Mimecast | Dropzone AI Documentation
Integration Overview
Dropzone AI integrates with Mimecast 2.0, a secure email gateway that sits in front of an organization's email and filters emails, detecting threats such as malware, phishing and scams.
To enable these integrations you will perform the following actions:
- Create a Custom Administration Role for your application
- Create an API 2.0 application
- Select integration parameters, such as which alert types to sync
Create a Custom Admin Role
To limit Dropzone's access to your data, you may choose to create a custom administrator role for your API application. You may skip this step and use the Full Administrator role instead, though some advanced features of the integration will be unavailable to you.
- In your Mimecast homepage, click "Administration Console"
Click Administration Console
- In the left hand sidebar, navigate to Account > Admin Roles
Click "Admin Roles"
Click "New Role"
Name the role something memorable, such as "Dropzone AI Application Role"
Assign the role the following permissions:
| Permission | Scope | Purpose |
|---|---|---|
| Security Events and Data Retrieval - Threat and Security Statistics | Read | Allows Dropzone to see flagged threats and alerts within Mimecast |
| Gateway - Tracking | Read | Allows Dropzone to search for and retrieve specific email messages |
| Archive - Search | Read | Allows Dropzone to retrieve email body content |
| Archive - Search | Content View | Allows Dropzone to retrieve email body content |
The Archive - Search Content View permission is only available to those with Superadmin privileges. Contact your Mimecast representative if you do not have it.
Only the Security Events and Data Retrieval permission is required for the basic function of the integration.
The "Security Events and Data Retrieval" permission section
- At the top of the role, click "Save and Exit"
Create an API Key
Mimecast requires an API key to enable. To create an API key, you must have a Security Permissions setting of "Manage Application Roles".
- In your Mimecast homepage, click "Administration Console"
Click Administration Console
- In the left hand sidebar, navigate to Integrations > API and Platform Integrations
Click "API and Platform Integrations"
Locate the Mimecast API 2.0 tile
Click "Generate Keys"
Click "Generate Keys"
Name the application something memorable, such as Dropzone AI
Select the products you want Dropzone to have access to
Assign the application a role (either the custom role you just created or the Full Administrator role)
Input a memorable description for the application
Input the application details
- Designate a Technical Point of Contact for the application
Input the Notification Settings
- At the top of the application, click "Save"
- Copy the credentials shown for use later in the Dropzone UI where they are called "Client ID" and "Client Secret" respectively
Save the API Credentials
Enable Mimecast
To enable the Alert Source integration, you will need the following information:
- API URL: The URL of your Mimecast 2.0 instance. If you do not know your API URL, see here for more information.
- Client ID: The Client ID value you generated earlier.
- Client Secret: The Client Secret value you generated earlier.
To enable the Alert Source integration, do the following:
- Navigate to your Dropzone AI tenant home page e.g. https:// mycompany.dropzone.app
- In the bottom left hand corner, click Settings > Integrations
Integrations Dropdown
- Click "Available"
Click Available
- In the Search bar, search Mimecast, then click "Configure"
The Mimecast Tile
- Input the API URL, Client ID and Client Secret
The Mimecast Alert Source Configuration (pt 1)
- Select the types of threats you wish for Dropzone AI to investigate
The Mimecast Alert Source Configuration (pt 2)
- Select the statuses of threats you wish for Dropzone AI to investigate
The Mimecast Alert Source Configuration (pt 3)
- Select the threat sources you want Dropzone AI to ingest
The Mimecast Alert Source Configuration (pt 4)
- Check the box labeled "Search Content View Enabled" to allow Dropzone to retrieve the content of emails for analysis
Only do so if you have granted the application the necessary permissions.
The Mimecast Alert Source Configuration (pt 5)
- Input your desired poll interval and lookback
The Mimecast Alert Source Configuration (pt 5)
If you wish to further filter alerts using the Python CEL package, check the box labeled "Use advanced filtering"
Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
Contact your Dropzone AI support representative for more information about this feature
The Mimecast Alert Source Configuration (pt 6)
- Click "Test & Save" to finish
If you have any errors or questions, engage your Dropzone AI support representative.