Skip to content

Integrate Mimecast API v2

You can integrate Mimecast API v2 with Sophos XDR so that it sends data to Sophos for analysis.

This page refers to Mimecast API v2. Mimecast API v1 is not supported by Sophos XDR.

Key steps

The key steps in a Mimecast API v2 integration are as follows:

  • Create a Mimecast role with the required permissions.
  • Turn on logging in Mimecast.
  • Create an API v2 application for Sophos XDR.
  • Configure the integration in Sophos XDR.

Requirements

The following is required for a Mimecast API v2 integration:

  • Access to the Mimecast Administrator Console.
  • A company-branded administrator account, not the temporary onboarding administrator account provided by Mimecast.
  • Ensure that you've allowed the Sophos IP addresses we use to reach your Mimecast. To find the IP addresses you need, see Allow Sophos IPs. You might want to add these addresses to the allow lists in your network infrastructure so they can reach your Mimecast application.

Add a Mimecast API v2 integration

To integrate Mimecast API v2, you must first create a role with the required permissions, then gather certain details from Mimecast, then lastly provide them in Sophos XDR.

Create a role with the required permissions

To create a role in Mimecast with the required permissions, do as follows:

  1. In the Mimecast Administrator Console, go to Account > Roles.
  2. Click New Role and enter a name. For example, XDR Integration Role.
  3. In Application Permissions, select the following permissions:

    • Menu > Attachment Protection > Read
    • Monitoring Menu > URL Protection > Read
    • Monitoring Menu > Impersonation Protection Logs > Read
  4. Click Save and Exit.

Next, you need to turn on logging in Mimecast.

Turn on logging in Mimecast

To turn on logging in Mimecast, do as follows:

  1. In the Mimecast Administrator Console, go to Administration > Account > Account Settings.
  2. In Enhanced Logging, choose the following logging types:

    • Inbound
    • Outbound
    • Internal
  3. Click Save.

Next, you create an API v2 application in Mimecast.

Create an API v2 application for Sophos XDR

To create an API v2 application for Sophos XDR in Mimecast, do as follows:

  1. Follow the instructions in Mimecast's own documentation: API & Integrations - Managing API 2.0 for Email Security.
  2. In the Application Details section, enter the following values:

    • Application Name: Give the application a name, for example, Taegis Integration.
    • Category: Select XDR Integration.
    • Products: Choose Select All.
    • Application Role: Select the role you created above in Create a role with the required permissions.
  3. In the Notification Settings section, provide email contact details in case Mimecast needs to speak to you about the use of this API.

  4. Review the summary and click Add and Generate Keys.
  5. Your Client ID and Client Secret keys are shown. Copy the keys to a safe place. They will be used to complete the integration.

    Record your keys at the time of creation as they cannot be viewed or retrieved again after this point. If lost, you must generate new ones.

Next, you configure an integration in Sophos XDR.

Configure the integration in Sophos XDR

To integrate Mimecast API v2 with Sophos XDR, do as follows:

  1. In Sophos Fusion, go to Security Operations > Integrations > Marketplace.
  2. Click Mimecast API v2.

    The Mimecast API v2 page opens. You can configure integrations here and see a list of any you've already configured.

  3. In Configured integrations, click Add new.

  4. In Add an integration, do as follows:

    1. Enter a name for the integration.
    2. Enter the Client ID you got from Mimecast.
    3. Enter the Client Secret you got from Mimecast.
  5. Click Done.

The new integration appears under Configured integrations. If its status icon is a green tick, your data should appear in the Sophos Data Lake after validation.

Additional resources

For more information on configuring Mimecast API v2, see the following documents: