Last updated: September 29, 2026
Guide for Microsoft 365 and Google Workspace admins
This is an English translation for convenience. If it differs from the Spanish version, the Spanish version prevails.
This page is for people who manage a Microsoft 365 tenant (Microsoft Entra ID) or a Google Workspace domain and want their users to use Strix Mail with their work mailbox. Other users do not need any of this.
The details marked as pending are completed before Strix Mail goes live.
What Strix Mail does with the mailbox
Strix Mail is a web email client: it reads the mailbox over IMAP and sends over SMTP or the provider's send API, just like desktop Outlook, Apple Mail or Thunderbird. Each person connects their own mailbox and only that person sees it inside Strix Mail. What data is stored, where and for how long is described in the Privacy Policy.
Microsoft 365
Why an admin is needed
Since November 2025, Microsoft's default consent policy does not let users in an organization approve on their own apps that request mailbox access (such as IMAP.AccessAsUser.All), even if the publisher is verified. That is why, the first time someone in your organization wants to connect their mailbox, an admin has to grant admin consent. It is done once per tenant.
Application details
| Item | Value |
|---|---|
| Name | Strix Mail |
| Publisher | 3-101-084807 Sociedad Anónima (Microsoft verified publisher) |
| Application (client) ID | [[COMPLETAR: ENTRA_CLIENT_ID]] |
| Website | https://mail.strixapps.com |
| Type | Multitenant, delegated permissions only |
Permissions requested
All of them are delegated: the app acts on behalf of the person who signs in and only on their mailbox. Strix Mail does not request application permissions and cannot read other mailboxes in the tenant.
| Permission | API | Why |
|---|---|---|
openid, email, profile |
Microsoft identity platform | To know which account was connected (address and name). |
offline_access |
Microsoft identity platform | To keep syncing when the person does not have the app open (refresh token). |
IMAP.AccessAsUser.All |
Office 365 Exchange Online | To read and organize mail over IMAP: folders, messages, flags, moving and deleting. |
SMTP.Send |
Office 365 Exchange Online | To send mail over SMTP as the person. |
Mail.Send |
Microsoft Graph | To send mail without depending on SMTP AUTH being enabled on the mailbox. |
The final list is the one shown on Microsoft's consent screen. If the app ever needs a new permission, Microsoft asks for consent again.
Granting admin consent
You need a role that can grant consent (Global Administrator, Cloud Application Administrator or Application Administrator).
- Open this link with your admin account: [[COMPLETAR: ADMIN_CONSENT_URL]]
- Review the permissions and choose Accept ("Consent on behalf of your organization").
- Done: everyone in your organization can now connect their mailbox from Settings → Accounts → Add account → Microsoft.
You can also do it from the Microsoft Entra admin center: Identity → Applications → Enterprise applications → Strix Mail → Permissions → Grant admin consent.
Limiting who can use it
If you do not want the whole tenant to use it: in Enterprise applications → Strix Mail → Properties, turn on Assignment required? and then, under Users and groups, add the people who may use it.
SMTP AUTH
If your tenant has SMTP AUTH disabled (for example, with security defaults), sending goes through Microsoft Graph (Mail.Send) and nothing needs to change. We do not ask you to enable SMTP AUTH.
Revoking access
- For the whole organization: in the Entra admin center, Enterprise applications → Strix Mail → Properties → Delete (or turn off Enabled for users to sign in?). Issued tokens stop working and Strix Mail can no longer sync any mailbox in the tenant.
- For one person: remove them from the app's Users and groups (if assignment is required) or revoke their sessions from their user page (Revoke sessions).
- Each person can revoke their own access at myapps.microsoft.com or account.microsoft.com, and disconnect the mailbox from Settings → Accounts in Strix Mail.
Revoking access does not delete the data Strix Mail has cached. For that, the person disconnects the mailbox (its cache is deleted) or writes to us; see Delete your data.
Google Workspace
Strix Mail requests the https://mail.google.com/ scope from Google (the only one that enables IMAP and SMTP with OAuth), plus openid and email to know which account was connected. The use of that data complies with the Google API Services User Data Policy, including the Limited Use requirements; details are in the Privacy Policy.
- Allowing the app: in the Admin console, Security → Access and data control → API controls → Manage Third-Party App Access → Configure new app, search for the client ID [[COMPLETAR: GOOGLE_CLIENT_ID]] and mark it as Trusted (or Limited if you want to restrict it).
- Revoking access: on that same screen, mark it as Blocked. Each person can revoke their own access at myaccount.google.com/permissions.
Contact
For security or compliance questions (questionnaires, data processing agreements): [email protected]. To exercise rights over personal data: [email protected].