What Managing Thousands of Shared Mailboxes Taught Me About Governance (and What Small Businesses Get Wrong)
In my enterprise role I am responsible for the lifecycle of thousands of shared mailboxes in a 200,000-user Microsoft 365 environment. Every one of them has automated governance wrapped around it: access is time-boxed and reviewed on a schedule, legal hold and audit settings are enforced rather than hoped for, and mailboxes that stop being used get archived by a process, not by a person remembering. Small businesses do not need that machinery. But after years of watching what goes wrong at scale, I can tell you the failure patterns are identical in a tenant with twelve shared mailboxes, they just take longer to hurt. Here is what the enterprise version taught me, and the small business version of each lesson.
Lesson one: shared mailboxes are immortal unless something kills them
Nobody ever decommissions a shared mailbox. Creating one takes two minutes and solves today's problem; deleting one requires someone to be confident nothing still depends on it, and nobody is ever confident. So they accumulate. At scale, unmanaged, you end up with thousands of mailboxes where a meaningful fraction have had no activity in years, each one still holding data, still a compliance surface, still something an attacker can hide in.
The enterprise answer is automation: if a mailbox has no activity for a defined period, a process flags it, checks with the owner, and archives it. The small business answer is a calendar entry: once or twice a year, list every shared mailbox, look at last activity, and make a deliberate keep-or-archive decision for each. Twelve mailboxes takes twenty minutes. The point is not the tooling, it is that removal is somebody's job.
Lesson two: access should expire by default
This is the single biggest mindset difference between well-governed and badly-governed tenants. In most small businesses, access to a shared mailbox is granted once and lives forever. The person who covered accounts@ during someone's parental leave in 2022 still has access. The ex-contractor's account was disabled, but the permission entry is still sitting there waiting for the account to be reused or restored.
At enterprise scale we time-box access: it is granted for a period, and keeping it requires the access to be re-justified at a periodic review. The scaled-down version is not complicated: when you grant shared mailbox access for a temporary reason, put an end date in your calendar to remove it, and once a year pull the permission list for each mailbox and ask one question per name: does this person still need this? You will remove someone every single time you do this. I have never seen a review that removed nobody.
Lesson three: ownership is the whole game
Every governance failure I have investigated traces back to the same root cause: nobody owned the mailbox. Not nobody had access, plenty of people had access. Nobody was responsible. When a mailbox has a named owner, questions have somewhere to go: should this person get access, is this mailbox still needed, why is it nearly full, who approved that auto-forward to an external address. When it does not, every one of those questions gets answered by silence.
The fix costs nothing: a simple register, even a spreadsheet, listing every shared mailbox, its purpose, and its owner, reviewed whenever someone leaves. Offboarding is the moment ownership breaks, because the departing person's mailboxes silently become orphans. Make reassignment of owned mailboxes a line item in your offboarding checklist and the problem largely disappears.
Lesson four: legal hold is a decision you make before you need it
Here is the uncomfortable one. When a legal matter, an insurance claim, or a serious HR issue lands, the first question is whether the relevant email still exists. If the answer depends on which mailbox it sat in, whether that mailbox was licensed, whether retention was configured, and whether anyone thought about it, you are having the worst version of that conversation, at the worst possible time.
In the enterprise environment, hold and audit settings are enforced by policy across the fleet, so the answer is always yes before anyone asks. A small business does not need fleet automation, it needs one deliberate decision: which of our mailboxes hold material we may need to produce (accounts@, contracts@, anything customer-facing in a regulated industry), and is retention or hold actually configured on those, noting that litigation hold on a shared mailbox requires a licence. Deciding this in a calm quarter costs an hour. Discovering it during a dispute costs considerably more, and sometimes the case.
Lesson five: governance is what runs when nobody is looking
The pattern across all of these: a policy document is not governance. A well-intentioned rule that relies on a busy person remembering is a rule that stops working the first busy month. At scale we solve that with automation. At small scale you solve it with recurring calendar events and checklists, which are just automation for humans. The standard is the same: would this still happen if the person who cares about it went on leave?
| Enterprise practice | The 12-mailbox version |
|---|---|
| Automated inactivity detection and archiving | Annual keep-or-archive review of every shared mailbox |
| Time-boxed access with scheduled access reviews | End dates on temporary access, yearly permission list check |
| Ownership recorded and enforced in tooling | A mailbox register with a named owner per mailbox |
| Hold and audit settings enforced by policy | One deliberate retention decision on the mailboxes that matter |
| Offboarding triggers automated reassignment | Mailbox reassignment as an offboarding checklist item |
If you want the current state of your own tenant measured against this list, mailbox permissions, ownership, retention posture and all, that is exactly what the fixed-price Microsoft 365 Health Check produces: $599 GST inclusive, prioritised report, 30-minute walkthrough.
See what the Health Check covers →Where to start this week
- •List every shared mailbox in your tenant (five minutes in the admin centre).
- •Write a name next to each one. Anything with no plausible owner goes on the review pile.
- •Pull the permission list for your three most important mailboxes and remove anyone who should not be there.
- •Decide your retention posture for the mailboxes that hold material you might one day need to produce.
- •Put the annual review in the calendar. That single recurring event is most of the value.
None of this requires enterprise tooling, a project, or a budget. It requires deciding that shared mailboxes are infrastructure rather than furniture, and giving them the same twenty minutes of periodic attention you would give anything else the business depends on.
Frequently asked questions
How often should shared mailbox access be reviewed?
At minimum annually for a small business, and immediately whenever someone leaves the organisation. Enterprise environments run scheduled access reviews; the small business equivalent is a recurring calendar event and a permission list.
What should a shared mailbox register include?
The mailbox address, its purpose, a named owner, who currently has access, and whether retention or legal hold applies. A spreadsheet is entirely adequate at small scale.
Does legal hold work on an unlicensed shared mailbox?
No. Litigation hold and archiving on a shared mailbox require an Exchange Online licence. If a mailbox holds material you may need to produce, licensing it is part of the retention decision.
What happens to shared mailboxes when the owner leaves?
By default, nothing, which is the problem. The permissions stay, the mailbox keeps receiving mail, and nobody is responsible for it. Reassigning ownership should be a standard step in your offboarding process.