Part 1: Secure Credential Generation & Configuration Reference
Configure an impersonation role directly within your AWS WorkMail organization to establish permissions for mail retrieval.
- Open the AWS WorkMail Console and select your organization.
- In the navigation pane, click on Impersonation roles and choose Create impersonation role.
- Role Name: Assign a descriptive identifier (e.g., ews-impersonation-role).
- Access Type: Select Read-only (or Full access if your workflow requires message modification/sending).
- Rules: Add an explicit rule with an ALLOW effect targeting all users (*).
- Save the role and copy its generated Impersonation Role ID (UUID format).
Part 2: Create the IAM User & Attach Permissions
To safely programmatically download emails, we create a dedicated IAM user. This user needs explicit permissions to assume the WorkMail impersonation role created in Part 1, allowing the script to safely access mailboxes.
1. Create the IAM User
Navigate to the IAM Console → Users → Create user.
User Name: workmail-ews-impersonation.
Access Type: Programmatic access only (do not grant console access).
2. Attach the Least-Privilege Policy
Attach a custom inline policy to the user, replacing the placeholder below with your actual Impersonation Role ID:
3. Generate Access Keys
Open your newly created IAM user → Security credentials tab → Create access key.
Select use case: Application running outside AWS.
Securely download or copy your Access Key ID (starting with AKIA...) and Secret Access Key.
Security Note: Your Secret Access Key is shown only once. Please keep these credentials secure and send them back via a secure transmission channel.
Part 3: Register the following information
| AWS Account ID | Enter your 12 digit account ID |
| Region | Enter the region of your service |
| Access Key ID | Enter Access key starting with AKIA... |
| Secret Access Key | Enter Secret access key |
| Organization ID | Enter your WorkMail Organization ID |
| Impersonation Role ID | Enter Role ID created in Part 1 |