Aware - New System Roles and Manage System Settings Permission Enhancement - FAQ

This article contains information on new Aware system roles, how Mimecast roles map to them, their permissions, and how role changes or assignments affect Aware access.

Q What new Aware roles are being introduced?
A Four new system roles: Partner Admin, Sys Admin:Basic, Sys Admin:Read Only, and Basic Admin. These complement the existing Global Admin, Search and Discover Admin, Signal Admin, Spotlight Admin, and Data Management Admin roles.
Q How does the mapping of existing Mimecast administrator roles to these new Aware roles work?
A

Aware roles are automatically assigned based on the user's Mimecast administrator role per the mapping table below. The mapping is evaluated on each login, so any change to a user's Mimecast role triggers a corresponding change in their Aware role assignment.

Mimecast Role Aware Role
Global Sys Admin, Super Administrator, Full Administrator Global Admin
Partner Administrator Partner Admin
Sys Admin - Server Ops, Sys Admin - SD Full, Sys Admin - Messaging Basic, Sys Admin - Product Management Basic, Sys Admin - Messaging Full, Sys Admin - SD Basic. Sys Admin:Basic
Sys Admin - Read Only CS, Sys Admin - Read Only Basic Sys Admin:Read Only
Basic Administrator Basic Admin
Discovery Officer Search and Discover Admin
Q What is the permissions structure for these new roles?
A

The permission structure for the new roles is described below:

Permission Partner Admin Sys Admin: Basic Sys Admin: Read Only Basic Admin
SPOTLIGHT
Manage Custom Reports
View Custom Reports
Access MimecastIQ Gen AI
View Message Content (Spotlight)
SIGNAL
Manage Policies
Manage Rules
Manage Events
View Policies and Rules
View Events
View Message Content (Signal)
SEARCH & DISCOVER
Create Searches
Manage Search Results
View Search Results
Access MimecastIQ Gen AI (S&D)
Redact Content
View Message Content (S&D)
DATA MANAGEMENT
Manage Data Holds
Create Retention Policies
Remove User Data
SYSTEM SETTINGS
Manage System Settings
Q What happens to existing custom Aware role assignments when a user receives a mapped Mimecast role?
A If the user receives a Mimecast administrator role assignment, their existing Aware role assignment is replaced by the Mimecast→Aware mapped role. If the Mimecast role is later removed, the user loses Aware access entirely and must be reassigned manually by an Aware Global Admin.
Q What happens if a user's Mimecast role changes?
A The change is reflected in their Aware role assignment on subsequent login. Active sessions continue under the previous role until the next login.
Q What happens if a new user has a Mimecast role that is not in the mapping table?
A They will not receive Aware access automatically. To grant access, either assign them an appropriate Mimecast administrator role, or have an Aware Global Admin add them to a system or custom Aware role manually.
Q Can the new system roles be edited?
A No. The four new system roles are system-defined with fixed permission sets.
Q Do permission changes via Mimecast role updates take effect immediately?
A Aware role changes take effect on the user's next login. If a user loses their mapped Mimecast role, Aware access is removed immediately rather than waiting for the next login.

See Also...

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.