Continuity - Prerequisites

This article contains information on configuring and managing a Continuity event in Mimecast, including detection algorithms, inbound and outbound traffic monitoring, failure thresholds, and notification settings to ensure email continuity during disruptions.

Overview

Mimecast's Continuity solution ensures uninterrupted email access; email remains accessible, and no data is lost during outages.
Ensuring that you meet the prerequisites described in this article will reduce the amount of administration required during the Continuity event itself, to ensure that you are in the best possible position to deal with a disruption or outage.
Using this and the following Related Articles, you will be able to:

Step 1 -  Ensure your Contact Information is Correct

You must ensure that the contact information that Mimecast has for you is kept up-to-date so that SMS alerts or email notifications can be sent.

Step 2 - Check your Continuity Functionality and Permissions

  • You have Continuity as part of your Mimecast subscription.
  • You need to have a role of Basic Administrator or higher for the Mimecast Administration Console.
  • If you're using a custom role, this must have Write access to the following Mimecast Administration Console menu items:

You will need to grant the following permissions to complete the setup:

Continuity Permissions
MS Entra App Permission Common Name Application /Delegate Identifier Permission Description MS KB Permissions Reference
full_access_as_app full_access_as_app 00000002-0000-0ff1-ce00-000000000000 Use Exchange Web Services (EWS) with full access to all mailboxes. N/A
Domain.Read.All Read domains dbb9058a-0e50-45d7-ae91-66909b5d4664 Allows the app to read all domain properties without a signed-in user. Microsoft Graph permissions reference - Microsoft Graph | Microsoft Learn
User.Read Sign in and read user profile e1fe6dd8-ba31-4d61-89e7-88639da4683d Allows users to sign-in to the app, and allows the app to read the profile of signed-in users. It also allows the app to read basic company information of signed-in users. Microsoft Graph permissions reference - Microsoft Graph | Microsoft Learn

Step 3 - Check your Microsoft Exchange Settings

  • Ensure that you have enabled Cached Exchange Mode in Outlook Exchange Account Settings.
  • If you have a Microsoft Exchange Web Services On-Premises deployment, ensure you have:
    • Set it up to allow inbound HTTPS access from Mimecast to your organization's Client Access Server (/ews/exchange.asmx). This will need to be done in your environment; follow a process similar to that detailed in Microsoft's Application Security Groups article. 
    • Shared the credentials of a mailbox with the Application Impersonation management role with Mimecast.
  • If you have a Microsoft 365 Standalone or Hybrid Environment, a Continuity Connector is required to securely link your Microsoft 365 Tenant to Mimecast.

Step 4 - Configure Mimecast Service Monitor

Ensure you have configured the Mimecast Service Monitor, which can be used to monitor email services and issue SMS/email alerts when configured mail flow thresholds are breached.
It is also used by our Support teams as an alternate method of contact, in the event of a severe outage.
See Service Monitor - Monitoring Services and bookmark Mimecast Service Status, which provides the latest service information.

Step 5: Configure Cloud Password for Administrator Authentication

Ensure that you have set up an Administrator email address(es) that has a Cloud password, to ensure Mimecast services (e.g., Mimecast Administration Console) can be logged into during a Continuity event.

It's not possible to set up a Cloud password for Administrators who have been set up to use a Single Sign-On authentication method.
Ensure that you have at least one Administrator set up to use a Cloud password, without Single Sign On enforced.

Step 6 - Ensure End Users Can Authenticate

If you use Network Directory Authentication, you need to consider how your end users will be able to access Mimecast services if there are connection failures and Directory unavailability.

We recommend that when configuring your Directory Integration via Directory Synchronization, you ensure that the selected Connector has an Alternate Host specified, as a fallback.
If possible, you should set up a secondary Directory Integration instance as a backup. This means that if the primary instance is unavailable, authentication will continue to work seamlessly.

It may be necessary to upload a spreadsheet to import Cloud passwords. See Spreadsheet Import.
Once complete, these passwords will need to be communicated to the users. As email communication will be unavailable, another method should be considered to issue these passwords to users.
Alternatively, it is possible to configure the Cloud passwords beforehand and issue them to the user before Continuity events.

It's not possible to set up a Cloud password for users who have been set up to use a Single Sign-On authentication method.

You will need to change the Authentication Profile settings to remove Single Sign On enforcement and allow Cloud passwords.

Step 7 - Configure and Enable End User Tools

You should consider which End User Applications and services you wish to have available to your End Users during a Continuity event.
All End User applications can be controlled from the Mimecast Administration Console, via Services | Applications, which can be applied to specific sets of users, or all users simultaneously.

You and your users can access Mimecast Knowledge Base articles or use Mimecast University Training to learn how to use the required end-user applications.

  • Mimecast Personal Portal: Permission may be required to access this webmail service. For ease of use, you could add a Desktop shortcut to the Mimecast Personal Portal for your users.

You should also check that several users can successfully log into the Mimecast Personal Portal to confirm that the settings are correct.

The connection state reported by Microsoft Outlook is not 100% reliable. Therefore, to prevent entering Continuity mode unnecessarily, we recommend that this option be disabled for Mimecast for Outlook.

  • Mimecast for Mac: This application allows your Mac users to continue to send and receive emails during a Continuity event, and view Archived Folders.
  • Mimecast for Mobile: This application allows your Android and iOS users to continue to send and receive emails during a Continuity event, and view Archived Folders.

The Mimecast Synchronization Engine or Sync & Recover offers features that enhance the end-user experience with Continuity.

This is an additional Archiving package, and is available for Microsoft Exchange-based environments only.

  • Sync & Recover and Mimecast Synchronization Engine provide features that can greatly enhance the end-user continuity experience for unavoidable occasions when the corporate Microsoft Exchange server is unavailable, or users cannot access the corporate network.
  • Mailbox Folder Replication: Exchange mailbox folders greatly affect how end users organize and find important emails and attachments. Mailbox Metadata Synchronization (Folder Replication) provides the ability to replicate emails in the same folder structure that end users are familiar with to Mimecast.

If using Folder Replication in your environment, Exchange Folders Live View is available via the Mimecast Personal Portal. This gives end users a view of the messages stored within their archive in the same familiar folder structure used in their Exchange mailbox. They can find, view, reply to, and forward emails using this Live View, just like when using their standard Exchange mailbox.

Folder Replication will also display the information from historical email data before implementing Mimecast if this information has been ingested.

  • Calendars: Exchange calendars are an extensively utilized feature of Microsoft Outlook, allowing end users to track important meetings and activities.
    Using calendar replication, end users logging onto the Mimecast Personal Portal have read-only access to this data during a Microsoft Exchange outage.
  • File Archive: If enabled, Mimecast can provide users with access to files stored in user home drives and shared network drives. The files are accessible through Mimecast for Outlook and Mimecast Personal Portal.

Step 8 - Configure connections to Mimecast Data Centers

 It is important to ensure that you allow connections to the appropriate ports from the entire Mimecast Regional IP Ranges, and that they are mapped to the correct destination on your network. See Data Centers & URLs.

Step 9 - Ensure Journaling is Configured

If you already have a journal connector configured and your organization is journaling to Mimecast using SMTP to capture your messages, you do not need to make any changes to this configuration.
Messages will queue as per your SMTP configuration. Make sure you have the capacity to queue emails for a sufficient period. See Configuring Journaling for more inforation.

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.