Enhancing Security for Shared Mailboxes: Seeking Best Practices and Advice

Al Khazragy Laith 40 Reputation points
2024-07-31T11:32:54.4+00:00

Hello,

I want to enhance the security level of access control for our shared mailboxes. Currently, users are being added individually to manage access, which is not ideal.

In my opinion, distribution lists (DLs) are best suited for sharing news with a large number of people at once, rather than for managing access to shared mailboxes. To improve security, I’ve started using security groups for this purpose, and it works efficiently. However, there’s an issue: when I add a user individually, the shared mailbox appears automatically in their Outlook. But when I add the user to a security group, the shared mailbox does not appear automatically.

Can you advise on the best practices and standard methods to securely handle this situation?

Thanks.

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,598 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,686 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Vasil Michev 108.6K Reputation points MVP
    2024-07-31T15:33:06.53+00:00

    If Automapping is a requirements, you don't have a choice really - this only works when granting permissions individually to the user, nor via group. The alternative it to educate users how to add the shared mailbox as additional account in Outlook (via File > Add account) or OWA (Open another mailbox feature)... which might be a harder task :)

    1 person found this answer helpful.
    0 comments No comments

  2. Xintao Qiao-MSFT 3,995 Reputation points Microsoft Vendor
    2024-08-01T05:41:57.87+00:00

    Hi, @Al Khazragy Laith

    From your description, I understand that after you add a user to a security group, the shared mailbox does not appear in Outlook.

    As Vasil Michev said, auto-mapping only works if you assign permissions to individual users, but not for groups. And when you assign full access to a security group, the shared mailbox does not appear in each user's Outlook file. This is also confirmed by the screenshots and articles below.

    User's image

    More information can be found Manage permissions for recipients | Microsoft Learn

    In addition, you can follow Vasil Michev, and you can also try the following methods to check and add a shared mailbox to the folder pane.

    1.Check if MAPI is enabled for the affected shared mailbox in Exchange admin center.

    Exchange admin center > Recipients > Mailboxes > select the shared mailbox > manage email apps settings.

    User's image

    User's image

    2.In OWA, right click on folders in the folder pane > Add shared folder or mailbox > type the shared mailbox name/email address.

    Then the shared mailbox will appear in the folder pane.

    User's image

    Similar threads are available for your reference Shared Mailbox permissions to security group not showing in Outlook? - Microsoft Q&A

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.