Quick Links

Integrating with Mimecast

Overview

Mimecast safeguards an organization and its employees against sophisticated email-borne attacks. It helps defend against attackers trying to steal data or credentials, plant ransomware, trick employees into transferring money, and springboard to attack supply chains. These kinds of threats require advanced security measures beyond what is provided by traditional email security systems.

With Blumira, customers can reduce the noise and focus on the highest priority alerts from Mimecast while they tune and manage it for their organization.

Before you begin

First, ensure that logging is enabled for your organization in Mimecast. Logging begins as soon as the settings are enabled; however, collecting the files may take up to 30 minutes after saving the new settings.

Note: The Mimecast integration allows Blumira to receive logs up to 30 minutes into the past from the time of configuration and onward. 

To enable Mimecast logging, do the following:

  1. In the Mimecast Administrator Console, navigate to Administration > Account > Account Settings.
  2. Expand the Enhanced Logging section.
  3. Select the check box next to all log types:
    • Inbound: Logs for messages from external senders to internal recipients.
    • Outbound: Logs for messages from internal senders to external recipients.
    • Internal: Logs for messages between internal domains.
  4. Click Save.

Gathering your Mimecast credentials

Gather the necessary credentials for the Blumira Cloud Connector by completing the procedure below.

Note: If you previously had a v1 Mimecast Cloud Connector configured using a Mimecast API 1.0 application, you must replace the integration with a v2 Cloud Connector before 2026 when Mimecast will deprecate API 1.0.
  1. Create a custom role for the API 2.0 application by completing these steps:
    1. In the Mimecast Administration Console, navigate to Account > Roles.
    2. Click New Role.
    3. Under Properties, type a role name and description to help you identify this service account user as intended for use with your Blumira integration.
    4. Under Security Permissions, select Cannot Manage Roles.
    5. Under Application Permissions, within each subsection, deselect the check boxes next to "Edit" and "Protected areas" options, leaving only "Read" permissions for the role.
    6. Click Save and Exit.
  2. Add a new Mimecast API 2.0 Application in Mimecast and gather the Client ID and Client Secret by doing the following:
    1. Navigate to Integrations > API and Platform Integrations.
    2. On the Mimecast API 2.0 tile, click Generate Keys.
      Note: Do not click the "Blumira" tile to generate keys. The tile has not been updated to use the latest API version.
    3. In Disclaimer, click the check box next to I accept, and then click Next.
    4. In Details, enter the following information:
      1. Type an application name that represents the Blumira log integration.
      2. In Category, select SIEM Integration.
      3. In Products, click Select all and then click Apply.
      4. In Application Role, select the role you created for the Blumira integration above.
      5. Provide a description for the SIEM logging integration with Blumira.
      6. Click Next.
    5. In Notifications, provide the name and email address of the person Mimecast can reach as a technical contact regarding the application.
    6. Click Next.
    7. Click Add and Generate Keys.
    8. Copy and save the Client ID and Client Secret for use in the Blumira Cloud Connector.

Providing your Mimecast credentials to Blumira

To configure the Blumira Cloud Connector and begin logging, do the following:

  1. In Blumira, navigate to Settings > Cloud Connectors.
  2. Click + Add Cloud Connector.
  3. In the Available Cloud Connectors window, select the connector you want to add.
  4. In Cloud Connector Name, type a name that will help you identify the integration.
  5. In the remaining fields, enter the credentials you gathered in the previous steps.
  6. Click Connect.

Screenshot 2025-05-15 at 2.06.26 PM.png

Endpoints included in the integration

The integration with Mimecast delivers the secure email gateway functionality, which includes these endpoints: