Who this is for: Microsoft 365 / Entra ID administrators, and users who see "Need admin approval", "Approval required" or a 403 Forbidden error when signing in to a Microsoft 365 account in Mail Attachment Downloader.
Your organization does not let users approve third-party apps themselves. An administrator has to grant consent to Mail Attachment Downloader once for the organization. After that, users can sign in normally.
A 403 on a shared mailbox usually means that the person who signed in does not have permission to open that mailbox. Signing in alone is not enough.
| Application name | Mail Attachment Downloader |
| Application (client) ID | 327a7151-62e7-4ab6-af0a-55120ca90505 |
| App type | Multi-tenant public client (desktop app). It has no client secret, and it only acts as the signed-in user (delegated permissions). |
| Redirect URI | http://localhost |
| Permission | Why it is needed |
|---|---|
Mail.ReadWrite | Reads messages and attachments. Moves, flags or marks messages when a download rule asks for it. |
Mail.Send | Sends mail for rules that send or forward email. |
offline_access | Keeps the connection working in the background (Windows service) without asking the user to sign in again. |
Mail.ReadWrite.Shared, Mail.Send.Shared | Only requested when the account is set up to access a shared or delegated mailbox. |
openid, profile | Standard sign-in. Microsoft adds these automatically. |
Legacy EWS protocol only: EWS.AccessAsUser.All (Office 365 Exchange Online). Microsoft is retiring EWS in Exchange Online, so we recommend using the Microsoft Graph protocol instead.
Choose one of these options. Each one needs a Global Administrator, Cloud Application Administrator or Application Administrator.
Use this option if the user already submitted an approval request.
Replace YOUR_TENANT with your tenant ID or primary domain (for example, contoso.onmicrosoft.com). Then open the link while you are signed in as an administrator.
Standard mailboxes:
https://login.microsoftonline.com/YOUR_TENANT/v2.0/adminconsent?client_id=327a7151-62e7-4ab6-af0a-55120ca90505&scope=https://graph.microsoft.com/Mail.ReadWrite https://graph.microsoft.com/Mail.Send offline_access&redirect_uri=http://localhost
Standard and shared mailboxes:
https://login.microsoftonline.com/YOUR_TENANT/v2.0/adminconsent?client_id=327a7151-62e7-4ab6-af0a-55120ca90505&scope=https://graph.microsoft.com/Mail.ReadWrite https://graph.microsoft.com/Mail.Send https://graph.microsoft.com/Mail.ReadWrite.Shared https://graph.microsoft.com/Mail.Send.Shared offline_access&redirect_uri=http://localhost
After you click Accept, the browser goes to http://localhost and may show "This site can't be reached". This is expected. Consent has been granted.
This option works if the app already appears in your tenant, for example after a user's first sign-in attempt.
Note: This option grants the permissions that users have requested so far. If shared mailbox access is needed and nobody has requested it yet, use Option B with the shared-mailbox link.
In Enterprise applications > Mail Attachment Downloader > Properties:
Also check that no Conditional Access policy blocks this app, the user's device or the user's location. Look in Sign-in logs and filter by the application ID to find the exact reason for a failure.
A shared mailbox has no sign-in of its own. Instead, a real user signs in, and that user must have permission to open the shared mailbox.
Add-MailboxPermission -Identity shared@yourdomain.com -User person@yourdomain.com -AccessRights FullAccess -InheritanceType All.Shared permissions are requested.Please contact support and include: