations/alert/mimecast.md).

# Mimecast

Dropzone AI integrates with [Mimecast 2.0](https://www.mimecast.com/), a secure email gateway that sits in front of an organization's email and filters emails, detecting threats such as malware, phishing and scams.

## Integration Overview

To enable these integrations you will perform the following actions:

* Create a Custom Administration Role for your application
* Create an API 2.0 application
* Select integration parameters, such as which alert types to sync

## Create a Custom Admin Role

To limit Dropzone's access to your data, you may choose to create a custom [administrator role](https://mimecastsupport.zendesk.com/hc/en-us/articles/34000745394963-Roles-Understanding-Administrator-Roles#h_01JA88CBVKZ961KRA66F67D34Q) for your API application. You may skip this step and use the `Super Administrator` role instead.

* In your Mimecast homepage, click "Administration Console"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-e80336c606bb97e879a4073dc76c690726291f2b%2Fmimecast-1.png?alt=media" alt=""><figcaption><p>Click Administration Console</p></figcaption></figure>

* In the left hand sidebar, navigate to Account > Admin Roles

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-87f7b77c2ad5f6d8a0a0781beb8c14f6e4208bf2%2Fmimecast-2.png?alt=media" alt=""><figcaption><p>Click "Admin Roles"</p></figcaption></figure>

* Click "New Role"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-f6304ae3bee07446b4932614d8e135ddc703b32d%2Fmimecast-3.png?alt=media" alt=""><figcaption></figcaption></figure>

* Name the role something memorable, such as "Dropzone AI Application Role"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-3b9548818825abb33d0e9606fa249e555dd709b8%2Fmimecast-4.png?alt=media" alt=""><figcaption></figcaption></figure>

* Assign the role the following permissions:

| Permission                                                          | Scope        | Purpose                                                            |
| ------------------------------------------------------------------- | ------------ | ------------------------------------------------------------------ |
| Security Events and Data Retrieval - Threat and Security Statistics | Read         | Allows Dropzone to see flagged threats and alerts within Mimecast  |
| Gateway - Tracking                                                  | Read         | Allows Dropzone to search for and retrieve specific email messages |
| Archive - Search                                                    | Read         | Allows Dropzone to retrieve email body content                     |
| Archive - Search                                                    | Content View | Allows Dropzone to retrieve email body content                     |

{% hint style="info" %}
You may only create a role with the Archive - Search `Content View` permission if you have Superadmin privileges. Contact your Mimecast representative if you do not have it.
{% endhint %}

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-ae3bbd11d96b1dd86a74345389206301e8ef8f55%2Fmimecast-5.png?alt=media" alt=""><figcaption><p>The "Security Events and Data Retrieval" permission section</p></figcaption></figure>

* At the top of the role, click "Save and Exit"

## Create an API Key

Mimecast requires an API key to enable. To create an API key, you must have a Security Permissions setting of "Manage Application Roles"

* In your Mimecast homepage, click "Administration Console"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-e80336c606bb97e879a4073dc76c690726291f2b%2Fmimecast-1.png?alt=media" alt=""><figcaption><p>Click Administration Console</p></figcaption></figure>

* In the left hand sidebar, navigate to Integrations > API and Platform Integrations

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-58c0fab53d4f0a2b5cef76243135ad16d7b67d0f%2Fmimecast-6.png?alt=media" alt=""><figcaption><p>Click "API and Platform Integrations"</p></figcaption></figure>

* Locate the Mimecast API 2.0 tile
* Click "Generate Keys"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-e31af50d10474c1d607da5ed2bb99a47569e9b22%2Fmimecast-7.png?alt=media" alt=""><figcaption><p>Click "Generate Keys"</p></figcaption></figure>

* Name the application something memorable, such as Dropzone AI
* Select the products you want Dropzone to have access to
* Assign the application a role (either the custom role you just created or the Full Administrator role)
* Input a memorable description for the application

