Convert a user mailbox to a shared mailbox in Office 365 using the Microsoft 365 Admin Center, Exchange Admin Center, and Exchange Online PowerShell.
Converting a user mailbox to a shared mailbox in Office 365 is standard practice enterprise administrators use to:
- Preserve offboarded employees’ data
- Optimizing licensing costs
- Managing security vulnerabilities
Even industry data shows that 35% of M365 budgets for licenses remain completely inactive and underutilized. And over 80% of corporate data breaches happen due to weak, stolen, or compromised credentials.
So, if you are looking for a reliable and effortless way to convert an M365 mailbox to a shared mailbox, go through this straightforward guide. It will share the best 3 methods IT professionals and MSPs use for mailbox conversions.
Let’s get started and learn how to transform an Office 365 user mailbox to a shared mailbox.
Trending Right Now: 3 Best Methods to Move Email from Office 365 Group to Shared Mailbox
Pre-Conversion Checklist
Having a pre-conversion checklist ensures a smooth and error-free Office 365 user mailbox to shared mailbox conversion. It makes sure that the mailboxes being converted are ready for storage consumption and compliance holds.
Most admins skip auditing the targeted mailboxes in advance and remove the users’ Microsoft 365 license -only to find out immediate mail flow disruption or compliance violations.
So, must go through the following checklist to convert an Office 365 mailbox to a shared mailbox securely.
#1: The 50 GB Free Tier Storage Limit
You might not know, but the default free-tier quota for a shared mailbox is 50 GB. In simple terms, your shared mailbox operates free of charge only if its total storage doesn’t exceed the 50 GB storage limit.
So, what happens if the user mailbox is over 50 GB before I convert it?
- Audit the current size of the user’s mailbox before converting the regular mailbox to a shared mailbox. And if you try to convert a mailbox exceeding the default 50 GB limit and remove its license, the shared mailbox will instantly surpass the free-tier quota. The mailbox will continue to receive emails temporarily. But it will eventually reject incoming messages with a Non-Delivery Report (NDR). And, discourage users from sending outgoing mail.
- Since an unlicensed shared mailbox exceeding the 50 GB default threshold cannot be used, assigning an Exchange Online Plan 2 licence is the sole solution. Allocating this will instantly expand the shared mailbox capacity to 100 GB.
- Additionally, if mailboxes have crossed the 100 GB storage capacity, leverage auto-expanding archiving capabilities. For that, either an Exchange Online Plan 2 license or a Plan 1 license combined with the Exchange Online Archiving add-on is required.
Must Check Out: How to Increase Office 365 Mailbox Size From 50 GB to 100 GB? A Guide
#2: Litigation Hold and Compliance Dependencies
By default, an unlicensed shared mailbox is deficient in a security framework to support advanced Microsoft Purview compliance features. Hence, keep the following in mind before changing an Exchange mailbox to a shared mailbox:
- The shared mailbox must be licensed if the converting mailbox is currently under an Office 365 Litigation Hold, In-Place Hold, or Data Loss Prevention (DLP) policy.
- Also, managing a Litigation Hold requires either an active Exchange Online Plan 2 License, or an Exchange Online Plan 1 + Exchange Online Archiving add-on.
- And, if you attempt to convert a user mailbox that is under an active Litigation Hold and, curiously, remove its E3 or E5 license to save costs, the compliance hold will break. And the data becomes vulnerable to deletion by anyone with delegate access.
#3: The Entra ID “Anchor” Rule
A shared mailbox requires the original user object to anchor it to the directory. It doesn’t exist as an independent entity.
- So, make sure not to delete the user account. Because removing the user in Entra ID or the Microsoft 365 Admin Center deletes the shared mailbox completely.
- Also, the original account preserves its credentials post-conversion. So, you’re required to block direct sign-ins to the account to safeguard it against unauthorized access. Remember, all access must occur through delegation from licensed users.
#4: Run a Complete Backup
Run a complete backup of the target user before converting a regular mailbox to a shared mailbox. This mandatory step ensures complete data retention, OneDrive & Teams Protection, and compliance.
- Because removing a Microsoft 365 license after a conversion immediately revokes access to the user’s OneDrive data, SharePoint files, and Teams chat history.
- And as mentioned above, shared mailboxes without active licenses have only a 50 GB limit. And if a user mailbox is more than that, removing the license will result in data loss.
So, use the experts’ favourite, SysTools Office 365 backup tool. This promising backup software assures a handy & secure solution to back up Microsoft 365 data.
- It allows you to back up complete Office 365 data (Emails, Contacts, Calendars, and Documents) of multiple accounts. Including In-Place Archive mailboxes.
- It also provides a delta backup feature that downloads only newly arrived data in the mailbox.
