Microsoft 365: How IT can grant permissions to grant access

Microsoft 365: How IT can grant permissions to grant access

Microsoft 365: How IT Grants Mail Attachment Downloader Access (Admin Consent & Shared Mailboxes)

Who this is for: Microsoft 365 / Entra ID administrators, and users who see "Need admin approval", "Approval required" or a 403 Forbidden error when signing in to a Microsoft 365 account in Mail Attachment Downloader.

Symptoms

  • Microsoft sign-in succeeds, then a page says "Approval required" or "Need admin approval" and asks for a reason to send to IT. Submitting the request does not complete the sign-in.
  • The connection fails with 403 Forbidden or Access is denied, often on shared mailboxes.

Why this happens

Your organization does not let users approve third-party apps themselves. An administrator has to grant consent to Mail Attachment Downloader once for the organization. After that, users can sign in normally.

A 403 on a shared mailbox usually means that the person who signed in does not have permission to open that mailbox. Signing in alone is not enough.

Application details for IT

Application nameMail Attachment Downloader
Application (client) ID327a7151-62e7-4ab6-af0a-55120ca90505
App typeMulti-tenant public client (desktop app). It has no client secret, and it only acts as the signed-in user (delegated permissions).
Redirect URIhttp://localhost

Permissions requested (all delegated, Microsoft Graph)

PermissionWhy it is needed
Mail.ReadWriteReads messages and attachments. Moves, flags or marks messages when a download rule asks for it.
Mail.SendSends mail for rules that send or forward email.
offline_accessKeeps the connection working in the background (Windows service) without asking the user to sign in again.
Mail.ReadWrite.Shared, Mail.Send.SharedOnly requested when the account is set up to access a shared or delegated mailbox.
openid, profileStandard sign-in. Microsoft adds these automatically.

Legacy EWS protocol only: EWS.AccessAsUser.All (Office 365 Exchange Online). Microsoft is retiring EWS in Exchange Online, so we recommend using the Microsoft Graph protocol instead.

Choose one of these options. Each one needs a Global Administrator, Cloud Application Administrator or Application Administrator.

Option A: Approve the pending request

Use this option if the user already submitted an approval request.

  1. Sign in to the Microsoft Entra admin center.
  2. Go to Identity > Applications > Enterprise applications > Admin consent requests.
  3. Open the request for Mail Attachment Downloader, review the permissions, and click Review permissions and consent. Then click Accept.

Replace YOUR_TENANT with your tenant ID or primary domain (for example, contoso.onmicrosoft.com). Then open the link while you are signed in as an administrator.

Standard mailboxes:

https://login.microsoftonline.com/YOUR_TENANT/v2.0/adminconsent?client_id=327a7151-62e7-4ab6-af0a-55120ca90505&scope=https://graph.microsoft.com/Mail.ReadWrite https://graph.microsoft.com/Mail.Send offline_access&redirect_uri=http://localhost

Standard and shared mailboxes:

https://login.microsoftonline.com/YOUR_TENANT/v2.0/adminconsent?client_id=327a7151-62e7-4ab6-af0a-55120ca90505&scope=https://graph.microsoft.com/Mail.ReadWrite https://graph.microsoft.com/Mail.Send https://graph.microsoft.com/Mail.ReadWrite.Shared https://graph.microsoft.com/Mail.Send.Shared offline_access&redirect_uri=http://localhost

After you click Accept, the browser goes to http://localhost and may show "This site can't be reached". This is expected. Consent has been granted.

Option C: From the Enterprise application

This option works if the app already appears in your tenant, for example after a user's first sign-in attempt.

  1. Go to Enterprise applications and search for Mail Attachment Downloader or the client ID above.
  2. Go to Security > Permissions and click Grant admin consent for <your organization>.

Note: This option grants the permissions that users have requested so far. If shared mailbox access is needed and nobody has requested it yet, use Option B with the shared-mailbox link.

Step 2: Check the Enterprise application settings

In Enterprise applications > Mail Attachment Downloader > Properties:

  • Enabled for users to sign in? must be Yes.
  • If Assignment required? is Yes, add every user who will sign in under Users and groups.

Also check that no Conditional Access policy blocks this app, the user's device or the user's location. Look in Sign-in logs and filter by the application ID to find the exact reason for a failure.

Step 3: Shared mailboxes (fixes most 403 Forbidden errors)

A shared mailbox has no sign-in of its own. Instead, a real user signs in, and that user must have permission to open the shared mailbox.

  1. Give the user Full Access to the shared mailbox.
    • Exchange admin center: Recipients > Mailboxes > (shared mailbox) > Delegation > Read and manage (Full Access) > add the user.
    • Or use PowerShell:
      Add-MailboxPermission -Identity shared@yourdomain.com -User person@yourdomain.com -AccessRights FullAccess -InheritanceType All
    • Allow up to 60 minutes for the permission to take effect.
  2. Test the permission in Outlook on the web: sign in as the user and use Open another mailbox to open the shared mailbox. If this fails, Mail Attachment Downloader will fail too.
  3. In Mail Attachment Downloader:
    • Set the account's email address to the shared mailbox address.
    • When the Microsoft sign-in page appears, sign in as the user who has Full Access. Do not sign in as the shared mailbox.
    • Make sure shared-mailbox access is enabled for the account so the .Shared permissions are requested.

Step 4: Reconnect in Mail Attachment Downloader (user)

  1. Make sure you are on the latest version of Mail Attachment Downloader.
  2. Open the account settings and set the protocol to Microsoft Graph.
  3. Clear the saved sign-in (clear the cache), then sign in again. Use the account IT gave Full Access to.
  4. This time the sign-in should finish without the "Approval required" page.

Still not working?

Please contact support and include:

  • The mailbox address entered in the program and the account used on the Microsoft sign-in page.
  • Whether the mailbox is a user mailbox or a shared mailbox.
  • The error text or a screenshot. If possible, include the Correlation ID and Request ID from the Microsoft error page, or the matching entry from Entra Sign-in logs.