Authentication Profiles - Enabling Cloud Authentication

This article contains information on preparing and managing Mimecast Cloud Passwords, including configuring password complexity, creating passwords, defining authentication profiles, setting permitted IP ranges, and applying profiles to enhance security and user access control.

Cloud Password Authentication is available for all customers and is typically used when your organization wants to manage and use specific Mimecast passwords when accessing Mimecast.

Preparing Cloud Passwords

Defining Password Complexity and Expiration

These settings affect Mimecast Cloud Passwords only and are applied to all users in the organization.

You can configure Password Complexity and Expiration settings, by using the following steps:

  1. Log in to the Mimecast Administration Console.
  2. Navigate to Account | Account Settings.
  3. Expand the Password Complexity and Expiration section.
  4. Change the Settings as required.

Cloud passwords are separate from any passwords managed by your identity provider (such as Azure AD or other SSO providers). Changing a Mimecast cloud password does not change a domain or SSO-managed password, and vice versa.

Create a Mimecast Cloud Password

Setting the Cloud Password this way automatically revokes all active Registered Applications tokens, forcing that user to re-authenticate. This includes tokens created by other authentication mechanisms. See Registered Applications.

You can create a Mimecast cloud password, by using the following steps:

  1. Log in to the Mimecast Administration Console.
  2. Navigate to Users & Groups | Internal Directories.
  3. Select the Primary Domain of the user you want to set a cloud password for.
  4. Select the Primary Email Address of the user you want to set a Cloud Password for.
  5. In the permissions section of the Email Address Update page, enter and confirm the new password.
  6. Optionally select whether the:
  • Passwords should expire or not, using the Password Never Expires option.
  • Users should be required to change their passwords the next time they log in, using the Force Change at Logon setting.

For administrator accounts that currently sign in with SSO only, you can use these steps to create Mimecast cloud passwords once an appropriate authentication profile that allows cloud authentication has been applied to those addresses.

Create an Authentication Profile

An Authentication Profile is referenced by a Mimecast Application Setting, which is in turn applied to a group of users. It is possible to edit existing Authentication Profiles or create new ones, depending on your requirements.

You can create or edit an existing Authentication Profile, by using the following steps:

  1. Log in to the Mimecast Administration Console.
  2. Navigate to Users & Groups | Applications.
  3. Select Authentication Profiles.
  4. To edit an existing Authentication Profile, select it from the list. Alternatively, to create a new profile, select the New Authentication Profile button.
  5. Add a Description. This will be used to reference the profile when it is later selected in an Application Setting.
  6. Select the option you would like to apply from the Allow Cloud Authentication drop-down list.

This option controls whether users whose accounts use this profile can sign in with Mimecast cloud passwords in addition to any SSO or SAML settings you configure. For example, you can set a profile to always allow cloud authentication, or to allow cloud authentication only for continuity, so that users can fall back to cloud login if your SSO service is unavailable.

Unless the Enforce SAML Authentication for Administration Console setting is used, Cloud Authentication will always be available for the Mimecast Administration Console, regardless of the option selected here.

If SAML enforcement is later enabled for the Administration Console, cloud sign-in for administrators is no longer available through that enforced flow. To reintroduce cloud login, you can either disable SAML enforcement or create a separate authentication profile that has SAML disabled and cloud authentication enabled, then apply that profile to specific administrator accounts that should be able to sign in with Mimecast passwords.

  1. Select a time period from the Authentication TTL drop-down list. When the time elapses and the binding expires, the application uses the credentials originally entered by the user to automatically request a new binding. The user is only prompted to re-enter a password if the password has changed.

This is applicable to Mimecast for Outlook, Mimecast for Mac, and Mimecast Mobile only and defines the length of time a binding issued after a successful authentication is valid for.

  1. Select Save and Exit to complete the configuration.

Defining Permitted IP Ranges

To add a layer of security, Mimecast provides optional Permitted IP Range settings for the Mimecast Administration Console, End User Applications, and Gateway Authentication attempts.

You can configure Permitted IP Ranges by using the following steps:

  1. Log in to the Mimecast Administration Console.
  2. Navigate to Account | Account Settings.
  3. Expand the User Access and Permissions section.
  4. In the Admin IP Ranges text box, enter the public IP address ranges you want to restrict access to in CIDR format, one range per line.

Configuring Permitted IP Ranges for End User Applications

You can configure Permitted Application Login IP Ranges by using the following steps:

  1. Log in to the Mimecast Administration Console.
  2. Navigate to Users & Groups | Applications.
  3. Click Authentication Profiles.
  4. To edit an existing Authentication Profile, select it from the list. Alternatively, to create a New Profile, select the New Authentication Profile button.
  5. Select the check box to enable Permitted Application Login IP Ranges.
  6. In the Permitted Application Login IP Ranges text box, enter the public IP address ranges you want to restrict access to in CIDR format, one range per line.
  7. Select Save and Exit to apply the new settings.

Configuring Permitted IP Ranges for Gateway authentication using SMTP or POP

You can configure Permitted Gateway Login IP Ranges by using the following steps:

  1. Log in to the Mimecast Administration Console.
  2. Navigate to Users & Groups | Applications.
  3. Select Authentication Profiles.
  4. To edit an existing Authentication Profile, select it from the list. Alternatively, to create a New Profile, select the New Authentication Profile button.
  5. Select the check box to enable Permitted Gateway Login IP Ranges.
  6. In the Permitted Gateway Login IP Ranges text box, enter the public IP address ranges you want to restrict access to in CIDR format, one range per line.
  7. Select Save and Exit to apply the new settings.

Other Options

An Authentication Profile is applied to a group of users. Each user can only have one effective profile at a time. Consequently, it may be useful to add additional authentication options to your Authentication Profile.

For administrators, this allows you to design separate profiles for different scenarios. For example, you can keep an administrators profile that allows cloud authentication for continuity, while using another profile that enforces SSO or SAML for regular users. By assigning the appropriate profile to each group, selected admin accounts can still sign in using Mimecast cloud passwords if your identity provider is unavailable.

Applying the Authentication Profile to an Application Setting

Once your Authentication Profile is complete, you need to reference it in an Application Setting for it to be applied, by using the following steps:

  1. Log in to the Mimecast Administration Console.
  2. Navigate to the Users & Groups | Applications menu item.
  3. Select the Application Setting that you want to use.
  4. Use the Lookup button to find the Authentication Profile you want to reference and click the Select link on the lookup page.
  1. Select Save and Exit to apply the change.

Next Steps

You can test your configuration and verify that your Authentication Profile has been configured correctly by using the following steps:

  1. Open or navigate to a Mimecast application.
  2. Enter your primary email address.
  3. You should be able to select and enter a Cloud Password.
  4. Enter your Cloud Password and log in. You should be granted access to the application.

During an SSO or domain outage, you can use this same cloud password flow to access Mimecast, provided your account’s authentication profile allows cloud authentication. If you cannot remember your cloud password, use the usual password reset option for Mimecast cloud login before attempting to sign in.

For administrator access to the Mimecast Administration Console in environments that use Azure AD (Entra), sign in using Mimecast cloud authentication rather than Azure basic authentication. Open a private browser window and go to https://login.mimecast.com/u/login/?gta=apps#/login, then enter your primary email address and Mimecast cloud password.

Was this article helpful?
1 out of 1 found this helpful

Comments

0 comments

Please sign in to leave a comment.