Does a shared mailbox need a license? The limits that decide it
Shared mailboxes are the standard answer for info@, billing@, and the mailbox of someone who left. They're also a common source of quiet licensing gaps: one is over its size limit, another is on a hold with no license, and a third still has an enabled account with a password somebody knows.
This post covers the conditions that usually require a license, a read-only audit you can run monthly, and a safe order for converting a leaver's mailbox. Microsoft has changed shared mailbox rules and enforcement more than once, so treat this as a checklist to verify against the current "About shared mailboxes" documentation, not as licensing advice.
1. When a shared mailbox usually needs a license
A shared mailbox without a license works for normal shared use. Microsoft's documentation lists situations where it does need a license. At the time of writing, the main ones are:
| Situation | Why it matters |
|---|---|
| Mailbox is over the unlicensed size limit (50 GB at the time of writing) | Unlicensed shared mailboxes have a fixed storage limit |
| You want an online archive on it | Archiving needs a license that includes it |
| You want auto-expanding archiving | Needs a plan that supports it |
| The mailbox is under Litigation Hold (and some other hold types) | Holds generally need a licensed mailbox |
| Someone signs in to it directly as a user | That's using it as a user mailbox, which needs a user license |
Two related points people miss:
- People who open the shared mailbox need their own license. A user without an Exchange Online license can't access a shared mailbox just because they have Full Access on it.
- Some security and compliance features may have their own licensing requirements for shared mailboxes. Check the docs for each feature you rely on.
2. Read-only audit: size, archive, holds
Connect with a read-only role (View-Only Organization Management or Global Reader is enough):
Connect-ExchangeOnline -UserPrincipalName auditor@contoso.com -ShowBanner:$false
$shared = Get-EXOMailbox -RecipientTypeDetails SharedMailbox -ResultSize Unlimited `
-Properties ArchiveGuid, ArchiveName, LitigationHoldEnabled, InPlaceHolds, ProhibitSendReceiveQuota, ExternalDirectoryObjectId
$report = foreach ($m in $shared) {
$stats = Get-EXOMailboxStatistics -Identity $m.PrimarySmtpAddress
[pscustomobject]@{
Mailbox = $m.PrimarySmtpAddress
EntraObjectId = $m.ExternalDirectoryObjectId
SizeGB = [math]::Round(($stats.TotalItemSize.Value.ToBytes() / 1GB), 2)
DeletedGB = [math]::Round(($stats.TotalDeletedItemSize.Value.ToBytes() / 1GB), 2)
HasArchive = ($m.ArchiveGuid -ne [guid]::Empty)
LitigationHold = $m.LitigationHoldEnabled
OtherHolds = ($m.InPlaceHolds -join ';')
SendReceiveQuota = $m.ProhibitSendReceiveQuota
}
}
$report | Sort-Object SizeGB -Descending | Format-Table -AutoSize
Notes:
-
TotalItemSize.Value.ToBytes()works in a normal Exchange Online PowerShell session. If the value comes back as a plain string in your environment, parse the number in brackets instead. -
InPlaceHoldscan list Purview retention policy IDs as well as older hold types. A non-empty value means "find out what this is", not automatically "needs a license". - Sort by size and look at anything near the unlicensed limit. Those are next month's tickets.
3. Read-only audit: licenses and sign-in state
Every shared mailbox has a user object in Microsoft Entra ID. That object has a password and can be enabled or disabled. Use Microsoft Graph PowerShell (read scopes only) to check licenses and sign-in state for the IDs collected above:
Connect-MgGraph -Scopes 'User.Read.All' -NoWelcome
$licenseReport = foreach ($r in $report) {
$u = Get-MgUser -UserId $r.EntraObjectId -Property Id, UserPrincipalName, AccountEnabled, AssignedLicenses
[pscustomobject]@{
Mailbox = $r.Mailbox
AccountEnabled = $u.AccountEnabled
LicenseCount = @($u.AssignedLicenses).Count
SizeGB = $r.SizeGB
HasArchive = $r.HasArchive
LitigationHold = $r.LitigationHold
}
}
# Likely gaps: big, archived, or on hold, with no license
$licenseReport | Where-Object { $_.LicenseCount -eq 0 -and ($_.SizeGB -ge 45 -or $_.HasArchive -or $_.LitigationHold) }
# Sign-in still enabled on a shared mailbox account
$licenseReport | Where-Object { $_.AccountEnabled }
The 45 GB threshold is just an early-warning number. Pick your own. Also export both reports to a dated, access-controlled folder. They contain mailbox addresses and hold information.
