Service Update
| Availability | June 24th, 2022 |
| Product(s) | Email Security Cloud Gateway (CG) |
| Who's affected | Email Security Cloud Gateway (CG), Administrators |
Overview
Microsoft is ending support for the Azure Active Directory Graph API.
What's changing
To allow for continued service, Mimecast will migrate all Azure Active Directory Synchronization integrations to the MS Graph API. For Mimecast to do so seamlessly, you need to grant the required API permissions to the Azure application you created for the Azure Active Directory Synchronization to your Mimecast account. This action should be completed as soon as possible and no later than June 14, 2022, to avoid the risk of service disruption.
To allow for continued service for your Azure Active Directory Synchronization integration when Microsoft ends support for the Azure AD Graph API, Mimecast needs to migrate all Azure Active Directory connections to the MS Graph API.
Recommended actions
For Mimecast to be able to seamlessly migrate your Azure Active Directory Synchronization integration to the MS Graph API, you need to grant the required API permissions to the Azure application you created for the Azure Directory Synchronization to your Mimecast account.
The below steps should be followed to grant the correct permissions for the Microsoft Graph API:
- Log in to the Microsoft Azure Portal.
- Navigate to Azure Active Directory.
- Click on the App registrations menu item.
- Search for the application created for Azure Directory Synchronization to your Mimecast account.
- Open the application and click on the API Permissions option in the left-hand menu.
- Click on the Add a permission button.
- Select the Microsoft Graph option.
- Click on the Application permissions button.
- Expand the Directory section.
- Select the Directory.Read.All option.
- Expand the User section.
- Select the User.Read.All option.
- Click on the Add permissions button. The permissions should look like the example below:
- Click on the Grant admin consent for… button.
- To confirm consent, click on the Yes button.
The below steps should be followed to remove permissions / revoke Admin Consent for the Microsoft Graph API
Removing Permissions:
- Log in to the Microsoft Azure Portal.
- Navigate to Azure Active Directory | App Registrations
- Search for the application created for Azure Directory Synchronization to your Mimecast account.
- Open the application and click API Permissions.
- Click the
icon next to the permission you want to remove.
- Click Remove permission.
- A confirmation pop-up will show to verify the action required.
Revoking Admin Consent :
- Log in to the Microsoft Azure Portal.
- Navigate to Azure Active Directory | App Registrations.
- Search for the application created for Azure Directory Synchronization to your Mimecast account.
- Open the application and click API Permissions.
- Click the
icon next to the permission you want to revoke.
- Click Revoke Admin Consent.
- A confirmation pop-up will show to verify the action required.
These permissions are necessary for your Azure Active Directory Synchronization integration to continue working correctly when Mimecast migrates your Directory connections to the MS Graph API. To avoid the risk of service disruption, please make these changes by June 14, 2022.
Monitoring
Mimecast will monitor if the permissions have been granted and will actively migrate integrations to the MS Graph API from June 1, 2022, onwards.
You can use the Test Connection feature to see if your Azure Active Directory integration has been migrated. We recommend testing from June 1, 2022.
To run a Directory Connection Test:
- Log in to the Mimecast Administration Console
- Navigate to Users & Groups | Directory Synchronization.
- Select the Directory Synchronization.
- Click on the Test Connection button.
Synchronization with Azure AD Graph API Synchronization with Microsoft Graph API
Deployment Schedule
Migrations started on April 19, 2022, and have been completed on June 24, 2022. On this date, Mimecast has also updated this article to assist with resolving failing integrations due to incorrectly configured API permissions.
Current Status: Completed.
Comments
Please sign in to leave a comment.