This article contains information on new Aware system roles, how Mimecast roles map to them, their permissions, and how role changes or assignments affect Aware access.
| Q | What new Aware roles are being introduced? | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| A | Four new system roles: Partner Admin, Sys Admin:Basic, Sys Admin:Read Only, and Basic Admin. These complement the existing Global Admin, Search and Discover Admin, Signal Admin, Spotlight Admin, and Data Management Admin roles. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Q | How does the mapping of existing Mimecast administrator roles to these new Aware roles work? | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| A |
Aware roles are automatically assigned based on the user's Mimecast administrator role per the mapping table below. The mapping is evaluated on each login, so any change to a user's Mimecast role triggers a corresponding change in their Aware role assignment.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Q | What is the permissions structure for these new roles? | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| A |
The permission structure for the new roles is described below:
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Q | What happens to existing custom Aware role assignments when a user receives a mapped Mimecast role? | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| A | If the user receives a Mimecast administrator role assignment, their existing Aware role assignment is replaced by the Mimecast→Aware mapped role. If the Mimecast role is later removed, the user loses Aware access entirely and must be reassigned manually by an Aware Global Admin. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Q | What happens if a user's Mimecast role changes? | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| A | The change is reflected in their Aware role assignment on subsequent login. Active sessions continue under the previous role until the next login. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Q | What happens if a new user has a Mimecast role that is not in the mapping table? | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| A | They will not receive Aware access automatically. To grant access, either assign them an appropriate Mimecast administrator role, or have an Aware Global Admin add them to a system or custom Aware role manually. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Q | Can the new system roles be edited? | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| A | No. The four new system roles are system-defined with fixed permission sets. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Q | Do permission changes via Mimecast role updates take effect immediately? | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| A | Aware role changes take effect on the user's next login. If a user loses their mapped Mimecast role, Aware access is removed immediately rather than waiting for the next login. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Comments
Please sign in to leave a comment.