How to set up and manage shared mailboxes in Microsoft 365

Author: Tech Advisory

How to set up and manage shared mailboxes in Microsoft 365

A shared mailbox in Microsoft 365 lets multiple people send and receive email from a single address without any of them needing to log in separately or manage it as a personal inbox. When set up correctly, it’s an effective tool for managing shared communication. When set up incorrectly, however, it creates confusion, security exposure, and storage headaches. Here’s what administrators and IT managers need to know.

What is a shared mailbox?

A shared mailbox is a mailbox that multiple users can access and send email from, typically associated with a role address rather than an individual. Common use cases include general company contact inboxes (info@), customer support or help desk addresses (support@), and reception or front desk mailboxes. 

Users with the appropriate permissions can send email as the shared mailbox address itself or send on behalf of it. This distinction affects how the sender appears to recipients. When they send as the shared mailbox, recipients see the shared address as the sender; when they send on behalf of it, the message identifies both the user and the shared mailbox. 

Shared mailboxes are designed for users within your organization. External contacts can send messages to the shared address, but they cannot be added as members with the same access as internal users. If collaboration with people outside your organization is required, a Microsoft 365 Group may be more suitable, depending on what they need to access and do. 

Licensing and storage: What’s free and what isn’t

A shared mailbox in Microsoft 365 doesn’t require its own license as long as it stays under 50 GB of storage. Each user who accesses it does need a licensed Exchange Online mailbox of their own, but the shared mailbox account itself is license-free up to that threshold. Your organization also needs a Microsoft 365 plan that includes Exchange Online to create a shared mailbox. Microsoft 365 Apps for Business does not include Exchange Online, while Microsoft 365 Business Standard does. 

Beyond 50 GB, additional licensing is required. Expanding storage to 100 GB requires an Exchange Online Plan 2 license assigned to the shared mailbox. You also need appropriate licensing to enable in-place archiving, preserve mailbox content under a litigation hold, or use advanced compliance features such as Microsoft Purview eDiscovery and retention policies. Administrators should plan for these thresholds before they become a problem, particularly for mailboxes that accumulate high volumes of email over time.

Access, permissions, and the sign-in question

Permissions to a shared mailbox are granted through the Microsoft 365 admin center by assigning users as members. This provides a secure and manageable way to provision access without sharing login credentials. Every shared mailbox has an associated system-generated account, but that account is not intended for direct sign-in, and Microsoft’s guidance is explicit: block sign-in for the shared mailbox account and keep it blocked. Users should always access the shared mailbox through their own accounts.

Shared mailboxes support a maximum of 25 concurrent users, or users actively connected to the mailbox at the same time. If more than 25 users need to access the mailbox simultaneously, connection failures or other issues may occur. Organizations that regularly need broader concurrent access should consider a Microsoft 365 Group instead, which uses a different architectural model and is better suited to larger user populations.

Mobile access and client behavior

Shared mailboxes are accessible through Microsoft Outlook on the web, Outlook on desktop, and the Outlook mobile apps for iOS and Android. In Outlook for desktop and the web, the shared mailbox typically appears as an additional folder alongside the user’s primary inbox once permissions are granted. On mobile, it may need to be added manually, but the process is straightforward through the app settings.

One notable limitation affects organizations with strict email security requirements: email sent from a shared mailbox cannot be encrypted using standard per-user encryption keys. Because the mailbox doesn’t have its own security context, it can’t be assigned an encryption key in the conventional sense. Messages encrypted by individual members using their own keys may not be readable by other members of the shared mailbox.

A few things that catch administrators off guard

Two common setup issues are worth flagging. First, if you try to create a shared mailbox using an address that’s already in use by another mailbox or alias in the tenant, you’ll get a proxy address conflict error. The solution is either to use Exchange Online PowerShell to create mailboxes with the same alias across different domains or to create the mailbox with a temporary name and rename it afterward in the admin center.

Second, new shared mailboxes sometimes throw a permissions error when a user first tries to send from them, even when permissions have been correctly assigned. This is a replication latency issue on Microsoft’s end, as the mailbox information is still propagating across data centers. Waiting approximately an hour before retrying typically resolves it without any further intervention.

Need help setting up shared mailboxes, configuring permissions, or managing your Microsoft 365 environment more efficiently? Our team handles Microsoft 365 administration for businesses of all sizes. Get in touch to see how we can help.

Subscribing to our
monthly newsletter

is your gateway to staying well-informed and up-to-date on the latest developments in the world of information technology and our upcoming events.

This field is for validation purposes and should be left unchanged.