DEV Community

AdminPackStudio
AdminPackStudio

Posted on

Does a shared mailbox need a license? The Exchange Online limits that decide it, plus a read-only audit

Does a shared mailbox need a license? The limits that decide it

Shared mailboxes are the standard answer for info@, billing@, and the mailbox of someone who left. They're also a common source of quiet licensing gaps: one is over its size limit, another is on a hold with no license, and a third still has an enabled account with a password somebody knows.

This post covers the conditions that usually require a license, a read-only audit you can run monthly, and a safe order for converting a leaver's mailbox. Microsoft has changed shared mailbox rules and enforcement more than once, so treat this as a checklist to verify against the current "About shared mailboxes" documentation, not as licensing advice.


1. When a shared mailbox usually needs a license

A shared mailbox without a license works for normal shared use. Microsoft's documentation lists situations where it does need a license. At the time of writing, the main ones are:

Situation Why it matters
Mailbox is over the unlicensed size limit (50 GB at the time of writing) Unlicensed shared mailboxes have a fixed storage limit
You want an online archive on it Archiving needs a license that includes it
You want auto-expanding archiving Needs a plan that supports it
The mailbox is under Litigation Hold (and some other hold types) Holds generally need a licensed mailbox
Someone signs in to it directly as a user That's using it as a user mailbox, which needs a user license

Two related points people miss:

  • People who open the shared mailbox need their own license. A user without an Exchange Online license can't access a shared mailbox just because they have Full Access on it.
  • Some security and compliance features may have their own licensing requirements for shared mailboxes. Check the docs for each feature you rely on.

2. Read-only audit: size, archive, holds

Connect with a read-only role (View-Only Organization Management or Global Reader is enough):

Connect-ExchangeOnline -UserPrincipalName auditor@contoso.com -ShowBanner:$false

$shared = Get-EXOMailbox -RecipientTypeDetails SharedMailbox -ResultSize Unlimited `
  -Properties ArchiveGuid, ArchiveName, LitigationHoldEnabled, InPlaceHolds, ProhibitSendReceiveQuota, ExternalDirectoryObjectId

$report = foreach ($m in $shared) {
  $stats = Get-EXOMailboxStatistics -Identity $m.PrimarySmtpAddress
  [pscustomobject]@{
    Mailbox          = $m.PrimarySmtpAddress
    EntraObjectId    = $m.ExternalDirectoryObjectId
    SizeGB           = [math]::Round(($stats.TotalItemSize.Value.ToBytes() / 1GB), 2)
    DeletedGB        = [math]::Round(($stats.TotalDeletedItemSize.Value.ToBytes() / 1GB), 2)
    HasArchive       = ($m.ArchiveGuid -ne [guid]::Empty)
    LitigationHold   = $m.LitigationHoldEnabled
    OtherHolds       = ($m.InPlaceHolds -join ';')
    SendReceiveQuota = $m.ProhibitSendReceiveQuota
  }
}
$report | Sort-Object SizeGB -Descending | Format-Table -AutoSize
Enter fullscreen mode Exit fullscreen mode

Notes:

  • TotalItemSize.Value.ToBytes() works in a normal Exchange Online PowerShell session. If the value comes back as a plain string in your environment, parse the number in brackets instead.
  • InPlaceHolds can list Purview retention policy IDs as well as older hold types. A non-empty value means "find out what this is", not automatically "needs a license".
  • Sort by size and look at anything near the unlicensed limit. Those are next month's tickets.

3. Read-only audit: licenses and sign-in state

Every shared mailbox has a user object in Microsoft Entra ID. That object has a password and can be enabled or disabled. Use Microsoft Graph PowerShell (read scopes only) to check licenses and sign-in state for the IDs collected above:

Connect-MgGraph -Scopes 'User.Read.All' -NoWelcome

$licenseReport = foreach ($r in $report) {
  $u = Get-MgUser -UserId $r.EntraObjectId -Property Id, UserPrincipalName, AccountEnabled, AssignedLicenses
  [pscustomobject]@{
    Mailbox        = $r.Mailbox
    AccountEnabled = $u.AccountEnabled
    LicenseCount   = @($u.AssignedLicenses).Count
    SizeGB         = $r.SizeGB
    HasArchive     = $r.HasArchive
    LitigationHold = $r.LitigationHold
  }
}

# Likely gaps: big, archived, or on hold, with no license
$licenseReport | Where-Object { $_.LicenseCount -eq 0 -and ($_.SizeGB -ge 45 -or $_.HasArchive -or $_.LitigationHold) }

# Sign-in still enabled on a shared mailbox account
$licenseReport | Where-Object { $_.AccountEnabled }
Enter fullscreen mode Exit fullscreen mode

The 45 GB threshold is just an early-warning number. Pick your own. Also export both reports to a dated, access-controlled folder. They contain mailbox addresses and hold information.

