Skip to content
Exchange & EmailTroubleshooting

Shared Mailbox Permissions Not Working in Microsoft 365: Full Fix

Full Access granted but the mailbox won't show up, Send As fails, or sent items land in the wrong place. The permission types, how to check them, and every common fix.

Shared mailbox problems almost always come down to three things: the wrong permission type, a caching delay, or a client that behaves differently from the others. Here's how to tell which one you're dealing with.

The three permission types

PermissionWhat it allowsGranted with
Full AccessOpen the mailbox and read, delete, and organize its contentsAdd-MailboxPermission
Send AsSend mail that appears to come from the shared mailboxAdd-RecipientPermission
Send on BehalfSend mail that shows "User on behalf of Shared Mailbox"Set-Mailbox -GrantSendOnBehalfTo

Full Access doesn't include Send As. That single fact explains about half of all shared mailbox tickets.

Check what's actually granted

powershell
Connect-ExchangeOnline

# Full Access
Get-MailboxPermission -Identity "sales@yourcompany.com" |
  Where-Object { $_.User -notlike "NT AUTHORITY*" } |
  Format-Table User, AccessRights, IsInherited

# Send As
Get-RecipientPermission -Identity "sales@yourcompany.com" |
  Where-Object { $_.Trustee -notlike "NT AUTHORITY*" } |
  Format-Table Trustee, AccessRights

# Send on Behalf
Get-Mailbox "sales@yourcompany.com" | Select-Object -ExpandProperty GrantSendOnBehalfTo

Problem: the mailbox doesn't appear in Outlook

Cause 1: automapping hasn't kicked in yet. When Full Access is granted with automapping (the default), Outlook desktop adds the mailbox automatically, but it can take up to an hour and needs an Outlook restart.

Cause 2: permission was granted through a group. Automapping only works when the user is granted access directly. If access came through a security group, the user has to add the mailbox by hand.

Cause 3: automapping was turned off. If someone granted access with -AutoMapping $false, the mailbox won't appear on its own. To switch it on, remove and re-add the permission:

powershell
Remove-MailboxPermission -Identity "sales@yourcompany.com" -User "alex@yourcompany.com" -AccessRights FullAccess -Confirm:$false
Add-MailboxPermission -Identity "sales@yourcompany.com" -User "alex@yourcompany.com" -AccessRights FullAccess -AutoMapping $true

Problem: "You don't have permission to send as this sender"

  1. Confirm Send As is granted, not just Full Access (see the commands above).
  2. If it was granted in the last hour, wait. Send As permissions take time to apply.
  3. Make sure the user is choosing the shared address in the From field, not typing it in a way Outlook caches incorrectly. Clear the autocomplete entry for the address and pick it again from the address book.
  4. If the user has both Send As and Send on Behalf, Send As wins. Remove the one you don't want.
powershell
Add-RecipientPermission -Identity "sales@yourcompany.com" -Trustee "alex@yourcompany.com" -AccessRights SendAs -Confirm:$false

Problem: sent items land in the user's own mailbox

By default, mail sent from a shared mailbox is saved in the sender's Sent Items. To keep a copy in the shared mailbox:

powershell
Set-Mailbox "sales@yourcompany.com" -MessageCopyForSentAsEnabled $true -MessageCopyForSendOnBehalfEnabled $true

Problem: it works in Outlook on the web but not desktop

That points at the Outlook profile, not permissions:

  • Turn off Download shared folders in Cached Exchange Mode settings if the mailbox is very large and Outlook is struggling.
  • Create a new Outlook profile as a test. If the mailbox works there, the old profile is the problem.
  • In hybrid environments, check whether the user and the shared mailbox are on the same side (both on-prem or both in the cloud). Permissions across the two are limited.

Hygiene worth doing while you're here

  • Shared mailboxes don't need a license under 50 GB, unless they need an archive or litigation hold.
  • Block sign-in for the shared mailbox's own account. Nobody should sign in as the shared mailbox.
  • Use groups for permissions when many people need access, and accept that they'll add the mailbox by hand.
// Newsletter

New runbooks, straight to your inbox.

One email when something worth reading ships. No spam, unsubscribe anytime.