MithiDocs

Getting access to Workmail mailbox data

Part 1: Secure Credential Generation & Configuration Reference

Configure an impersonation role directly within your AWS WorkMail organization to establish permissions for mail retrieval.

  1. Open the AWS WorkMail Console and select your organization.
  2. In the navigation pane, click on Impersonation roles and choose Create impersonation role.
  3. Role Name: Assign a descriptive identifier (e.g., ews-impersonation-role).
  4. Access Type: Select Read-only (or Full access if your workflow requires message modification/sending).
  5. Rules: Add an explicit rule with an ALLOW effect targeting all users (*).
  6. Save the role and copy its generated Impersonation Role ID (UUID format).

Part 2: Create the IAM User & Attach Permissions

To safely programmatically download emails, we create a dedicated IAM user. This user needs explicit permissions to assume the WorkMail impersonation role created in Part 1, allowing the script to safely access mailboxes.

1. Create the IAM User

Navigate to the IAM Console → Users → Create user.

User Name: workmail-ews-impersonation.

Access Type: Programmatic access only (do not grant console access).

2. Attach the Least-Privilege Policy

Attach a custom inline policy to the user, replacing the placeholder below with your actual Impersonation Role ID:

3. Generate Access Keys

Open your newly created IAM user → Security credentials tab → Create access key.

Select use case: Application running outside AWS.

Securely download or copy your Access Key ID (starting with AKIA...) and Secret Access Key.

Security Note: Your Secret Access Key is shown only once. Please keep these credentials secure and send them back via a secure transmission channel.

Part 3: Register the following information

AWS Account IDEnter your 12 digit account ID
RegionEnter the region of your service
Access Key IDEnter Access key starting with AKIA...
Secret Access KeyEnter Secret access key
Organization IDEnter your WorkMail Organization ID
Impersonation Role IDEnter Role ID created in Part 1