Give every shared mailbox an owner, sign-in boundary, and review cadence

Shared mailboxes outlive projects and teams unless someone owns membership, direct sign-in, forwarding, retention, licensing, automation, and closure. Govern each mailbox as a business service, not a permanent bucket of delegated access.

Governed cloud identity system with connected service and lifecycle nodes.
DSE visual intelligenceIdentity & cloudChecklist · 3 min read
Executive summary

What you need to know

Shared mailboxes outlive projects and teams unless someone owns membership, direct sign-in, forwarding, retention, licensing, automation, and closure. Govern each mailbox as a business service, not a permanent bucket of delegated access.

Potentially affected

Exchange Online shared mailboxes and associated user objects, Full Access, Send As and Send on Behalf permissions, automapping, forwarding and inbox rules, mobile access, applications, retention and holds, licenses, inactive owners, external mail, and continuity procedures.

DSE recommendation

Assign business and technical owners, block direct sign-in, document purpose and data handling, grant delegates through their own licensed identities with least privilege, review membership and configuration, monitor risky changes, and use a controlled closure or transfer process.

Source facts: a shared mailbox is accessed through delegated user identities

Microsoft’s shared-mailbox overview describes shared mailboxes for addresses used by multiple people, such as support or reception. It says delegates should access through their own licensed Exchange Online mailboxes and that the associated shared-mailbox account is not intended for direct sign-in. Microsoft instructs administrators to block that sign-in and keep it blocked.

Microsoft’s recipient-permissions documentation distinguishes Full Access, Send As, and Send on Behalf. These permissions produce different capabilities: opening mailbox contents is not the same as sending with the mailbox identity. Microsoft also documents licensing and feature conditions that can apply based on mailbox size, archive, hold, Defender, Purview, and other use.

Licensing and service limits change, so the current Microsoft service description and tenant entitlements must be checked. Retention, litigation hold, privacy, records, labor, and industry obligations require qualified governance or legal input. Blocking direct sign-in does not remove delegated access, application access, forwarding, rules, or content already copied elsewhere.

DSE recommendation: manage the mailbox from request through retirement

Create a register for every shared mailbox: SMTP addresses, purpose, business owner, technical owner, delegates by permission, approved send behavior, applications, forwarding, data classification, retention or hold, license, expected volume, continuity use, review date, and closure trigger. A mailbox without an accountable business owner should be escalated, not automatically preserved forever.

  1. Establish the sign-in boundary. Verify the associated user object is blocked from direct sign-in and has no known human password in use. Remove unnecessary authentication methods under the supported process. Do not distribute a shared password as a substitute for delegation.
  2. Grant the minimum permission. Decide separately who must read and manage content, who may send as the mailbox, and who may send on behalf. Use named governed identities or approved groups as supported, avoid nested ambiguity, and require stronger review for mailboxes that authorize transactions or reset accounts.
  3. Inspect hidden movement. Review mailbox and inbox rules, forwarding, delegates, mobile and application access, connectors, aliases, automatic replies, and approved automation. Confirm external forwarding and OAuth applications comply with policy. Preserve authorized business workflows while removing unexplained paths.
  4. Design continuity. Define who monitors the mailbox, expected response time, out-of-hours handling, alternate owner, queue or ticket integration, and what happens during owner absence. A mailbox is not a service desk merely because several people can open it.
  5. Review content governance. Match retention and deletion to approved records requirements, holds, privacy, and business need. Confirm license requirements for the selected features. Limit local exports and personal-folder copies that defeat central governance.
  6. Retire deliberately. At project or function end, stop new use, communicate replacement addresses, preserve required records, remove delegates and applications, handle aliases and forwarding for a bounded period, and document final disposition. Verify the old identity cannot still receive privileged workflows.

Review high-impact mailboxes more frequently and after owner, team, vendor, application, or business-process change. Monitor permission changes, sign-in enablement, forwarding, unusual sending, rule creation, and administrative modifications through the tenant’s available audit and alerting capabilities. Investigate a mailbox account that authenticates directly.

The review record should distinguish business approval from technical verification. An owner approves who needs what; administrators prove the resulting permissions, sign-in state, rules, licensing, and controls. That separation turns a shared mailbox from an inherited convenience into an accountable communications service.

For the review sample, use both directions: start with delegates and confirm their authorized mailbox need, then start with mailboxes and confirm every delegate and send permission. Send a controlled message only where appropriate to prove display identity and reply handling. Stop closure if a legal hold, application, regulated record, customer-facing address, or continuity process has no approved disposition; resolve ownership before changing delivery.

Official references

Primary reference

Review the official source

Microsoft Learn: About shared mailboxes in Microsoft 365 · Verified August 17, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE