- Exchange Online
- Licensing
- Microsoft 365
Shared mailboxes in Microsoft 365: when they save you a license and when they don't
info@, sales@, support@… A shared mailbox in Exchange Online needs no license, but it has limits. When to use one, when not to, and how to convert a user mailbox.
Almost every company has addresses that belong to nobody in particular: info@, accounts@, support@. And in many tenants each one sits behind a fully licensed user that nobody uses for anything else. That's money down the drain, and one more account to protect.
What a shared mailbox is
A shared mailbox is an Exchange Online mailbox with no user attached. Nobody signs in to it: team members see it inside their own Outlook and can read and send as that address. It needs no license as long as it stays under 50 GB and doesn't use archiving or litigation hold.
When it fits
- Generic addresses handled by several people (
info@,orders@). - Mailboxes of former employees that must be kept for a while without paying a license.
- Resource calendars: rooms, vehicles, loanable equipment.
When it doesn't
- If someone needs to sign in directly to that mailbox (phone, Teams, applications).
- If it will exceed 50 GB or needs an online archive: then it must be assigned an Exchange Online Plan 2 license or similar.
- If it's used to send from a device (scanner, ERP) over authenticated SMTP: it can't authenticate because it has no password.
Converting a user mailbox into a shared one
It's a reversible change with no data loss:
- In the Exchange admin center, open the user's mailbox and choose Convert to shared mailbox.
- Wait for the conversion to finish (a few minutes).
- Grant Full Access and Send As permissions to the people who need to use it.
- Remove the license from the original user. If they have data in OneDrive, save it first: OneDrive isn't kept with the mailbox.
- Block sign-in on the account. A shared mailbox with an active password is an attack vector with no MFA.
A detail almost nobody checks
Shared mailboxes keep their account in Entra ID. If you don't block sign-in and they have no MFA, anyone who gets the password can walk in. It's one of the points we always review in a security audit.