# Give every shared mailbox an owner, sign-in boundary, and review cadence

> Shared mailboxes outlive projects and teams unless someone owns membership, direct sign-in, forwarding, retention, licensing, automation, and closure. Govern each mailbox as a business service, not a permanent bucket of delegated access.

- Canonical URL: https://update.dsesecurity.com/updates/give-every-shared-mailbox-owner-signin-boundary-review-cadence/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-17T13:02:00+00:00
- Modified: 2026-08-17T19:22:09+00:00
- Last reviewed by DSE: 2026-08-17
- Resource type: Checklist
- DSE priority: Advisory
- Topics: Business Continuity, Cybersecurity, IT, Microsoft 365 & Identity
- Reading time: 3 minutes

## What you need to know

Shared mailboxes outlive projects and teams unless someone owns membership, direct sign-in, forwarding, retention, licensing, automation, and closure. Govern each mailbox as a business service, not a permanent bucket of delegated access.

## Potentially affected

Exchange Online shared mailboxes and associated user objects, Full Access, Send As and Send on Behalf permissions, automapping, forwarding and inbox rules, mobile access, applications, retention and holds, licenses, inactive owners, external mail, and continuity procedures.

## DSE recommendation

Assign business and technical owners, block direct sign-in, document purpose and data handling, grant delegates through their own licensed identities with least privilege, review membership and configuration, monitor risky changes, and use a controlled closure or transfer process.

## Article

## Source facts: a shared mailbox is accessed through delegated user identities

Microsoft’s [shared-mailbox overview](https://learn.microsoft.com/en-us/microsoft-365/admin/email/about-shared-mailboxes?view=o365-worldwide) describes shared mailboxes for addresses used by multiple people, such as support or reception. It says delegates should access through their own licensed Exchange Online mailboxes and that the associated shared-mailbox account is not intended for direct sign-in. Microsoft instructs administrators to block that sign-in and keep it blocked.

Microsoft’s [recipient-permissions documentation](https://learn.microsoft.com/en-us/exchange/recipients-in-exchange-online/manage-permissions-for-recipients) distinguishes Full Access, Send As, and Send on Behalf. These permissions produce different capabilities: opening mailbox contents is not the same as sending with the mailbox identity. Microsoft also documents licensing and feature conditions that can apply based on mailbox size, archive, hold, Defender, Purview, and other use.

Licensing and service limits change, so the current Microsoft service description and tenant entitlements must be checked. Retention, litigation hold, privacy, records, labor, and industry obligations require qualified governance or legal input. Blocking direct sign-in does not remove delegated access, application access, forwarding, rules, or content already copied elsewhere.

## DSE recommendation: manage the mailbox from request through retirement

Create a register for every shared mailbox: SMTP addresses, purpose, business owner, technical owner, delegates by permission, approved send behavior, applications, forwarding, data classification, retention or hold, license, expected volume, continuity use, review date, and closure trigger. A mailbox without an accountable business owner should be escalated, not automatically preserved forever.

- Establish the sign-in boundary. Verify the associated user object is blocked from direct sign-in and has no known human password in use. Remove unnecessary authentication methods under the supported process. Do not distribute a shared password as a substitute for delegation.

- Grant the minimum permission. Decide separately who must read and manage content, who may send as the mailbox, and who may send on behalf. Use named governed identities or approved groups as supported, avoid nested ambiguity, and require stronger review for mailboxes that authorize transactions or reset accounts.

- Inspect hidden movement. Review mailbox and inbox rules, forwarding, delegates, mobile and application access, connectors, aliases, automatic replies, and approved automation. Confirm external forwarding and OAuth applications comply with policy. Preserve authorized business workflows while removing unexplained paths.

- Design continuity. Define who monitors the mailbox, expected response time, out-of-hours handling, alternate owner, queue or ticket integration, and what happens during owner absence. A mailbox is not a service desk merely because several people can open it.

- Review content governance. Match retention and deletion to approved records requirements, holds, privacy, and business need. Confirm license requirements for the selected features. Limit local exports and personal-folder copies that defeat central governance.

- Retire deliberately. At project or function end, stop new use, communicate replacement addresses, preserve required records, remove delegates and applications, handle aliases and forwarding for a bounded period, and document final disposition. Verify the old identity cannot still receive privileged workflows.

Review high-impact mailboxes more frequently and after owner, team, vendor, application, or business-process change. Monitor permission changes, sign-in enablement, forwarding, unusual sending, rule creation, and administrative modifications through the tenant’s available audit and alerting capabilities. Investigate a mailbox account that authenticates directly.

The review record should distinguish business approval from technical verification. An owner approves who needs what; administrators prove the resulting permissions, sign-in state, rules, licensing, and controls. That separation turns a shared mailbox from an inherited convenience into an accountable communications service.

For the review sample, use both directions: start with delegates and confirm their authorized mailbox need, then start with mailboxes and confirm every delegate and send permission. Send a controlled message only where appropriate to prove display identity and reply handling. Stop closure if a legal hold, application, regulated record, customer-facing address, or continuity process has no approved disposition; resolve ownership before changing delivery.

## Official references

- Microsoft, [About shared mailboxes in Microsoft 365](https://learn.microsoft.com/en-us/microsoft-365/admin/email/about-shared-mailboxes?view=o365-worldwide).

- Microsoft, [Manage permissions for recipients in Exchange Online](https://learn.microsoft.com/en-us/exchange/recipients-in-exchange-online/manage-permissions-for-recipients).

## Primary reference

- Name: Microsoft Learn: About shared mailboxes in Microsoft 365
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/microsoft-365/admin/email/about-shared-mailboxes?view=o365-worldwide
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Give every shared mailbox an owner, sign-in boundary, and review cadence,” DSE Security, https://update.dsesecurity.com/updates/give-every-shared-mailbox-owner-signin-boundary-review-cadence/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