- This tool also doubles down on data security through encryption during storage and transfer.
- For dedicated & precise backups, it offers a date filter.
- You can also track the backup process via the intuitive built-in centralized dashboard.
- It is compatible with Windows and Mac OS versions.
Related Read: How to Create Shared Mailbox in Office 365: 3 Ways Explained
3 Best Ways to Convert Office 365 User Mailbox to Shared Mailbox
Here are the 4 best & effective ways to convert a user mailbox to a shared mailbox. The following methods are frequently utilized by seasoned IT professionals and experts globally for mailbox conversions:
Method #1: Microsoft 365 Admin Center (The GUI Approach)
The Microsoft 365 Admin Center is the standard method to convert an M365 mailbox to a shared mailbox. IT admins use this direct route for single mailbox conversions. And those who prefer a graphical user interface over PowerShell.
To use this method, Role-Based Access Control (RBAC) is required; you must be logged in as a Global Administrator or an Exchange Administrator.
Step 1: Execute the Mailbox Conversion
- Go to the “Microsoft 365 Admin Center” >> log in with admin credentials.
- On the left navigation menu, expand “Users” >> select “Active Users”.
- Find and click on the “Display Name” (of the target user).
Note: Avoid selecting the checkbox. Click the name itself to open the properties flyout pane.
- Select the “Mail” tab (at the top of the flyout pane).
- In the More actions section, click “Convert to shared mailbox”.
- Click the “Convert” button (in the confirmation prompt).
- Wait until the green banner stating “the mailbox was successfully converted” appears. Then, close the window.
Step #2: Revoke Access (Block Sign-in)
Since a shared mailbox lacks its own dedicated independent credentials, it depends on the original user account as an Entra ID anchor. And to secure this anchor, blocking direct logins is a must. To do so, follow the steps given below:
- In the same user properties flyout pane, switch to the “Account” tab.
- Click on “Block sign-in”.
- Check the box for “Block the user from signing in” >> click “Save Changes”.
Step #3: Remove the Microsoft License (Conditional)
Once the mailbox passes the pre-conversion storage and compliance checks, users’ licences can be reclaimed. Reassign them to new employees or cancel them to reduce billing overhead. To remove the license, apply the following steps:
- Go to the “Licenses and apps” tab (in the user properties flyout pane).
- Uncheck the primary Microsoft 365 license (such as Microsoft 365 Business Standard, Office 365 E3).
- Click “Save Changes”.
Note: If the Office 365 mailbox goes past the 50 GB limit or is on Litigation Hold, leave the Exchange Online Plan 2 license intact.
Step #4: Assign Delegate Permissions
A shared mailbox can’t be viewed and used to send emails until the active users’ permissions are granted. Use the given steps to assign delegated permissions:
- In the left navigation menu, expand “Teams & groups” >> select “Shared Mailboxes”.
- Click on the newly converted shared mailbox.
- Under the Members section, click “Edit”.
- Click “Add members” >> select the target users (who need access) >> click “Save”.
Method #2: Exchange Admin Center
When it comes to precise control regarding how delegation and sending permissions should be handled, the Exchange Admin Center (EAC) is the preferred choice of IT admins.
It simply separates the mail routing and delegation configurations from the general user identity management. Office 365 Experts and MSPs use this method to get complete control over Send As vs. Send on Behalf permissions. The standard M365 Admin portal often merges them.
So, how to convert a mailbox to a shared mailbox in Exchange Admin Center?
Step #1: The Conversion Execution
Similar to the Microsoft 365 Admin Center, before attempting to change the mailbox’s license status, execute the conversion. Otherwise, removing a licence from a user mailbox immediately triggers a soft-delete process. Resulting in halting the conversion until the mailbox is restored.
- Go to the modern “Exchange Admin Center”.
- In the left-hand navigation pane, expand “Recipients” >> click “Mailboxes”.
- Use the search bar to find the target user mailbox to convert.
- To open the properties flyout pane (on the right side of the screen), click on the user’s Display Name.
- Select the “Others” tab (in the flyout pane).
- Click on “Convert to shared mailbox” (under the Mailbox actions section).
- Right-click “Confirm” (on the warning prompt). And wait till the green success confirmation appears on the screen.
Step #2: Set up Granular Delegation
The Exchange Admin Center allows users to precisely define how users should interact with the shared mailbox. This is unlike the M365 Admin Center that assigns basic “Member” access.
- Close the conversion success prompt. But stay on the user’s property flyout pane.
- Switch to the “Delegation” tab.
- Click “Edit” >> Add members.
- Assign one of the following permissions explicitly:
- Read and manage (Full Access): This permission grants users the ability to open the mailbox, read emails, and even create calendar events. Note: This doesn’t allow sending emails.
