Click New Role, and then in the Properties section, configure these settings:
Role Name — Enter a unique name for the role. For example, Arctic Wolf App Role.
Description — Enter a description for the role.
In the Application Permissions section, clear all of the checkboxes, and then select these permissions:
Account Menu > Logs > Read
Monitoring Menu > Attachment Protection > Read
Monitoring Menu > Impersonation Protection Logs > Read
Monitoring Menu > URL Protection > Read
Click Save and Exit.
Create the API application
Note:
Based on your cloud firewall settings, add firewall exceptions for Arctic Wolf IP addresses if necessary. To see all the IP addresses that you must allowlist, sign in to the Arctic Wolf Unified Portal, click Resources > Allowlist Requirements, and then view the IP addresses in the section for your product.
Description — Enter a description for the API application.
Technical Point of Contact — Enter the name of the person who Mimecast should contact if necessary. For example, the active user configuring the API application.
Email — Enter the email address of the technical point of contact. This email address must be valid in your Mimecast directory.
Click Save.
In the Credentials generated successfully dialog, copy the Client ID and Client Secret values, and then save them in a safe, encrypted location.
You will provide these values to Arctic Wolf later.
Note:
This is the only time that the client secret value is available.
Click Close.
Optional: Set admin IP address ranges:
Note:
You must set admin IP address ranges to apply IP address restrictions. For example, a public IP address range.
In the navigation menu, click Account > Account Settings.
In the User Access and Permissions section, in the Admin IP Ranges field, enter the IP addresses.
CAUTION:
Do not only enter Arctic Wolf IP addresses. This restricts sign in permissions for all other accounts except for managed service providers.
Click Save.
Provide Mimecast credentials to Arctic Wolf
Note:
Time-based events are polled with a delay to make sure that data is available. For new deployments, Arctic Wolf begins polling and reviewing activity from approximately one hour prior to configuration success. If API credentials fail, for example due to expired credentials, Arctic Wolf notifies you and requests a new set of credentials. After receiving refreshed credentials, Arctic Wolf can only retrieve data from the previous 12 hours. Provide refreshed credentials within 12 hours of expiry to enable complete data polling and coverage.