For IT administrators

Deploy and manage PostMount across your organization

Approve PostMount once, roll it out from Microsoft Store or Intune and set it up centrally with Group Policy — users get a ready-to-use app: signed in with their Windows account, with the shared mailboxes they have access to.

English · Ukrainian · PostMount 1.0.27 and later

PostMount-ADMX.zip
  • PostMount.admx
  • en-US / uk-UA
  • 11 policies in 6 groups
  • Works in the Microsoft Store version

Rollout in four steps

From approval to a ready app on every computer — without visiting each one.

1

Approve PostMount

Microsoft requires an administrator to approve apps that work with mail. Do it once for the whole organization — see below.

2

Deploy the app

From Microsoft Store, or with Intune as a Microsoft Store app — see below.

3

Set the policies

Add the ADMX templates to Group Policy or Intune and set what you need — see below.

4

Users are ready

On PCs joined to Microsoft Entra ID, PostMount signs in with the Windows account by itself.

Managed settings

11 policies in six groups. Each one comes with a detailed description right in the policy editor; a setting set by policy is locked in the app with a “managed by your organization” note.

Zero-touch minimum — three policies

1 · Organization key
Licenses and organization membership assign themselves.
2 · Automatic sign-in
On by default: Entra-joined PCs sign in with the Windows account — no sign-in window.
3 · Shared mailboxes
List them once — everyone gets exactly the shared mailboxes they have access to.

Sign-in

  • Sign in automatically with the Windows account key
    AutoSignIn
    Silent single sign-on on PCs joined to Microsoft Entra ID (or hybrid joined), through the Windows authentication broker. Device compliance goes to Conditional Access. On by default.
  • Allow sign-in only for these organizations
    AllowedTenants
    Tenant IDs or email domains — personal accounts and other organizations are refused.

Mailboxes and access

  • Connect shared mailboxes key
    SharedMailboxes
    One list for the whole organization. On each PC, PostMount checks which of them the user has access to and connects only those; the rest are skipped. Rechecked every 4 hours; a mailbox is removed again when access is revoked or the address is removed from the list. Mailboxes users add themselves are never touched.
  • Mailbox access from the network
    AccessScope
    This computer only (default), allowed IP addresses, or the local network — locked in the app.
  • Allowed IP addresses
    AllowedIps
    Single IPv4 addresses or CIDR subnets that may connect when access is set to “Allowed IP addresses”.

Mail gateway

  • Turn off the mail gateway
    DisableGateway
    The SMTP relay for printers, scanners and ERP does not start and cannot be turned on.

Data protection

  • Turn off mailbox export
    DisableExport
    No export to PST, EML, MBOX or MSG — mailbox content stays in Microsoft 365 (DLP).

User interface

  • Start PostMount at Windows sign-in
    Autostart
    Email apps work right after sign-in.
  • Interface language
    Language
    Windows language or one of the 24 interface languages.
  • Theme
    Theme
    Windows setting, Light or Dark.

Licensing

  • Join the organization key
    OrgKey
    Every user of a managed PC joins your organization in the PostMount portal and gets its licenses. More below.

How to deploy the templates

Pick the scenario that fits your infrastructure.

Domain (Active Directory)

Copy the files to the Central Store — the policies become available on every domain controller and workstation:

\\<domain>\SYSVOL\<domain>\Policies\ PolicyDefinitions\PostMount.admx …\PolicyDefinitions\en-US\PostMount.adml

Manage them in the Group Policy Management Console (GPMC), linking GPOs to the OUs you need.

Microsoft Intune

In the Intune admin center:

  1. Devices → Configuration → Create → Import ADMX.
  2. Upload PostMount.admx together with en-US\PostMount.adml.
  3. Create a configuration profile from the imported template and assign it to your groups.

The PostMount settings appear among the profile options.

Standalone computer

Copy the files to the local policy store:

C:\Windows\PolicyDefinitions\ PostMount.admx …\en-US\PostMount.adml

Manage via gpedit.msc → Administrative Templates → PostMount.

Tip. If the domain has an active Central Store, the policy editor takes templates only from there. After changing policies run gpupdate /force and restart PostMount — settings are read at start-up. Without Group Policy you can write the same values to the registry (Intune remediation, scripts): lists accept a REG_MULTI_SZ value, for example:

HKLM\SOFTWARE\Policies\PostMount SharedMailboxes (REG_MULTI_SZ) = support@contoso.com sales@contoso.com

Deploying the app with Intune

PostMount is distributed through Microsoft Store and updates automatically. Microsoft Store →

Add the app

  1. Intune admin center → Apps → Windows → Add.
  2. App type: Microsoft Store app (new).
  3. Search for PostMount (ID 9PN0511DJX9K) and select it.
  4. Assign it as Required to your device or user groups.

What comes with it

  • Windows Firewall rules for the PostMount ports (domain and private networks) are created by the package itself — no firewall policy needed.
  • Out of the box the mail servers listen on this computer only; network access is a separate decision (the “Mailbox access from the network” policy).
  • Autostart at sign-in is on by default (the “Start PostMount” policy).

Deploying with the organization key

The key removes the manual user list: everyone who signs in to PostMount on a managed computer automatically joins your organization and gets a license as soon as a seat is free.

Where to get the key

In the customer portal → Organization → the “Organization ID · join key for deployment” block, format XXXXX-XXXXX-XXXXX-XXXXX-XXXXX.

Keep the key secret: anyone who has it can add users to your organization and occupy paid seats. If it leaks, regenerate it in the portal — the old key stops working at once, existing members are not affected.

Group Policy or registry

The “Join the organization” policy (the “Licensing” group of these templates), or the registry value directly:

HKLM\SOFTWARE\Policies\PostMount OrgKey (REG_SZ) = XXXXX-XXXXX-XXXXX-XXXXX-XXXXX

The key is read live, so it also applies to copies that are already installed. A single computer can also join in the app: Monitor → Organization → Join.

What happens next

  1. The user signs in to PostMount with their Microsoft 365 account and becomes an organization member at once (visible in the portal).
  2. If a paid seat is free, the license is issued by that same request.
  3. If seats run out, the user keeps their own trial and is marked “over seats” in the portal — add seats and the license follows automatically.
  4. Members of another organization are never pulled in by the key.

Ready to roll out PostMount?

Download the ADMX templates, approve PostMount for your organization and deploy it from Microsoft Store.

© 2026 SkylFlow · Custom Software & IT Solutions