Ellipse Gradient for Header

Mimecast Integration Guide

Connect Mimecast security, directory, archive, and message operations with enterprise systems through REST APIs and controlled Martini workflows.

Mimecast integration options at a glance

Mimecast primarily integrates through service-specific REST APIs covering administration, directory, email security, archive, continuity, monitoring, and reporting. API 2.0 uses OAuth-style application authorization where available, while older API 1.0 operations may require signed requests and application credentials. Mimecast uses region-specific API hosts, so the endpoint should be environment configuration. General webhook coverage, universal bulk APIs, direct database access, and a general-purpose attachment API were not confirmed. Martini can consume the documented REST resources, schedule polling workflows, paginate and filter collections, transform responses, apply business rules, and expose a controlled REST API for archive or security operations.

Integration pointSupported by Mimecast?Common use casesHow Martini supports it
REST APIsYesMimecast exposes service-specific REST resources for administration, directory, email security, archive, continuity, monitoring, reporting, and related operations.Martini can consume Mimecast REST endpoints from workflows, generate reusable API integration assets from documented definitions where available, map responses, and expose controlled APIs for downstream applications.
AuthenticationYesAPI 2.0 uses OAuth 2.0-style application authorization, while older API 1.0 operations may use application credentials, request identifiers, timestamps, expiration values, and signed requests.Martini stores client credentials, tokens, access keys, application keys, and signing secrets in protected secrets or environment configuration and can support the authentication flow required by the selected API.
Webhooks / outbound callbacksNot confirmedA general webhook framework for all Mimecast objects and events was not confirmed. A particular Mimecast product may expose a notification or callback that must be verified independently.If an official product-specific notification is available, Martini can receive it through a webhook-triggered workflow, validate it, retrieve current resource details, and route the result.
Collection, reporting, and batch operationsLimitedMimecast endpoints may return collections of Users, Groups, Messages, reports, or archive results, but a universal bulk or asynchronous API model was not confirmed.Martini can implement endpoint-specific pagination, filtering, date windows, continuation markers, watermarks, and scheduled reconciliation workflows.
File and attachment handlingLimitedMimecast processes email messages and attachments in security and archive services, but a general-purpose file or attachment API was not confirmed.Martini can handle files or attachment data only when the selected Mimecast operation explicitly returns or accepts it, with payload minimization and protected storage.
Database or direct analytics accessNot confirmedNo direct customer-database access was confirmed. Supported APIs, reporting, or export facilities should be used instead of connecting to Mimecast infrastructure.Martini can write normalized Mimecast results to an approved database or analytics platform without requiring direct access to Mimecast databases.

How Mimecast exposes data and business events

Mimecast REST APIs

Mimecast's primary integration model is a set of service-specific REST APIs covering administration, directory, email security, archive, continuity, monitoring, reporting, and related resources. The available paths and permissions vary by product, tenant configuration, and API generation.

Martini implementation pattern

Martini implementation pattern: Martini authenticates against the region-specific Mimecast host, calls the selected API resource from a workflow, handles pagination and filtering, maps the response into a canonical model, applies business rules, and writes to a target system or returns a controlled API response. API 2.0 and legacy API 1.0 authentication must not be mixed.

Implementation sequence

Configure the region-specific Mimecast API host
Store OAuth or signed-request credentials in protected Martini configuration
Invoke the documented Mimecast REST resource
Follow endpoint-specific pagination and filtering rules
Map the response to the target data model
Apply validation, authorization, and idempotency rules•Write the result and persist a sync

Scheduled Mimecast synchronization

Mimecast collection, reporting, message-tracking, directory, and archive operations can support scheduled retrieval where the selected service exposes the required resource. A universal asynchronous or bulk model was not confirmed.

Martini implementation pattern

Martini implementation pattern: a scheduler starts a workflow using a persisted watermark or bounded time window. The workflow retrieves pages of results, transforms them, writes downstream records, and stores the checkpoint only after successful processing. This pattern is suitable when a general event or webhook mechanism is unavailable.

