What is a Shared Mailbox and Why Use One?
You have a central email address for your organization, like contact@ or support@, and multiple people need to monitor it. The old way was to create a regular user account and share the password among the team. In my experience, this is one of the most common security risks small organizations face.
The real issue is maintaining central communication without compromising security or creating confusion. When multiple people use the same login, you have no way to know who sent a specific email or deleted a critical message. If someone leaves the organization, you have to change the password and inform everyone else, which is inefficient and prone to error.
A shared mailbox is Microsoft’s solution to this problem. It’s a special type of mailbox that doesn’t have its own password and cannot be logged into directly. Instead, you grant access to licensed users, who can then open the shared mailbox from within their own Outlook account. This approach is more secure, provides a clear audit trail, and is free for mailboxes under 50 gigabytes (GB).
Shared Mailbox vs. Individual Mailbox: What’s the Difference?
It can be tempting to just create another licensed user for an address like accounting@, but this creates unnecessary cost and risk. Understanding the fundamental differences between a shared mailbox and a standard, individual user mailbox is key to making the right decision for your team.
The primary difference is how you access them. An individual mailbox has a username and a password; it’s designed for one person. A shared mailbox has no password; it’s designed for a team function and is only accessible by users you have explicitly granted permission to.
This structural difference leads to practical advantages. Since a shared mailbox doesn’t require a license (as long as it stays under 50GB), it saves you money. More critically, it centralizes management. You control access from one place—the Microsoft 365 admin center—instead of trying to manage a shared password written on a sticky note.
Who Can Access Our Shared Mailbox? Understanding Members.
Creating a shared mailbox is only the first step. By default, no one, not even the administrator who created it, can access it. The power of a shared mailbox comes from assigning “members” and giving them specific permissions. These permissions dictate exactly what each person can and cannot do.
Think of it like giving out keys to a building. Just because the building exists doesn’t mean anyone can get in. You have to decide who gets a key and what doors that key opens. In Microsoft 365, these “keys” are the core permissions you assign to each user for that specific shared mailbox.
The most fundamental permission is Full Access. This allows a user to open the shared mailbox in their own Outlook, view its contents, create new items (like calendar appointments), and delete messages. Without Full Access, a user cannot even see the mailbox. This is always the first permission you should grant to any team member who needs to work with the shared inbox.
“Send As” vs. “Send on Behalf”: Which Permission Do We Need?
Once a user has Full Access, they can read and manage emails. But what happens when they need to reply? This is where sending permissions come in, and you have two distinct options: “Send As” and “Send on Behalf.” The choice you make directly impacts how your recipients see your emails.
Send As permission allows a user to send an email that appears to come directly from the shared mailbox. For example, if Jane has “Send As” permission for the [email protected] mailbox, when she sends an email from it, the recipient sees the sender as “Support Team” or “[email protected].” The recipient has no idea Jane was the one who wrote it. This creates a unified, anonymous voice for a department.
Send on Behalf permission is different. It provides transparency. If Jane has “Send on Behalf” permission, when she sends an email, the recipient sees the sender as “Jane Smith on behalf of [email protected].” This makes it clear that a specific person is communicating for the group. In practice, this is less common for general-purpose mailboxes like info@ or sales@.
For most small businesses and non-profits, “Send As” is the better starting point. It presents a more polished and cohesive image to the outside world. Your customer feels like they are talking to “the company,” not just one individual.
| Concept | What It Means | Why It Matters | What To Do Next |
|---|---|---|---|
| Full Access | The user can open the shared mailbox, read, delete, and move emails, and manage the calendar. | This is the foundational permission. Without it, a user cannot see or interact with the mailbox at all. | Grant this to every team member who needs to monitor or manage the shared inbox. |
| Send As | The user can send emails that appear to come directly from the shared mailbox address (e.g., from “[email protected]”). | It presents a single, unified identity to your customers and partners. The recipient doesn’t know which individual sent the message. | Grant this along with Full Access for a seamless team experience. This is the standard for most support and info mailboxes. |
| Send on Behalf | The user can send emails that show they are sending “on behalf of” the shared mailbox (e.g., “John Doe on behalf of [email protected]”). | It provides transparency about who is sending the message, which can be useful for roles like an executive assistant managing a leader’s inbox. | Use this sparingly. Reserve it for specific situations where personal accountability or identity is required in the communication. |
Shared Mailbox vs. Delegating a Personal Mailbox
A common point of confusion is when to use a shared mailbox versus when to delegate access to a person’s individual mailbox. If your goal is for one person to cover for another during a vacation, a shared mailbox is the wrong tool for the job. That’s a classic case for delegate access.
