Approve PostMount once, roll it out from Microsoft Store or Intune and set it up centrally with Group Policy — users get a ready-to-use app: signed in with their Windows account, with the shared mailboxes they have access to.
English · Ukrainian · PostMount 1.0.27 and later
From approval to a ready app on every computer — without visiting each one.
Microsoft requires an administrator to approve apps that work with mail. Do it once for the whole organization — see below.
Add the ADMX templates to Group Policy or Intune and set what you need — see below.
On PCs joined to Microsoft Entra ID, PostMount signs in with the Windows account by itself.
PostMount reads and sends mail through Microsoft Graph with delegated permissions only: it acts as the signed-in user and reaches only the mailboxes that user already has access to. Microsoft no longer lets users consent to third-party apps that read mail, so a Global Administrator (or Privileged Role / Cloud Application Administrator) approves it once for the tenant.
Approve PostMount for my organizationSign in with an administrator account and accept. After approval the browser may show an empty
localhost page — that is expected, the approval is saved. You can also do it in the Microsoft Entra
admin center → Enterprise applications → PostMount → Permissions → Grant admin consent.
Mail.ReadWrite | Read the user's mail, move, flag and delete messages, save drafts — what IMAP and POP3 clients do. |
Mail.ReadWrite.Shared | The same for shared mailboxes the user has Full Access to. |
Mail.Send | Send mail as the user — what SMTP clients and devices do. |
Mail.Send.Shared | Send as / on behalf of shared mailboxes the user has Send As or Send on Behalf rights to. |
openid, profile, offline_access | Sign-in, user name and staying signed in. |
11 policies in six groups. Each one comes with a detailed description right in the policy editor; a setting set by policy is locked in the app with a “managed by your organization” note.
Pick the scenario that fits your infrastructure.
Copy the files to the Central Store — the policies become available on every domain controller and workstation:
Manage them in the Group Policy Management Console (GPMC), linking GPOs to the OUs you need.
In the Intune admin center:
PostMount.admx together with en-US\PostMount.adml.The PostMount settings appear among the profile options.
Copy the files to the local policy store:
Manage via gpedit.msc → Administrative Templates → PostMount.
Tip. If the domain has an active Central Store, the policy editor takes templates only from there. After changing policies run
gpupdate /force and restart PostMount — settings are read at start-up. Without Group Policy you can write the same values
to the registry (Intune remediation, scripts): lists accept a REG_MULTI_SZ value, for example:
PostMount is distributed through Microsoft Store and updates automatically. Microsoft Store →
9PN0511DJX9K) and select it.The key removes the manual user list: everyone who signs in to PostMount on a managed computer automatically joins your organization and gets a license as soon as a seat is free.
In the customer portal → Organization → the “Organization ID · join key for deployment” block, format XXXXX-XXXXX-XXXXX-XXXXX-XXXXX.
Keep the key secret: anyone who has it can add users to your organization and occupy paid seats. If it leaks, regenerate it in the portal — the old key stops working at once, existing members are not affected.
The “Join the organization” policy (the “Licensing” group of these templates), or the registry value directly:
The key is read live, so it also applies to copies that are already installed. A single computer can also join in the app: Monitor → Organization → Join.
Download the ADMX templates, approve PostMount for your organization and deploy it from Microsoft Store.