Implementation sequence

Start the scheduled Martini workflow
Load the last successful timestamp or source identifier
Request a filtered Mimecast collection
Process every returned page
Transform and route each object
Commit the checkpoint after successful writes

Product-specific notifications

General Mimecast webhook coverage for all directory, message, archive, and administrative events was not confirmed. A specific Mimecast product may provide a notification, event feed, or callback that must be verified before design approval.

Martini implementation pattern

Martini implementation pattern: when an official notification is available, Martini receives it through a webhook-triggered workflow, validates its origin and event data, retrieves the current Mimecast resource when necessary, and routes the normalized event. If no notification exists, use scheduled polling or a supported report instead.

Implementation sequence

Verify the Mimecast product-specific notification capability
Receive the notification in a protected Martini endpoint
Validate the event and correlate it to a Mimecast resource
Retrieve current details when the notification is not complete
Apply routing and authorization rules
Write the result and record the event key

Common Mimecast integration patterns

Pattern 1: Synchronize Mimecast directory data

When to use this pattern

Use this pattern when Mimecast Users, Groups, or Domains must be reconciled with Microsoft 365, Okta, or another identity and administration system. It supports scheduled comparison, controlled updates, and auditability without assuming that every directory operation is available in every tenant.

Integration direction
Mimecast
Martini
Okta
Example Mapping
Mimecast FieldCanonical FieldTarget Field
User identifierexternalUserIdOkta user profile ID
User statuslifecycleStatusOkta account status
Group namegroupNameOkta group name
Domain namemanagedDomainMicrosoft 365 domain
Martini implementation pattern

A scheduled Martini workflow retrieves Mimecast Users, Groups, and Domains, compares them with the target directory, and calculates additions, changes, and removals. Validation rules prevent unauthorized or destructive changes, deterministic keys make replay safe, and failures are isolated for retry rather than advancing the synchronization checkpoint.

Martini capabilities used
  • workflows
  • scheduling
  • API consumption
  • data mapping
  • business rules
  • error handling

Pattern 2: Reconcile Mimecast message activity

When to use this pattern

Use this pattern for delivery investigations, failed-message reporting, daily message-volume reconciliation, and security operations dashboards. It is appropriate when the required Mimecast message-tracking or reporting resource supports filtered collection retrieval.

Integration direction
Mimecast
Martini
Splunk
Example Mapping
Mimecast FieldCanonical FieldTarget Field
Message identifiersourceMessageIdevent.id
Delivery statusdeliveryStatusevent.status
Event timestampoccurredAtevent.time
Sender or recipientmailParticipantevent.actor
Martini implementation pattern

A scheduler starts a workflow with a bounded time window or persisted watermark. Martini retrieves and paginates Mimecast results, removes unnecessary message content, normalizes status and timestamps, enriches events with tenant context, and sends them to Splunk or an operational database. Retries use backoff, while the watermark advances only after successful downstream writes.

Martini capabilities used
  • scheduled workflows
  • API consumption
  • pagination orchestration
  • data transformation
  • mapping
  • retry handling

Pattern 3: Route archive investigations to a case system

When to use this pattern

Use this pattern for legal, compliance, employee mailbox, records-retrieval, or security investigations that require a controlled interface to Mimecast archive search and retrieval operations.

Integration direction
ServiceNow
Martini
Mimecast
Example Mapping
Mimecast FieldCanonical FieldTarget Field
Search criteriaarchiveQueryMimecast archive search request
Case identifierinvestigationIdMimecast correlation metadata
Archive message identifiermessageIdServiceNow work note reference
Result timestampretrievedAtServiceNow activity timestamp
Martini implementation pattern

Martini exposes a restricted REST API for approved search requests, validates the caller and query scope, invokes the applicable Mimecast archive operation, paginates results, and returns or stores only the permitted data. It creates a correlated ServiceNow case, protects sensitive message content, and routes long-running or failed requests to controlled retry and review paths.

