Granting necessary permissions to the app

Granting necessary permissions to the app

Granting necessary permissions to the app

Mail Attachment Downloader signs in to Gmail, Google Workspace, Outlook.com and Microsoft 365 with OAuth: you sign in on your mail provider's own page and it gives the app a set of permissions (also called scopes). If the provider gives fewer permissions than the app asked for, the app can't open your mailbox and shows "Some permissions weren't granted".

This article explains why that happens and how to fix it. The fixes are listed from quickest to most involved.

Why it happens

  • A permission was left unticked. Google's consent page shows some permissions as checkboxes, and they may start out unticked. If you click Continue without ticking them, Google doesn't grant them.
  • You signed in with a different account. If your browser is signed in to several accounts, it's easy to pick the wrong one on the sign-in page.
  • An earlier, smaller grant is being reused. If you allowed the app before with fewer permissions, the provider may reuse that grant instead of asking again.
  • Your organization restricts apps. For work or school accounts, an administrator may have to approve the app, or may have turned off IMAP or Exchange access for your mailbox.

1. Sign in again and allow everything

  1. In Mail Attachment Downloader, click Connect And Download (or Test Connection in the mail server settings) to sign in again.
  2. On the sign-in page, choose the account you're setting up in the app, not another account your browser is signed in to.
  3. On the consent page, allow every permission. On Google, tick every checkbox before clicking Continue.

2. Remove the app's earlier access, then sign in again

This makes the provider ask for every permission again instead of reusing an earlier grant.

  • Google (Gmail, Google Workspace): go to myaccount.google.com/permissions, select Mail Attachment Downloader and click Delete all connections (or Remove access).
  • Microsoft personal accounts (Outlook.com, Hotmail, Live): go to account.live.com/consent/Manage, select Mail Attachment Downloader and click Remove these permissions.
  • Microsoft work or school accounts (Microsoft 365): go to myapps.microsoft.com, find Mail Attachment Downloader and choose Manage your application > Revoke permissions. If you don't see that option, your administrator has to do it (see step 3).
  • Other providers: look in your account's security or privacy settings for "connected apps", "third-party access" or "app permissions", and remove Mail Attachment Downloader.

Then sign in again as in step 1.

3. Work or school accounts: ask your administrator

If you still can't grant every permission, your organization probably controls which apps can access mail. Send your administrator this article, and the details from the app (click Copy details in the "Some permissions weren't granted" window). They may need to:

  • Microsoft 365: in the Microsoft Entra admin center, go to Identity > Applications > Enterprise applications, open Mail Attachment Downloader, and under Permissions click Grant admin consent. Also check that IMAP (or EWS, for Exchange accounts) is enabled for your mailbox in the Microsoft 365 admin center (Users > Active users > your user > Mail > Manage email apps).
  • Google Workspace: in the Google Admin console, go to Security > Access and data control > API controls > Manage Third-Party App Access and set Mail Attachment Downloader to Trusted. Also check that IMAP is enabled under Apps > Google Workspace > Gmail > End User Access.
  • Other providers: allow the app to access mail on your behalf, and make sure IMAP access is enabled for your mailbox.

If your organization doesn't allow our app at all, it can register its own app and use it instead: see Custom app registration in Microsoft 365 (Entra) or Custom app registration in Google Workspace.

What the permissions are for

The window lists the permissions that weren't granted in plain words. Click Show details to see the exact scope names, for example:

Shown asScopeNeeded for
Read and manage your Gmailhttps://mail.google.com/Downloading from Gmail and Google Workspace over IMAP. Google only offers full mail access for IMAP.
Read and manage your mailbox over IMAPIMAP.AccessAsUser.AllDownloading from Outlook.com and Microsoft 365 over IMAP.
Read and manage your mailbox over Exchange (EWS)EWS.AccessAsUser.AllDownloading from Microsoft 365 with the Exchange connection type.
Send email over SMTP / Send email as youSMTP.Send, Mail.SendRules that forward or send email.
Save files to OneDrive / SharePointFiles.ReadWrite.All, Sites.ReadWrite.All, Sites.SelectedRules that upload attachments to OneDrive or SharePoint.

The app only asks for the permissions the features you use need. "Manage" is part of the permission name because mail providers don't offer read-only IMAP access; the app only changes mail when a rule tells it to (for example, to mark emails as read or move them).

Still stuck?

Contact support and include the text from Copy details. It lists the error and which permissions were requested and granted, which is usually enough to tell what's wrong.