How to Manage Microsoft Office 365 Shared Mailboxes

Shared mailboxes in Microsoft 365 enable teams to collaborate and share email responsibilities. Here, we’ll help you learn how to create, configure and use Microsoft 365 shared mailboxes.

What is a shared mailbox in Microsoft 365?

A shared mailbox allows multiple users with the appropriate permissions to access the same email account, whether to send emails, access shared folders, or use the same calendar and contacts list. Shared mailboxes can store up to 50GB of data without requiring a license.

Common examples of scenarios where businesses need a shared mailbox include:

  • Using a consistent alias for customer support or reception
  • Providing everyone in a department with access to the same inbox
  • Having contractors or vendors send invoices to one consistent place
  • Transitioning between former and new employees

If your organization has a hybrid Exchange environment, Microsoft suggests using the Exchange admin center (EAC) to manage your shared mailboxes.

What are the limitations of a shared mailbox?

Although convenient, shared mailboxes have some limitations:

  • Shared mailboxes have storage limits.
  • It’s not possible to encrypt emails that are sent from a shared mailbox.
  • A shared mailbox can be less secure because each user accesses it using their own credentials, and any of those credentials could be compromised.

How to Create a Microsoft 365 Shared Mailbox and Add Members

The process of creating a Microsoft 365 shared mailbox and adding new users is simple:

  1. Log in as an administrator, using either a global account or an Exchange account.
  2. Click Groups > Shared mailboxes.
  3. To create a new shared mailbox, click + Add a mailbox.
  4. Specify a name for the mailbox, which will appear in the “From” line in emails. You’ll automatically be assigned an email address, which you can edit. Click Add.
  5. To add members, select Add members to this mailbox under “Next steps.”
  6. Click +Add members and select the active users you want to have access to the new shared mailbox.
  7. Click Save and then Close.

Enabling Members to See and Use the Shared Mailbox

Exchange includes a feature called automapping, which automatically maps the shared mailboxes a user has permissions to, to their mailbox in Outlook. If automapping is enabled (it is on by default), new shared mailboxes will show up in each user’s Outlook application automatically after they close and restart Outlook. However, automapping is set on each user’s mailbox, not on the shared mailbox. Therefore, if you want to use automapping, you have to manage access to the shared mailbox by assigning permissions to each user explicitly, rather than by using a security group.

How to Configure a Shared Mailbox to Save Sent Emails

By default, when a person sends mail using a shared mailbox, the sent message is stored in that person’s Sent Items folder. To set up a shared mailbox so that replies and other sent emails are saved in the Sent folder of the shared mailbox as well, take these steps:

  1. Log in to the Microsoft 365 admin center using a global admin or an Exchange admin account.
  2. Go to Groups > Shared mailboxes.
  3. Click on your shared mailbox.
  4. Navigate to Properties.
  5. Click Edit next to Sent Items.
  6. Select On next to both Copy items sent as this mailbox and Copy items sent on behalf of this mailbox.
  7. Click Save.

How to Convert a User’s Mailbox to a Shared Mailbox

The user whose mailbox you want to convert to a shared mailbox must have a license assigned. If you deleted the license assigned to the user’s mailbox or account, you’ll have to restore it before you can convert the mailbox to shared mailbox.

To convert a user’s mailbox to a shared mailbox, take these steps:

  1. In the Exchange admin center, choose Recipients > Mailboxes.
  2. Select the user’s mailbox.
  3. Click Convert under Convert to Shared Mailbox.

How to Block Sign-in for an Account

Users usually access shared mailboxes using their own accounts. However, this means a hacker who compromises a user’s account could gain access to the shared mailbox. If this happens, you can block sign-ins from the compromised account by taking these steps:

  1. In the Exchange admin center, navigate to the Active users page under Users.
  2. Find the shared mailbox account and select the user.
  3. Select Block this user.
  4. Click Block the user from signing in.
  5. Click Save changes.

Teaching Users how to Open and Use a Shared Mailbox in Outlook and on the Web

As an admin of a shared mailbox, it’s your responsibility to help new users learn how to use shared mailboxes in Outlook. Some common questions from users include:

How do I add a shared mailbox to my Outlook?

This should happen automatically once you close and restart Outlook. You can also manually add the account from your account settings, under the “Email” tab.

How do I access the shared account from a mobile device?

You can access the web version of Outlook using a browser on your mobile device.

Staying on Top of Permissions to Shared Mailboxes

To prevent misuse of shared mailboxes and avoid security incidents, you should regularly:

  • Check which users have permissions to shared mailboxes
  • Monitor who reads what in those mailboxes.

These tasks are necessary to protect sensitive business information, detect potentially malicious users, and monitor for emails that are erroneously deleted or sent.

The Exchange Online Management Console helps you monitor who has access to what within the shared mailbox. However, native auditing has several drawbacks, including a short retention period and limited filtering and alerting options.

Having a third-party solution that supports monitoring of all systems will eliminate the inconvenience and human error inherent in juggling multiple solutions and consoles, as well as give you better visibility into permissions and user activity. In particular, Netwrix Auditor for Exchange provides easy-to-read reports for Exchange Online and Exchange Server that include crucial details, such as:

  • Non-owner mailbox access events
  • Which users have non-owner rights to which mailboxes
  • Changes to mailbox permissions and delegation

It also provides all the information you need to keep an eye on access events and changes to user permissions. Built-in filters make it easy to zero in on exactly the information you want. As a result, you can enjoy the convenience of shared mailboxes while minimizing security risks.

Product Evangelist at Netwrix Corporation, writer, and presenter. Ryan specializes in evangelizing cybersecurity and promoting the importance of visibility into IT changes and data access. As an author, Ryan focuses on IT security trends, surveys, and industry insights.