
Shared Mailbox: The Address That Does Not Leave When the Person Does
TL;DR:
A shared mailbox is an email address that belongs to a job rather than a person. Several people open it using their own sign-ins, and nobody logs in as the mailbox itself.
Think of it like the mail slot at the front desk versus a pigeonhole with somebody's name on it. Anyone working the desk can reach what arrives there, and when that person moves on the slot is still the slot.
On a good day nobody thinks about it. On a bad day it is the reason your vendor renewal notice, your bank verification code, and your domain expiry warning did not all follow one departed employee out the door.
Beyond the Basics:
Here's the shift: mail that matters to the business kept getting addressed to whoever happened to set the account up, and then that person left.
The pattern is easy to spot once you look for it. A social account registered to a manager's work address. A vendor portal whose password reset goes to someone who resigned in March. Verification codes arriving in a mailbox nobody can open. None of that is an email problem, it is an ownership problem, and a shared mailbox is the standard structural fix.
- It has an address but no sign-in. The account behind it stays disabled. Nobody has its password, because there is nothing to log in to, which is precisely why it is safe to give several people access.
- Access is granted per person. Full Access lets someone read it, Send As makes their reply come from the shared address, and Send on Behalf shows both names. These are separate permissions and are usually assigned together by mistake.
- It appears automatically in Outlook. Granting Full Access auto-maps the mailbox into the recipient's client, so there is nothing for them to configure.
- It costs nothing under 50GB. No license is required at that size. Cross the limit, or add an archive or a legal hold, and it needs one.
The offboarding move worth knowing: when someone leaves, their user mailbox can be converted to a shared mailbox. The mail stays reachable by the team, and the license comes back for reuse instead of being paid indefinitely to keep an inbox alive.
Here's the catch, and it has bitten people badly. A shared mailbox cannot be protected by MFA, because it is never signed into. That is fine while the account stays disabled, but re-enable sign-in for convenience and you have created a shared password with no second factor, which is exactly the account an attacker wants. Leave sign-in off. And a shared mailbox solves where the mail lands, not who holds the credentials, so pair it with a password manager rather than treating it as the whole answer.