On AccountEnabled: Microsoft's guidance is to block sign-in for shared mailbox accounts. Nobody should be signing in to billing@ with a password. An enabled shared mailbox account is a password-spray target that usually has no MFA registered. Blocking sign-in doesn't stop delegated users from opening the mailbox in Outlook.
4. Converting a leaver's mailbox: the safe order
Converting a departed user's mailbox to shared is a common way to keep their mail without paying for a seat. The order matters, because removing a license from a user mailbox starts a countdown to deletion.
1. Disable sign-in and revoke sessions (your offboarding process).
2. Check size and holds (section 2). Over the limit or on hold = keep a license.
3. Convert the mailbox to shared.
4. Confirm the conversion: RecipientTypeDetails = SharedMailbox.
5. Grant Full Access / Send As to the right people (with a ticket and an end date).
6. Only then remove the license, if none of the conditions in section 1 apply.
7. Record the decision and the review date.
Steps 3, 5, and 6 are changes. Step 3 is usually done in the Exchange admin center or with:
Set-Mailbox -Identity leaver@contoso.com -Type Shared
Then confirm with a read:
Get-EXOMailbox -Identity leaver@contoso.com | Select-Object PrimarySmtpAddress, RecipientTypeDetails
Don't remove the license before step 4 shows SharedMailbox. If you do it the other way round, the user mailbox enters its grace period, and you're racing a deletion window to fix it.
5. Keep the list small
Shared mailboxes created for leavers tend to live forever. Add a review date when you create one. At the review, decide whether the mail is still needed, whether a retention policy covers it, or whether it can be exported per your records policy and removed. Fewer shared mailboxes means fewer permission reviews and fewer licensing surprises.
6. Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
| Removing the license before converting | Mailbox heads toward deletion | Convert, confirm, then unlicense |
| Unlicensed shared mailbox growing past the limit | Mail stops arriving | Monthly size report; act before the limit |
| Leaving sign-in enabled | Password-guessing target | Block sign-in on shared mailbox accounts |
| Litigation Hold on an unlicensed shared mailbox | Licensing gap, compliance risk | Keep a license on held mailboxes |
| Giving access to unlicensed users | "Can't open the mailbox" tickets | Delegates need their own license |
| No review date | Leaver mailboxes pile up | Add an owner and a review date at creation |
Want the shared mailbox checklist?
The Exchange Online Admin Hygiene Pack ($29) from Admin Pack Studio includes shared vs user vs group mailbox guidance with a shared mailbox checklist, a permissions and external-forward audit with a findings worksheet, mail-flow triage cards, and a monthly hygiene checklist. It's docs only, with no scripts and nothing that changes your tenant.
Want the license side as a repeatable export? The Microsoft Graph Read-Only Inventory Toolkit ($24) includes a read-only user and assigned-license inventory script: https://cashflow4375.gumroad.com/l/microsoft-graph-read-only-inventory-toolkit
Admin Pack Studio. Not affiliated with Microsoft. Exchange Online, Microsoft 365, Microsoft Entra ID, Microsoft Graph, and Microsoft Purview are Microsoft products. Operational guidance for admins authorized to manage their tenant. Not licensing or legal advice. Limits, licensing rules, and enforcement change, so check current Microsoft documentation. Examples use placeholder names.
Top comments (0)