Martini capabilities used
  • API exposure
  • API consumption
  • authentication and authorization
  • data mapping
  • business rules
  • error handling

Pattern 4: Process held-message or security events

When to use this pattern

Use this pattern when a Mimecast product exposes the required notification or polling operation for held messages, security events, or delivery failures. Because general webhook support was not confirmed, the implementation must document whether it uses polling or a product-specific callback.

Integration direction
Mimecast
Martini
ServiceNow
Example Mapping
Mimecast FieldCanonical FieldTarget Field
Held message identifiersourceEventIdServiceNow correlation key
Reason or policy resultsecurityReasonincident category
Message timestampeventTimeincident occurred time
Severitypriorityincident priority
Martini implementation pattern

Martini receives a verified notification or polls the relevant Mimecast resource, validates the event, enriches it with current details, and applies severity and routing rules. It creates or updates a ServiceNow incident using a deterministic correlation key, avoids repeating release or other non-idempotent actions, and records failed events for bounded retry.

Martini capabilities used
  • webhook-triggered workflows when confirmed
  • scheduled polling
  • API consumption
  • business rules
  • data mapping
  • duplicate prevention

Applications commonly integrated with Mimecast

Mimecast data can be orchestrated with adjacent identity, productivity, service management, customer, and security platforms. The exact direction and operations depend on the Mimecast service, tenant permissions, selected API version, and the capabilities of the target application.

Application Scenario Direction Martini Pattern
Microsoft 365 Align directory users and domains with Microsoft 365 administration and correlate Mimecast message-tracking or email-security data with mail-flow operations. Microsoft 365 → Martini → Mimecast Use scheduled REST API workflows to retrieve and compare Users, Groups, and Domains, apply approved changes, and send message or security reporting to Microsoft 365-related operational processes. Store regional endpoints and credentials in protected configuration and make directory changes idempotent.
Salesforce Relate delivery issues, security notifications, or customer-related email events to customer and account workflows. Mimecast → Martini → Salesforce Poll or retrieve the applicable Mimecast message or security resources, normalize recipient and event data, apply customer-correlation rules, and create or update Salesforce records through its API with deterministic keys and retry handling.
ServiceNow Create incidents or service requests from held messages, delivery failures, security events, and archive investigations. Mimecast → Martini → ServiceNow Use a scheduled Mimecast polling workflow or a verified product-specific notification, validate the event, map it to a ServiceNow incident or request, and retain source identifiers to prevent duplicate tickets. Optional approval actions can invoke controlled Mimecast operations.
Splunk Centralize Mimecast message, threat, administrative, and reporting data for security analytics and correlation. Mimecast → Martini → Splunk Retrieve the relevant Mimecast API resources in bounded time windows, transform them into Splunk-compatible events, enrich them with tenant and operation metadata, and route failures to a retry or reconciliation workflow.
Jira Create investigation or remediation issues from Mimecast operational and security events. Mimecast → Martini → Jira Use Mimecast REST polling or an explicitly verified notification mechanism, map severity and correlation fields to Jira issues, and use a source-event key to make issue creation replay-safe.
Okta Coordinate identity lifecycle and access-related changes with Mimecast directory Users and Groups. Okta → Martini → Mimecast Compare Okta lifecycle changes with Mimecast directory resources, validate permissions and destructive operations, and apply only approved user or group updates through the applicable Mimecast API version.
Microsoft Sentinel Feed Mimecast security and message telemetry into cloud SIEM detection and response workflows. Mimecast → Martini → Microsoft Sentinel Retrieve supported Mimecast security or reporting data, normalize event timestamps and severity, enrich the payload, and deliver it to the Sentinel ingestion surface or an approved intermediary with bounded retries and audit logging.

How to build a Mimecast integration in Martini

Objective

Establish the correct Mimecast regional endpoint and authentication model for the selected API resource.

Instructions in Martini

  • Identify whether the operation uses Mimecast API 2.0 or legacy API 1.0
  • Configure the tenant's regional API host as environment data
  • Store OAuth credentials, application keys, access keys, tokens, and signing secrets in Martini secrets
  • Request only the permissions required by the workflow

Objective

Select an event, notification, API-led request, or scheduled trigger based on what the Mimecast product actually supports.