- Send as: It allows users to send an email with the shared mailbox email address. The recipient will not be able to see the actual sender’s name.
- Send on behalf: This enables users to send an email. It will highlight the identity of the recipient.
Step #3: Securing the Anchor Identity
In order to secure the account and adjust billing, moving back to the primary identity portal is required. This is because EAC maintains Exchange properties, not Entra ID identities. To secure the anchor identity:
- Open the “Microsoft 365 Admin Center” or “Entra ID Portal”.
- Find the converted user mailboxes.
- In the same user properties flyout pane, switch to the “Account” tab.
- Click on “Block sign-in”.
- Check the box for “Block the user from signing in” >> click “Save Changes”.
- Finally, go to the “Licenses and apps” tab >> remove the Microsoft 365 license. Ensure that the mailbox is under 50 GB and not under a Legal Hold.
Method #3: Exchange Online PowerShell
The Exchange Online PowerShell method is used by enterprise administrators for its speed and scriptability. It can convert hundreds of Office 365 regular mailboxes to shared mailboxes rapidly, bypassing M365 Admin Center’s caching delays. And allows immediate validation.
To use this method, the ExchangeOnlineManagement module needs to be installed. And the PowerShell requires Administrator rules to execute the scripts.
So, here’s how to bulk convert user mailboxes to shared mailboxes using PowerShell:
Step #1: Authenticate to Exchange Online
Establishing a remote session to a Microsoft 365 tenant is the first step to convert
Office 365 mailbox to a shared mailbox. This secure connection is required because modern Exchange Online modules use REST API connections. This makes the process highly reliable.
# Connect to your Exchange Online tenant
Connect-ExchangeOnline -UserPrincipalName [email protected]
Step #2: Execute the Conversion Cmdlet
The Set-Mailbox is the core of this PowerShell conversion process. Hence, defining the exact identity (UserPrincipalName) and the target mailbox type is mandatory.
# Convert the user mailbox to a shared mailbox
Set-Mailbox -Identity "[email protected]" -Type Shared
Step #3: Verify the Conversion
Experienced administrators do not assume that their conversion is successful; they validate it. But how? They query the directory immediately to confirm the RecipientTypeDetails property has successfully transitioned.
# Verify the mailbox type has changed
Get-Mailbox -Identity "[email protected]" | Select-Object Name, RecipientTypeDetails
Expected Output: The RecipientTypeDetails column should now precisely read SharedMailbox.
Step #4: Secure the Anchor Identity via Microsoft Graph
Since legacy Azure AD cmdlets are deprecated by Microsoft, using the Microsoft Graph PowerShell module has become essential to block sign-ins and remove licenses.
# Connect to Microsoft Graph with User modification scopes
Connect-MgGraph -Scopes "User.ReadWrite.All"
# Block the user from signing in (Disables the Entra ID account)
Update-MgUser -UserId "[email protected]" -AccountEnabled $false
Also Check Out: Office 365 Shared Mailbox Not Showing in Outlook? 5 Easy Fixes
Post-Conversion & Backup Checklist
Once the user mailbox to shared mailbox conversion is completed, it is critical to secure the newly created shared mailbox. And ensure its data is backed up securely. This requires specific administrative configurations.
Also, Microsoft functions on a “Shared Responsibility Model”. This clearly states that Microsoft holds accountability for the infrastructure. And the user is responsible for data retention and access control.
So, here are the technical configurations (with exact PowerShell cmdlets) that are required for a healthy post-conversion:
#1: Security And Licensing Lockdown
Killing active sessions and reclaiming their license is a common security practice enterprise administrators apply to prevent backend access to the shared mailbox.
So, do not just change the password. Remove existing OAuth tokens and completely disable the account to prevent backend access to the shared mailbox. To do so, run the given scripts in the Microsoft Graph PowerShell module:
# 1. Revoke all active sessions and refresh tokens
Revoke-MgUserSignInSession -UserId "[email protected]"
# 2. Block future sign-ins (Disables the account)
Update-MgUser -UserId "[email protected]" -AccountEnabled $false
Also, a shared mailbox doesn’t require a license until it crosses the 50 GB limit or needs a Litigation Hold. So, check the current mailbox size:
Get-MailboxStatistics -Identity “[email protected]” | Select DisplayName, TotalItemSize
- Under 50 GB: Revoke the license in the M365 Admin Center. The respective mailbox will remain active.
- Over 50 GB: Retain an Exchange Online Plan 2 license (or Plan 1+ Exchange Online Archiving). Do not remove the license if it is over 50 GB. Otherwise, the mailbox will stop receiving mail. And may eventually be deleted.
