Skip to main content

What this integration contributes

Mimecast can contribute normalized email threat, click, delivery, and data-protection activity. Reviewed examples include:
  • phishing.real.clicked — clicks links in real phishing emails
  • data.transfer.blocked — data transfer blocked
  • phishing.real.delivered — real phishing delivered to the inbox
See how integration data becomes signals.

What Living Security needs

Assign the application a role with Monitoring → URL Protection → Read. Living Security uses the OAuth 2.0 client-credentials flow and reads URL Protection click logs.

Setup

1

Create a Mimecast service application

In the Mimecast Administration Console, create an API 2.0 service application for Living Security and use the client-credentials grant.
2

Assign the minimum read permission

Assign a role that includes Monitoring → URL Protection → Read, then record the client ID and client secret.

Verify and troubleshoot

Verify that the connection can read URL Protection logs. An empty first result is expected when there were no recent protected-link clicks.
The client ID or secret is invalid, or the service application is disabled. Rotate the secret if necessary and reconnect.
Confirm that the role assigned to the service application includes Monitoring → URL Protection → Read.
Confirm that URL Protection is enabled for the relevant mail flow and that the role applies to the account being queried.
For the endpoint permission, see Mimecast’s URL Protection log reference.