Instructions in Martini

  • Use a scheduler for polling, reconciliation, reporting, or archive searches
  • Use a webhook-triggered workflow only after confirming a product-specific Mimecast notification
  • Use a Martini REST API when an internal application needs controlled archive or security access
  • Define the polling window or source watermark

Objective

Call the appropriate Mimecast REST resource and collect complete results without exceeding service or tenant constraints.

Instructions in Martini

  • Invoke the documented service-specific endpoint
  • Apply date filters, query filters, and narrow archive search criteria
  • Process endpoint-specific pagination or continuation markers
  • Capture source identifiers and correlation information without logging sensitive content

Objective

Coordinate retrieval, validation, enrichment, target writes, and checkpoint management in a maintainable Martini workflow.

Instructions in Martini

  • Separate authentication, retrieval, transformation, and delivery stages
  • Route invalid or unauthorized requests to a controlled error path
  • Use reusable workflow logic for common pagination and correlation behavior
  • Advance a checkpoint only after downstream processing succeeds

Objective

Convert Mimecast responses into a canonical model suitable for the target application or data store.

Instructions in Martini

  • Map Users, Groups, Domains, Messages, Held messages, or Archive messages explicitly
  • Normalize timestamps, statuses, identifiers, and severity values
  • Remove unnecessary message bodies, recipients, URLs, or attachment content
  • Validate required fields before writing to the target

Objective

Enforce tenant permissions, data-minimization requirements, routing decisions, and replay safety.

Instructions in Martini

  • Apply least-privilege and authorization rules to archive and administrative operations
  • Use deterministic correlation keys for incidents, reports, and directory updates
  • Require approval or additional validation for destructive changes and message actions
  • Avoid retrying non-idempotent operations without a replay strategy

Common Mimecast data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
UsersSynchronize Mimecast directory users, reconcile identity data, and support controlled administration workflows.Microsoft 365, Okta, ServiceNowMartini retrieves Users through the applicable REST resource, compares identifiers and status, applies validation and idempotency rules, and optionally submits approved changes.
GroupsAlign directory groups and membership-related administration with identity or business systems.Okta, Microsoft 365, ServiceNowMartini retrieves and normalizes group data, detects changes, protects destructive operations, and writes only permitted updates through the selected Mimecast API.
DomainsReconcile managed email domains with tenant administration and mail-flow configuration.Microsoft 365, internal configuration databases, ServiceNowMartini polls Domains, compares regional or tenant configuration, applies business rules, and records changes with an audit correlation key.
MessagesInvestigate delivery, tracking, security, reporting, and operational email activity.Splunk, Microsoft Sentinel, ServiceNow, operational databasesMartini retrieves filtered message collections, paginates through results, removes unnecessary sensitive content, maps metadata, and sends replay-safe downstream events.
Held messagesReview messages held by Mimecast controls and route approved investigation or release processes.ServiceNow, Splunk, internal review applicationsMartini can poll or invoke documented operations, validate authorization and business rules, create a correlated case, and avoid repeating non-idempotent actions.
Archive messagesSupport archive searches, legal or compliance requests, mailbox investigations, and records retrieval.ServiceNow, internal case applications, approved evidence storesA Martini API or workflow accepts restricted search criteria, invokes the applicable archive resources, paginates results, minimizes retained content, and applies access controls.

Authentication and security considerations

Version-aware authentication

Mimecast API 2.0 uses OAuth 2.0-style application authorization where available. Older API 1.0 operations may require application credentials, access credentials, request identifiers, timestamps, expiration values, and signed requests. The workflow must use the authentication model required by the selected resource.

Secrets and permissions

Store client secrets, tokens, application keys, access keys, and signing secrets in protected Martini secrets or environment configuration. Use region-specific API hosts and request only the permissions required for each integration domain.

Sensitive email data

  • Restrict archive, message, and held-message operations to authorized workflows and callers.
  • Minimize retention of message bodies, recipients, URLs, and attachments.
  • Never write credentials, tokens, signing secrets, or unnecessary message content to logs.