#2: Access and Delegation
Grant the users access to the newly converted shared mailbox. This will allow users to open the mailbox, read, and delete emails. Including replying to emails from the shared mailbox address while hiding their personal email address.
#To Grant Full Access (Read and Manage)
Add-MailboxPermission -Identity "[email protected]" -User "[email protected]" -AccessRights FullAccess -InheritanceType All -AutoMapping $true
#Send As Permission
Add-RecipientPermission -Identity "[email protected]" -Trustee "[email protected]" -AccessRights SendAs -Confirm:$false
#3: Mail Routing and Directory Cleanup
It is imperative for admins to manage the Global Address List (GAL). And ensure that offboarded employees do not clutter it while making sure that inbound external emails work perfectly.
Hiding offboarded employees from the GAL prevents the address from auto-populating when internal staff enters the user’s name in Outlook. Passively, forcing them to use active team members instead. To hide it, use the provided command:
Set-Mailbox -Identity "[email protected]" -HiddenFromAddressListsEnabled $true
Additionally, set up an internal and external message to notify senders that the individual is no longer with the company. But their message is being monitored. Run the given script:
Set-MailboxAutoReplyConfiguration -Identity "[email protected]" -AutoReplyState Enabled -InternalMessage "This person is no longer with the company. Your email is being reviewed by the team." -ExternalMessage "Thank you for reaching out. [Name] is no longer with [Company]. This inbox is monitored, and a team member will respond shortly."
#4: Backup and Retention Strategies
You may know that Microsoft does not take traditional point-in-time backups. This means if a delegate with “Full Access’ permanently deletes an email from the shared mailbox, it cannot be retrieved after 14 days (the default Recoverable Items window).
Therefore, one of the following backup configurations needs to be implemented.
- A Litigation Hold: It prevents anyone (including Global Admins) from permanently removing data from the mailbox for a specified duration.
- Export to PST using Microsoft Purview (eDiscovery): Ideal solution for organizations that want to remove the Microsoft 365 license completely. And no longer need the mailbox active.
- Use a third-party cloud-to-cloud backup such as SysTools Office 365 to Office 365 Migration Tool.
Conclusion
How to convert a user mailbox to a shared mailbox in Office 365 is more than just a routine query, specifically for admins tasked to:
- Eliminate license costs
- Strengthen identity security
- Data retention
- And overall business continuity
By applying the methods outlined in this comprehensive guide, you can easily convert an M365 regular mailbox to a shared mailbox without any data loss. And if you feel puzzled while executing any method or need any technical support, feel free to contact us at [email protected] or [email protected].
People Find Helpful:
- Office 365 Forward Shared Mailbox to Multiple Users Together
- Fix “Office 365 Shared Mailbox Emails Are Stuck in Outbox” Problem
- How to Save Sent Items in Shared Mailbox Office 365
- Migrate Shared Mailbox to Office 365 – Guide to Convert to Regular Mailbox
- How to Change Public Folder to Shared Mailbox?
FAQs (Frequently Asked Questions)
Q.1: Do I lose any emails when converting a user to a shared mailbox?
No, you will not lose any emails when converting a user to a shared mailbox. All your existing emails, calendar items, and contacts remain intact and accessible until you deactivate the user account.
Q.2: How long does it take for a shared mailbox to appear in Outlook?
After granting the required permissions, the shared mailbox usually takes 5 to 60 minutes to appear in Outlook.
Q.3: Do I need a license for a shared mailbox in Office 365?
No, a shared mailbox in Office 365 doesn’t require a separate license. Just make sure it remains under the 50 GB limit, and users access it using their own licensed accounts. Also, make sure each user who accesses the shared mailbox has an active Microsoft 365 business plan with Exchange Online.
Q.4: How to access a shared mailbox in Office 365 online?
Follow the given steps to access a shared mailbox in Office 365 online:
- Go to Outlook on the web >> sign in with the user account.
- Click on the profile picture or user icon (in the top-right corner).
- Select Open another mailbox >> enter the email address of the shared mailbox >> click Open.
Q.5: Shared mailbox greyed out in Exchange Admin Center?
This issue typically happens when the object is managed on-premises in a hybrid environment. Or your admin account lacks specific role permissions. To fix this issue, make changes on the local Exchange server or Active Directory. Check the assigned roles in the Exchange Admin Center under permissions.
Q.6: How to convert a hybrid mailbox to a shared mailbox?
Apply the following steps to convert a hybrid mailbox to a shared mailbox:
- Open the Exchange Management Shell (on the local server).
- Run the remote mailbox command: Set-RemoteMailbox -Identity [email protected] -Type Shared.
- Force a sync of Microsoft Entra Connect (to push the change to the cloud).
- Disable the user account in Active Directory and Block sign-in