Connect Application: Enabling Active Directory Synchronization Using the Mimecast Synchronization Engine

Document created by user.oxriBaJeN4 Employee on Apr 14, 2016Last modified by user.oxriBaJeN4 Employee on Feb 28, 2018
Version 25Show Document
  • View in full screen mode

Applies To...

 

This page applies to new clients connecting with Mimecast using the Connect Application. If you are not using the Connect Application, click here.

 

Walkthrough

 

If you have an On Premise or Hybrid Active Directory, you can automatically manage your users and groups by synchronizing your directory with the Mimecast Synchronization Engine. The Mimecast Synchronization Engine app runs on your network to securely back up changes in your Active Directory to our cloud.

Active Directory synchronization using the Mimecast Synchronization Engine doesn't synchronize passwords or provide any authentication functionality. If you require authentication for Mimecast applications, use Exchange EWS or ADFS domain authentication functionality

To synchronize your directory using the Mimecast Synchronization Engine, you'll need to complete the following tasks:

  1. Download the Mimecast Synchronization Engine app from  Application Downloads and install it on a local server.
  2. Create a user account that can query your Active Directory.
  3. Connect the app to your Active Directory with the account credentials provided.
  4. Bind the app to our cloud with the account credentials provided.
  5. Complete the synchronization in the Connect Application.
  6. Validate the Mimecast Synchronization Engine installation.

Installing the Mimecast Synchronization Engine

 

To synchronize your directory, install the Mimecast Synchronization Engine app on a local server. Follow the installation instructions listed in the Installing / Upgrading the Mimecast Synchronization Engine page.


The Mimecast Synchronization Engine must be installed on a Windows Server:

 

Alternatively, to install the Mimecast Synchronization Engine app from the Connect Application:

  1. Click on the Platform | Synchronize Your Directory menu item.
  2. Click the Start button in the Task Steps for Mimecast Synchronization Engine section.
  3. Click the Download link. The Mimecast Synchronization Engine will begin to download.
  4. Save the ZIP file to a Windows server that has access to your domain controller.
  5. Open the ZIP file and launch the installer. Follow the onscreen instructions in the wizard.
  6. Ensure our service layer hosts are accessible, and the app has outbound access to these hosts on port 443. The app communicates securely over HTTPS with our regional service layer hosts.
  7. When you're ready, click the Next button. The Configure the Synchronization Engine page is displayed where you'll connect your Active Directory with our cloud.

 

Creating a User Account to Connect with Active Directory

 

A user account is required in order to synchronize your Active Directory with us. Set this user account to:

  • Have a mailbox associated with it.
  • Have a password that doesn’t expire.
  • Not require a password change on the first log in.
  • Use the naming format of "mimecast_mse@customerprimarydomain.tld".
  • Have read access to the parts of your directory that require synchronization.
  • Be a member of the Organization Management group, if you have mail-enabled public folders.
If you intend to use other services provided by the Mimecast Synchronization Engine, you may need to configure additional Exchange permissions. For more information, consult the Mimecast Synchronization Engine page.

Configuring the Mimecast Synchronization Engine

 

To connect the Mimecast Synchronization Engine app to your Active Directory:

  1. Open the Site Configure Accounts utility on the server where the Mimecast Synchronization Engine is installed.
  2. Register the app by completing the dialog as follows:

    Field / OptionDescription
    SMTP AddressEnter the email address displayed under "Account Credentials" in the Connect Application. This is the user account that will be used to access your Active Directory. Ensure that you followed the above "Creating a User Account to Connect with Active Directory" step to create this user before proceeding.
    PasswordEnter the password for the email address displayed in the Configure the Mimecast Synchronization Engine page in the Connect Application.
    Use Exchange ImpersonationEnsure this option is selected. Although this is not used for Active Directory synchronization, it will be used if you ever use any of the Exchange-related Synchronization Engine tasks as described in the Mimecast Synchronization Engine space.
    Directory OptionSelect the default "Microsoft Active Directory" option from the drop-down list.
  3. Click the Apply button to start the site bind process (described below).

 

Binding the Mimecast Synchronization Engine to the Cloud

 

A binding is a security association between the Mimecast Synchronization Engine app and the Mimecast cloud. The binding is configured using the Site Bind process on the server where the Mimecast Synchronization Engine in installed. This binding is required so you can:

  • View the Mimecast Synchronization Engine site in the Administration Console.
  • Start scheduled tasks (e.g. Active Directory Synchronization).
Any Mailbox Unreachable errors can be ignored for this task.

Before binding your Mimecast Synchronization Engine site, you'll need to ensure:

  1. The server where the Mimecast Synchronization Engine is installed has outbound connectivity using HTTPS (port 443) to Mimecast.
  2. You have noted the email address and password as displayed in the Connect Application under "Account Credentials".

 

To bind the Mimecast Synchronization Engine app to our cloud:

  1. Enter the following account credentials in the Site Configure utility in the app:
    Field / OptionDescription
    Email AddressEnter the email address displayed in the Configure the Mimecast Synchronization Engine page in the Connect Application.
    PasswordEnter the password displayed in the Configure the Mimecast Synchronization Engine page in the Connect Application.
  2. Click the Bind button.

 

The Connect Application automatically performs the following steps:

  • Finds the Mimecast account associated with the domain name of the email address entered.
  • Binds the site to the discovered account.
  • Validates that the Microsoft mailbox can successfully query the specified Directory Type.
  • Saves the binding information to local storage.

 

Once the binding is configured:

  1. Click on the Synchronize button in the Configure the Mimecast Synchronization Engine page of the Connect Application.
  2. Review your directory synchronization details in the summary page that displays. We'll synchronize your directory shortly after.
  3. View your completed installation in the Mimecast Administration Console in the Services | Synchronization Engine Sites page.

 

Validating the Mimecast Synchronization Engine Installation

 

The Mimecast Synchronization Engine server picks up the site, and starts scheduling Active Directory synchronization, within two minutes of the site being bound. We'll validate the connection is up and running for you.

 

To validate the connection yourself:

  1. Log on to the Mimecast Synchronization Engine server that the Active Directory Sync connection is configured to use.
  2. Navigate to the Service Log directory. This is by default %ProgramData% \Mimecast Synchronisation Engine\logs\.
  3. Open the current day's Log File.
  4. Search for the string "calling siteConfig."

 

If you see a line similar to the one below, Active Directory synchronization is being applied.

DEBUG|02062015 08:46:37,319| 4|mseservice|

AntiCorruptionScheduler|+ event taskId: 2972, name: Task Description, next occurrence: 02/06/2015

13:00:00

If you don't see this line, you should see an error message indicating why the Active Directory synchronization cannot be applied. This is normally caused by a networking issue preventing the Mimecast Synchronization Engine connecting to the Mimecast API.

 

Resetting The Mimecast Synchronization Engine Account

 

If you've forgotten your Mimecast Synchronization Engine password, or you want to reset it, you can do so in the Administration console if your logon has a Basic Administrator (or greater) role. See Understanding Administrator Roles for more details.

1 person found this helpful

Attachments

    Outcomes