Operational considerations for Mimecast integrations

Pagination and synchronization

Collection endpoints may return limited result sets. Use documented pagination, continuation markers, filters, date windows, and persisted watermarks. Advance a checkpoint only after successful downstream processing.

Rate limits and retries

Design for throttling, transient HTTP errors, and regional service interruptions. Use bounded retries with backoff and avoid repeating non-idempotent operations without a replay strategy.

Idempotency and auditability

Use source identifiers and deterministic correlation keys for directory updates, incident creation, message actions, and reporting. Record operation type, tenant or region context, correlation identifiers, outcome, and workflow execution details.

Schema and API changes

Mimecast service areas can evolve independently. Use tolerant JSON mappings, validate required fields, monitor response changes, and test API-version or permission changes before production rollout.

Archive and attachment scope

Use narrow archive criteria and confirm attachment behavior for the selected operation. A general-purpose file or attachment API was not confirmed.

Why use Martini instead of scripts or point-to-point integrations?

Orchestration instead of isolated scripts

Mimecast integrations often combine authentication, pagination, filtering, transformation, target writes, and audit requirements. Martini represents that behavior as maintainable workflows and APIs rather than distributing it across one-off scripts.

Reusable integration logic

Common pagination, validation, mapping, checkpoint, and error-handling behavior can be reused across directory, message, archive, and security workflows while service-specific rules remain explicit.

Controlled enterprise access

Martini can expose a restricted API façade for archive or security operations, apply authorization and data-minimization rules, and keep credentials in protected configuration. This reduces the need for each consuming application to implement Mimecast authentication independently.

Operational reliability

Scheduled execution, retry paths, idempotency keys, monitoring, and deployment configuration provide a consistent operational model for Mimecast integrations that would otherwise be maintained separately in point-to-point code.

Frequently asked questions

How can Mimecast be integrated with enterprise systems?

Mimecast is primarily integrated through service-specific REST APIs covering administration, directory, email security, archive, continuity, monitoring, and reporting. Implementations can use API 2.0 OAuth-style authorization where available, legacy signed requests for API 1.0 operations, scheduled polling, and product-specific notifications when officially supported.

Can Martini integrate with Mimecast?

Yes. Martini can consume Mimecast REST APIs, authenticate using the model required by the selected API version, orchestrate scheduled or API-led workflows, transform Mimecast data, and expose controlled APIs for archive or security processes. No native Martini Mimecast connector is documented in the supplied materials.

Do I need a connector to integrate Mimecast with Martini?

No. A dedicated Mimecast connector is not required. Martini can integrate using Mimecast's confirmed REST APIs and authentication mechanisms, with scheduled polling or a product-specific notification or callback only where that capability is officially available.

Is there any extra Lonti cost to integrate Mimecast with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate Mimecast. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from Mimecast, cloud infrastructure, or other third-party systems based on subscription, usage, and deployment model.

Which Mimecast APIs and authentication methods should be used?

Use the documented REST resource for the required Mimecast service. Prefer API 2.0 OAuth-style authorization when the operation is available; older API 1.0 operations may require application and access credentials, request metadata, and signed requests. The region-specific host and required permissions must be confirmed for each tenant.

Can Martini receive Mimecast events through webhooks?

General webhook coverage for all Mimecast objects and email events was not confirmed. A particular Mimecast product may provide a notification, event feed, or callback, but it must be verified for the required event. Otherwise, Martini can use scheduled polling, reporting, or another documented REST operation.

How does synchronization with Mimecast work?

Martini can run scheduled workflows that retrieve filtered collections, paginate through results, normalize the data, and write it to identity, service-management, security, reporting, or database systems. Persisted timestamps, message identifiers, or other watermarks support incremental synchronization, while deterministic keys prevent duplicate downstream records.

How does Martini handle Mimecast mapping, errors, and duplicate operations?

Martini maps Mimecast's service-specific responses into canonical and target models, applies validation and business rules, and can use bounded retries with backoff for transient failures. Checkpoints should advance only after successful writes, while source identifiers and deterministic correlation keys support idempotency. Sensitive message content and credentials should be excluded from logs.