Accenture MDR Quick Start Guide for Mimecast Secure Email Gateway

 

This quick start guide will help Accenture MDR customers configure Mimecast Secure Email Gateway to allow log collection from the Log Collection Platform (LCP).

 

The document includes the following topics:

Supported Versions

A list of supported versions is available in the Accenture MDR Supported Products List document (Accenture_MDR_Supported_Products_List.xlsx) which can be found in

Accenture MDR Portal - https://mss.accenture.com/PortalNextGen/Reports/Documents

Port Requirements

Table1-1: Port requirements for LCP communication.

Source 

Destination

Port

Description

LCP

Mimecast Secure Email Gateway

443 (TCP)

Default port

Configuring Mimecast Secure Email Gateway

To configure the Mimecast Secure Email gateway, follow the below steps.

  • Enable Logging for Login Account.

  • Create API Application

  • Get Application ID and Application Key

 

I. Enable Logging for Login Account

  1. Log in to  Administration Console.

  2. Navigate to the Administration > Account > Account Settings menu item to display the Account Settings page.

  3. Expand the Enhanced Logging section.

  4. Select the types of logs you want to enable. The choices are:

  • Inbound - logs for messages from external senders to internal recipients

  • Outbound - logs for messages from internal senders to external recipients

  • Internal - logs for messages between internal domains

5. Select Save to apply the changes.

 

II. Create API Application

  1. Navigate to https://login-us.mimecast.com/u/login/?gta=administration&link=administration-dashboard#/login

  2. Enter the credentials.

  3. Click on the Add API Application button.

4. Fill the Details section as outlined below

Fields

Description

Application Name

Provide a name for the application that you can easily identify

Category

Select a category for the application from the drop down menu:

SIEM Integration: Relates to security information and event management (SIEM), that provides real-time analysis of security alerts generated by the application.

MSP Ordering & Provisioning: Assists with provisions for the Managed Service Provider (MSP) Portal, available for select Partners to manage customers.

Email / Archiving: The application relates to the messages and files stored in Mimecast.

Business Intelligence: The application's infrastructure and tools enable access to and analysis of information to improve and optimize decisions and performance.

Process Automation: The application allows automation of business processes. 

Other: Select this option if the application doesn't fit with any of the other categories.

Description

Provide a description of the application

  5. Click on the Next button. 

6. Fill the Settings section as outlined below:

Fields

Description

Developer

Add the name of the application's developer

Email

Add the email address of the application's developer

7. Click on the Next button.

8. Review the information displayed in the Summary page to ensure all details are correct.

9. To fix any errors:

  • Click on the Edit link next to the Details or Settings to return to the relevant page.

  • Make your changes and click on the Next button to proceed to the Summary page again.

 

III. Get Application ID and Application Key

  1. Navigate to Administration > Services > API Applications

  2. Click the API application created for Accenture MDR.

  3. You will find the details of the API application.

Creating API Access and Secret Key:

To generate access and secret key, please refer section Creating User Association Keys in the below document:

https://community.mimecast.com/s/article/Managing-API-Applications-505230018?_ga=2.78438932.1826345841.1663821316-882733488.1663821316#Creating-User-Association-Keys

LCP Configuration Parameters

Table 1-2: Mimecast Secure Email Gateway event collector(API-3862) properties to be configured by MDR are shown in the table

Property

Default Value

Description

Mimecast Login URL

 Custom Value

Mimecast Region Based Login API URL mentioned in the Pre-Installation Questionnaire (PIQ).

Refer Vendor Documentation for more information: https://www.mimecast.com/tech-connect/documentation/api-overview/global-base-urls/

Username

Custom Value

API User Name mentioned in the PIQ.

Password

Custom Value

API User Password mentioned in the PIQ.

Application ID

Custom Value

Application ID mentioned in the PIQ.

Note: The value of the application id provided when you registered your application

Application Key

Custom value

Application Key mentioned in the PIQ.

Note: The value of the application key provided when you registered your application

Access Key

 

API Access key of the user

Secret Key

 

API Secret key of the user

Note for Sensor Configuration:

  • Set username and password both the fields strictly as NA in case access and secret key method is used for authentication. Similarly, set access and secret key both as NA if username and password method is used for authentication.

  • If you would like to query specific endpoints and exclude querying other endpoints, you can add a property "excludeEndPoints" and mention the endpoints which you do not wish to query. For list of endpoints we query, please refer sensor details part later in the DRD.

 

Legal Notice

Copyright © 2021 Accenture. All rights reserved.

Accenture, the Accenture Logo, and DeepSight Intelligence are trademarks or registered trademarks of Accenture in the U.S. and other countries. Other names may be trademarks of their respective owners.

The product described in this document is distributed under licenses restricting its use, copying, distribution, and decompilation/reverse engineering. No part of this document may be reproduced in any form by any means without prior written authorization of Accenture and its licensors, if any.

THE DOCUMENTATION IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. ACCENTURE SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE.

The Licensed Software and Documentation are deemed to be commercial computer software as defined in FAR 12.212 and subject to restricted rights as defined in FAR Section 52.227-19 "Commercial Computer Software - Restricted Rights" and DFARS 227.7202, et seq. "Commercial Computer Software and Commercial Computer Software Documentation," as applicable, and any successor regulations, whether delivered by Accenture as on premises or hosted services. Any use, modification, reproduction release, performance, display or disclosure of the Licensed Software and Documentation by the U.S. Government shall be solely in accordance with the terms of this Agreement.