How to set up and manage shared mailboxes in Microsoft 365
A shared mailbox in Microsoft 365 lets multiple people send and receive email from a single address without any of them needing to log in separately or manage it as a personal inbox. When set up correctly, it’s an effective tool for managing shared communication. When set up incorrectly, however, it creates confusion, security exposure, and storage headaches. Here’s what administrators and IT managers need to know.
What is a shared mailbox?
A shared mailbox is a mailbox that multiple users can access and send email from, typically associated with a role address rather than an individual. Common use cases include general company contact inboxes (info@), customer support or help desk addresses (support@), and reception or front desk mailboxes.
Users with the appropriate permissions can send email as the shared mailbox address itself or send on behalf of it. This distinction affects how the sender appears to recipients. When they send as the shared mailbox, recipients see the shared address as the sender; when they send on behalf of it, the message identifies both the user and the shared mailbox.
Shared mailboxes are designed for users within your organization. External contacts can send messages to the shared address, but they cannot be added as members with the same access as internal users. If collaboration with people outside your organization is required, a Microsoft 365 Group may be more suitable, depending on what they need to access and do.
Licensing and storage: What’s free and what isn’t
A shared mailbox in Microsoft 365 doesn’t require its own license as long as it stays under 50 GB of storage. Each user who accesses it does need a licensed Exchange Online mailbox of their own, but the shared mailbox account itself is license-free up to that threshold. Your organization also needs a Microsoft 365 plan that includes Exchange Online to create a shared mailbox. Microsoft 365 Apps for Business does not include Exchange Online, while Microsoft 365 Business Standard does.
Beyond 50 GB, additional licensing is required. Expanding storage to 100 GB requires an Exchange Online Plan 2 license assigned to the shared mailbox. You also need appropriate licensing to enable in-place archiving, preserve mailbox content under a litigation hold, or use advanced compliance features such as Microsoft Purview eDiscovery and retention policies. Administrators should plan for these thresholds before they become a problem, particularly for mailboxes that accumulate high volumes of email over time.
Access, permissions, and the sign-in question
Permissions to a shared mailbox are granted through the Microsoft 365 admin center by assigning users as members. This provides a secure and manageable way to provision access without sharing login credentials. Every shared mailbox has an associated system-generated account, but that account is not intended for direct sign-in, and Microsoft’s guidance is explicit: block sign-in for the shared mailbox account and keep it blocked. Users should always access the shared mailbox through their own accounts.
Shared mailboxes support a maximum of 25 concurrent users, or users actively connected to the mailbox at the same time. If more than 25 users need to access the mailbox simultaneously, connection failures or other issues may occur. Organizations that regularly need broader concurrent access should consider a Microsoft 365 Group instead, which uses a different architectural model and is better suited to larger user populations.
Mobile access and client behavior
Shared mailboxes are accessible through Microsoft Outlook on the web, Outlook on desktop, and the Outlook mobile apps for iOS and Android. In Outlook for desktop and the web, the shared mailbox typically appears as an additional folder alongside the user’s primary inbox once permissions are granted. On mobile, it may need to be added manually, but the process is straightforward through the app settings.
One notable limitation affects organizations with strict email security requirements: email sent from a shared mailbox cannot be encrypted using standard per-user encryption keys. Because the mailbox doesn’t have its own security context, it can’t be assigned an encryption key in the conventional sense. Messages encrypted by individual members using their own keys may not be readable by other members of the shared mailbox.
A few things that catch administrators off guard
Two common setup issues are worth flagging. First, if you try to create a shared mailbox using an address that’s already in use by another mailbox or alias in the tenant, you’ll get a proxy address conflict error. The solution is either to use Exchange Online PowerShell to create mailboxes with the same alias across different domains or to create the mailbox with a temporary name and rename it afterward in the admin center.
Second, new shared mailboxes sometimes throw a permissions error when a user first tries to send from them, even when permissions have been correctly assigned. This is a replication latency issue on Microsoft’s end, as the mailbox information is still propagating across data centers. Waiting approximately an hour before retrying typically resolves it without any further intervention.
Need help setting up shared mailboxes, configuring permissions, or managing your Microsoft 365 environment more efficiently? Our team handles Microsoft 365 administration for businesses of all sizes. Get in touch to see how we can help.
If your organization uses a team inbox for customer inquiries, billing questions, or general contact, a shared mailbox in Microsoft 365 is likely your most practical solution. It doesn’t require users to share login credentials, doesn’t consume an additional license for the mailbox itself, and integrates naturally into Microsoft Outlook. However, there are several important technical considerations that should inform how you configure and manage it.
Support desks, front desk teams, and department-wide inboxes all have something in common: email that belongs to a role or function rather than a person. Microsoft 365’s shared mailbox feature is built for exactly this scenario, allowing a team to send and receive from a shared address while each member accesses it through their own licensed account. Understanding the setup, the limits, and the common mistakes makes the difference between a smooth deployment and an ongoing headache.
Staying competitive as a small or mid-size business increasingly means getting technology decisions right, not just at the point of purchase, but on an ongoing basis as tools evolve, business needs shift, and the threat landscape changes. A regular technology business review is the mechanism that keeps those decisions grounded in current reality rather than outdated assumptions.
Most small and mid-size businesses invest in technology as needs arise rather than as part of a long-term plan. That reactive approach tends to produce an IT environment that works on a day-to-day basis but gradually accumulates inefficiencies, security gaps, and missed opportunities. A technology business review replaces guesswork with a clear picture of where your technology stands and what it should be doing next.
Technology changes faster than most business strategies do. What was a sensible IT investment two years ago may now be redundant, undersized, or quietly creating security exposure. A technology business review — a structured, periodic assessment of how your IT environment is performing and where it needs to go — is how small and mid-size businesses close that gap before it becomes expensive.
Mobile data limits have a way of making themselves known at exactly the wrong moment, like when you’re away from Wi-Fi or trying to load something important. Fortunately, Android gives you more control over your data consumption than most people realize. These seven habits and settings adjustments can meaningfully extend how far your plan goes without requiring you to upgrade to a more expensive tier.
Between background app refreshes, auto-playing videos, and automatic updates downloading over cellular, Android phones can burn through data in ways that are easy to miss. A few targeted settings changes can make a significant difference without changing how you actually use your phone day to day. Here’s how to get started.
Constantly hitting your mobile data limit before the month ends? The problem probably isn’t your plan — it’s your apps. Some apps quietly consume far more data than you’d expect, but Android’s built-in tools make it easy to see exactly where your data is going. A few simple adjustments in your settings and usage habits can go a long way. Here’s what to do.
As Apple devices have become fixtures in business environments, managing them at scale has grown more complex. Apple provides tools for device deployment, account management, security, and authentication, including Apple Business Manager (ABM), managed Apple Accounts, mobile device management integration, and Platform SSO. Understanding how these tools work together — and where additional configuration may be required — is important for IT teams managing mixed-device or primarily Apple environments.