Delegate access is a feature for individual mailboxes. It lets you, the mailbox owner, give another person (a delegate) permission to read and manage your mail and calendar. This is a one-to-one relationship, designed for specific scenarios like an assistant managing a manager’s schedule.
A shared mailbox, on the other hand, is for a team function. It doesn’t “belong” to any single person. It belongs to a role, like “Customer Service” or “Project Alpha.” Use a shared mailbox when multiple people need to collaborate on a shared stream of work over the long term. Use delegate access for short-term coverage or specific one-on-one assistance.
When a person leaves an organization, their email can be converted to a shared mailbox so anyone filling their roll will have access to all emails and ongoing conversations for continuity.
How Do I Set Up and Manage These Permissions?
Once you understand the types of permissions, assigning them is done in the Microsoft 365 admin center. You don’t need any special tools, just your administrator account.
Here are the steps to manage permissions for an existing shared mailbox:
- Sign in to the Microsoft 365 admin center (admin.microsoft.com).
- In the left-hand navigation, go to Teams & groups, then select Shared mailboxes.
- Click on the name of the shared mailbox you want to manage. A details pane will appear on the right.
- To grant access to view the mailbox, find the section labeled Members and click Edit. Add the users who need Full Access and Save.
- To grant sending permissions, find the Send as permissions or Send on behalf permissions sections. Click Edit on the one you need, add the users, and Save.
A critical point: these changes are not instant. In my experience, it can take anywhere from a few minutes to an hour for the permissions to fully propagate through Microsoft’s systems. If a user reports they still can’t access the mailbox after you’ve granted permission, tell them to wait an hour and restart Outlook before you begin troubleshooting.
Common Pitfalls: Avoiding Access Mistakes
Setting up shared mailboxes is straightforward, but a few common mistakes can cause frustration. Being aware of them ahead of time can save you a lot of trouble.
The most frequent error is granting “Send As” permission without also granting “Full Access.” A user needs Full Access to even see the mailbox in their Outlook. Without it, the “Send As” permission is useless because they have no mailbox to send from. Always grant Full Access first.
Another pitfall is over-permissioning. Not everyone on the team needs to send emails from the shared address. Apply the principle of least privilege: give people only the access they need to perform their duties. Perhaps some team members only need to read incoming mail (Full Access) while only team leads are authorized to reply (“Send As”).
Finally, avoid using a shared mailbox as a long-term data archive. While they are useful for collaboration, they are not designed to be a permanent file cabinet for years of email. For that, you should look into Microsoft 365’s formal archiving policies, which are a more structured and scalable solution for data retention.
Our Recommendation
For the vast majority of small businesses and non-profits I work with, the best practice is consistent and simple. When you create a shared mailbox for a team function like info@, sales@, or donations@, follow this two-step permission model.
First, grant Full Access to every licensed user on the team who needs to read and process the incoming emails. Second, grant Send As permission to those same users. This combination provides the most effective and professional experience. Your team can collaborate seamlessly inside one inbox, and your customers receive clear, consistent communication from a single, official company address.
Frequently Asked Questions
What is the difference between a shared mailbox and a Microsoft 365 group?
A shared mailbox is primarily for a shared email inbox and calendar. A Microsoft 365 Group is a broader collaboration tool that includes a shared inbox, but also a SharePoint site for files, a Planner for tasks, and other integrated services. Use a shared mailbox for simple email collaboration; use a Group for more complex project work.
Do shared mailboxes require a Microsoft 365 license?
The shared mailbox itself does not require a license as long as its storage is under 50 GB. However, every user who accesses the shared mailbox must have their own active Microsoft 365 license that includes Exchange Online (such as a Business Basic, Standard, or Premium license).
How do I add or remove members from a shared mailbox?
You can manage membership in the Microsoft 365 admin center. Navigate to Teams & groups > Shared mailboxes, select the mailbox, and click “Edit” next to the Members section. From there, you can add or remove users who have Full Access permission.
When should I use “Send As” versus “Send on Behalf” permissions?
Use “Send As” when you want emails to appear as if they came directly from the team or department, creating a unified voice. Use “Send on Behalf” when you need to show which specific person sent the message, which is common for assistants managing an executive’s mail.
Can a shared mailbox have its own password for direct login?
No, a shared mailbox is intentionally designed without a password and cannot be logged into directly. This is a security feature. Access is only granted through a licensed user’s account after you assign them the appropriate permissions.
Properly managing your shared mailbox permissions is a small technical step that has a big impact on your team’s efficiency and your organization’s professional image. By assigning the right access for the right job—usually a combination of Full Access and Send As—you enable secure, effective collaboration without the risks of a shared password.
