Federated Account Administration

Document created by user.oxriBaJeN4 Employee on Sep 11, 2015Last modified by user.Yo2IBgvWqr on Jul 5, 2017
Version 3Show Document
  • View in full screen mode

Customers and/or Partners/Service Providers with more complex email management environments may select Federated Account Administration services for the organization to provide additional options and benefits as described below.


  • Policy Inheritance, so that sub-accounts that have opted-in to this functionality will respect Policies of the Master and/or Group accounts.
  • Federated Administration, to allow Administrators that belong to the Federated Administration Domain to gain access to nested accounts that have opted-in to this functionality, facilitating administration of multiple accounts from within the same browser window.


This setup is useful for organizations and/or Partners/Service Providers with multiple segregated Mimecast accounts. The Master and Group account Administrators can control specific (Inheritable) Policies that must be respected by nested accounts. In addition, Administrators of nested accounts can only access content and settings for their own sub-account.


Logging in


  1. Open your web browser and enter the URL (web address) as provided by the Connect team.
  2. Add your account email address, then click the Next button:


  3. In the password field, enter your Mimecast Cloud password, or if logging on with Directory service details, enter your Domain (Network) password.

    Note: The Master Administrator or any Federated Administrator can only logon using a cloud password. Directory passwords are not supported for Master accounts and Federated Administrators.


  4. Click the Login button. The Dashboard is displayed.


Master Accounts


Many of the menu options, and the functionality contained within them, are the same as the standard Administration Console. The following menu options are available in the Master Console:


AccountAnnouncementsDisplays latest product Announcements from Mimecast.
DashboardThe default landing page for the Master Console, as defined above.
HierarchyThis menu is used to manage the hierarchical structure of the Federated Account Administration setup.
LogsTracks activity in the Mimecast Account.
RolesManages Administrator permissions for the Console. By default, only the Master Administrator Role is available on the Master console.
SettingsControls settings for the Mimecast Account.
GatewayOutboundProvides a list of Authorized Outbound IP Addresses used by the Federated Account Administration setup
DirectoriesInternalProvides a read-only view of the Internal Domains of the nested accounts as well as the Federated Administration Domain belonging to the Master
ImportAllows Administrators to import data to Mimecast. Used for creating new addresses for the Federated Administration Domain.


Note: Some differences between the Federated Account Administration Master Console and the standard Administration Console are detailed below.


Account Settings


Four additional options are available within Account | Settings:




Enable Policy Inheritance

Allows Mail Processing nested accounts to consider the Policies configured on Group and/or Master accounts as long as all relevant accounts have this option enabled as well.


Note: This is enabled by Mimecast support.

Enable Federated Administration

Enables additional Roles to allow Federated Administration of Group and Mail Processing nested accounts.


Note: This is enabled by Mimecast support.

Enable Federated Content View

Allows Federated Administrators to have Content View permissions for all nested accounts that have enabled Federated Administration.


Note: This is enabled by Mimecast support.

Federated Administration DomainSpecifies the Domain name used for Federated Administration.


Accounts Hierarchy


The Accounts | Hierarchy section enables Master Administrators to view and manage the Hierarchy of the Federated Account Administration Setup. For more information view the Account Structures article.


Accounts Roles


Once the Basic Administrator has been allocated on the Master account, and with Federated Administration being enabled on the Group and/or Mail Processing accounts, the Basic Administrator can access the nested accounts by first logging into the Master account, then navigating to Account | Roles:




A new button at the top of the page, Federated Administrators Access, is used to access the nested accounts:




Click the Switch to Account button for the relevant account.


To navigate back to the Master account or to another account, navigate to Account | Roles on the nested account, and click the Federated Administrator Access button once again to switch to the appropriate account.


Group Accounts and Mail Processing Accounts


These nested accounts are controlled by the Master Account.


Account Settings


In order to enable Federated Administration, the appropriate checkbox must be selected within Account | Settings:




In effect, this allows the account to opt-in to Federated Account Administration and can be enabled by Super Administrators or Partner Administrators.


Note: Mimecast support will enable the option for the Group accounts.


View the full article for more information on Policy Inheritance.