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-a9a586c1d4cca1b71a3424191b6145197fa92da3%2Fmimecast-8.png?alt=media" alt=""><figcaption><p>Input the application details</p></figcaption></figure>

* Designate a Technical Point of Contact for the application

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-2fe370a6af2ac8eda3a82009f1f5ed107a152110%2Fmimecast-9.png?alt=media" alt=""><figcaption><p>Input the Notification Settings</p></figcaption></figure>

* At the top of the application, click "Save"
* Copy the credentials shown for use later in the Dropzone UI where they are called "Client ID" and "Client Secret" respectively

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-443c97f2f8acd417414845c28b4bf80fcc158491%2Fmimecast-10.png?alt=media" alt=""><figcaption><p>Save the API Credentials</p></figcaption></figure>

## Enable Mimecast

To enable the Alert Source integration, you will need the following information:

| Dropzone Field | Source                                                                                                                                                                                                                          |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| API URL        | The URL of your Mimecast 2.0 instance. If you do not know your API URL, see [here](https://developer.services.mimecast.com/api-overview#:~:text=with%20appropriate%20permissions.-,API,-Gateway%20Options) for more information |
| Client ID      | The Client ID value you generated earlier                                                                                                                                                                                       |
| Client Secret  | The Client Secret value you generated earlier                                                                                                                                                                                   |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-8c77435ef341f8180540e049f505d3390a27bbf4%2Fui-integrations-dropdown.png?alt=media" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-7e038b4f51ee27d4cf4f1ac6f76c5ddae2bf29c5%2Fapp_system_integrations_library.png?alt=media" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Mimecast, then click "Configure"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-103855ec6277404509d9c6048a5357c982763a27%2Fapp_system_integrations_available_mimecast.png?alt=media" alt=""><figcaption><p>The Mimecast Tile</p></figcaption></figure>

* Input the API URL, Client ID and Client Secret

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-869d4df1dfd8e5e35eb32e997df4e8baef8563ee%2Fapp_system_integrations_available_mimecast_alert_config_1.png?alt=media" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 1)</p></figcaption></figure>

* Select the [types](https://mimecastsupport.zendesk.com/hc/en-us/articles/34000509365651-Analysis-Response#h_01JED5RV0B0N5GXENM8PRVM6NG:~:text=Protection%20blocked%20clicks.-,Detection,-Categories) of threats you wish for Dropzone AI to investigate

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-77e6529ab0dd88338e5a8362714f188ac6bd0c59%2Fapp_system_integrations_available_mimecast_alert_config_2.png?alt=media" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 2)</p></figcaption></figure>

* Select the [statuses](https://mimecastsupport.zendesk.com/hc/en-us/sections/34523591340051-Message-Center) of threats you wish for Dropzone AI to investigate

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-dc52cf603962489a11052e5f7dbbc52750d91837%2Fapp_system_integrations_available_mimecast_alert_config_3.png?alt=media" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 3)</p></figcaption></figure>

* Select the threat sources you want Dropzone AI to ingest

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-076a95ddbbe4697fea5060bab10c781a046c045a%2Fapp_system_integrations_available_mimecast_alert_config_4.png?alt=media" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 4)</p></figcaption></figure>

* Check the box labeled "Search Content View Enabled" to allow Dropzone to retrieve the content of emails for analysis

{% hint style="success" %}
Only do so if you have granted the application the necessary permissions.
{% endhint %}

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-202514a32cb61bbbdc298076db844f5519fc5cb7%2Fapp_system_integrations_available_mimecast_alert_config_5.png?alt=media" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 5)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-79ab9c397241eb165f5157db81131207481ef1c3%2Fpoll-interval-lookback.png?alt=media" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 5)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-43a55827dfbfd5a9af3d744a16e7e8306fc8e253%2Fadvanced-filtering-test-save.png?alt=media" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 6)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors or questions, engage your Dropzone AI support representative.