On AccountEnabled: Microsoft's guidance is to block sign-in for shared mailbox accounts. Nobody should be signing in to billing@ with a password. An enabled shared mailbox account is a password-spray target that usually has no MFA registered. Blocking sign-in doesn't stop delegated users from opening the mailbox in Outlook.


4. Converting a leaver's mailbox: the safe order

Converting a departed user's mailbox to shared is a common way to keep their mail without paying for a seat. The order matters, because removing a license from a user mailbox starts a countdown to deletion.

1. Disable sign-in and revoke sessions (your offboarding process).
2. Check size and holds (section 2). Over the limit or on hold = keep a license.
3. Convert the mailbox to shared.
4. Confirm the conversion: RecipientTypeDetails = SharedMailbox.
5. Grant Full Access / Send As to the right people (with a ticket and an end date).
6. Only then remove the license, if none of the conditions in section 1 apply.
7. Record the decision and the review date.
Enter fullscreen mode Exit fullscreen mode

Steps 3, 5, and 6 are changes. Step 3 is usually done in the Exchange admin center or with:

Set-Mailbox -Identity leaver@contoso.com -Type Shared
Enter fullscreen mode Exit fullscreen mode

Then confirm with a read:

Get-EXOMailbox -Identity leaver@contoso.com | Select-Object PrimarySmtpAddress, RecipientTypeDetails
Enter fullscreen mode Exit fullscreen mode

Don't remove the license before step 4 shows SharedMailbox. If you do it the other way round, the user mailbox enters its grace period, and you're racing a deletion window to fix it.


5. Keep the list small

Shared mailboxes created for leavers tend to live forever. Add a review date when you create one. At the review, decide whether the mail is still needed, whether a retention policy covers it, or whether it can be exported per your records policy and removed. Fewer shared mailboxes means fewer permission reviews and fewer licensing surprises.


6. Common mistakes

Mistake What happens Fix
Removing the license before converting Mailbox heads toward deletion Convert, confirm, then unlicense
Unlicensed shared mailbox growing past the limit Mail stops arriving Monthly size report; act before the limit
Leaving sign-in enabled Password-guessing target Block sign-in on shared mailbox accounts
Litigation Hold on an unlicensed shared mailbox Licensing gap, compliance risk Keep a license on held mailboxes
Giving access to unlicensed users "Can't open the mailbox" tickets Delegates need their own license
No review date Leaver mailboxes pile up Add an owner and a review date at creation

Want the shared mailbox checklist?

The Exchange Online Admin Hygiene Pack ($29) from Admin Pack Studio includes shared vs user vs group mailbox guidance with a shared mailbox checklist, a permissions and external-forward audit with a findings worksheet, mail-flow triage cards, and a monthly hygiene checklist. It's docs only, with no scripts and nothing that changes your tenant.

Get the pack: https://cashflow4375.gumroad.com/l/exchange-online-admin-hygiene-pack?utm_source=devto&utm_medium=article&utm_campaign=shared_mailbox_license

Want the license side as a repeatable export? The Microsoft Graph Read-Only Inventory Toolkit ($24) includes a read-only user and assigned-license inventory script: https://cashflow4375.gumroad.com/l/microsoft-graph-read-only-inventory-toolkit


Admin Pack Studio. Not affiliated with Microsoft. Exchange Online, Microsoft 365, Microsoft Entra ID, Microsoft Graph, and Microsoft Purview are Microsoft products. Operational guidance for admins authorized to manage their tenant. Not licensing or legal advice. Limits, licensing rules, and enforcement change, so check current Microsoft documentation. Examples use placeholder names.

Top comments (0)