Recover
“We need the old mailbox or missing data back.”
This is a recovery problem. Determine whether the mailbox, user, deleted items, archive, or retained content still exists before creating forwarding or delegation as a substitute.
Everyday IT · Microsoft 365 & Email
Mailbox recovery, mailbox access, future mail delivery, and sending identity are different problems. Choosing the wrong action can create licensing, security, privacy, or offboarding mistakes.Do not start with the button. Start with what the business needs to happen next.
One sentence usually tells you which mailbox path belongs in the ticket.
Recover
This is a recovery problem. Determine whether the mailbox, user, deleted items, archive, or retained content still exists before creating forwarding or delegation as a substitute.
Read
This is delegation. Full Access allows an approved delegate to open and manage mailbox content, but sending permissions are separate.
Receive
This is mail-flow handling. Forwarding changes where future messages are delivered; it does not grant access to historical mailbox content.
Send
This is sending identity. Send As and Send on Behalf are separate from mailbox-reading access and should match the business requirement.
Preserve
This is an offboarding and lifecycle decision. Shared-mailbox conversion may preserve content while allowing approved users to access it, but retention, holds, licensing, security, and account state still matter.
Replace
Decide whether the business needs historical access, a shared role address, forwarding, or a clean new mailbox. Do not simply hand the former employee's identity to another person.
Separate data, access, delivery, identity, and lifecycle before changing anything.
1
If the requirement is historical recovery, establish the mailbox state first. Deleted-user recovery, retention, archive, and restore scenarios are not the same as delegation.
2
If yes, evaluate approved delegation or a shared-mailbox model. Full Access controls mailbox access; it does not automatically grant Send As or Send on Behalf.
3
If yes, decide whether the address remains an active shared business identity, should forward elsewhere, or should be replaced by another role-based address.
4
If yes, explicitly choose the appropriate sending permission. Do not assume mailbox access means sending rights.
5
Apply the organization's offboarding, privacy, legal, retention, and identity-verification requirements before granting access or changing delivery.
6
Forwarding policy, retention, legal hold, shared-mailbox design, executive mailboxes, privileged accounts, and tenant-wide mail-flow changes deserve planned review rather than an improvised ticket fix.
These actions solve different problems.
Restore / recover
Use recovery when the required content or mailbox is missing. First identify whether you are dealing with a deleted user, deleted mailbox, deleted items, archive, or retained content.
Full Access
Full Access allows reading and mailbox management. It does not by itself allow the delegate to send as the mailbox.
Send As
Messages appear to come directly from the mailbox. This is a stronger identity choice than simply allowing someone to read the mailbox.
Send on Behalf
The sender is shown as acting on behalf of the mailbox. Use it when that distinction matches the organization's communication requirement.
Forwarding
Forwarding changes delivery for new mail. It does not restore historical content and does not grant the recipient access to the original mailbox.
Shared mailbox
Conversion can preserve existing mail and calendar content while allowing approved delegates to access the mailbox. Licensing, mailbox size, archive/hold requirements, and the linked account state must still be checked.
Offboarding often needs several separate decisions.
Identity
Preserving the mailbox does not mean the former employee should retain the ability to sign in. Follow the organization's offboarding process for account, session, and authentication state.
Content
Grant only the approved users the level of mailbox access they need. Executive, HR, legal, finance, and other sensitive mailboxes may require additional approval.
Delivery
Keep the address active as a shared business identity, forward new messages, use an automatic reply, or retire the address according to business need.
Compliance
Business continuity access and legal retention are not the same thing. Holds, retention policies, archive licensing, and legal requirements should be handled under the organization's compliance design.
Preserve the mailbox if the business needs the mailbox. Delegate access if someone needs the content. Forward only if future delivery needs to change.
“Shared mailbox means no license” is too simple to use as an operating rule.
Baseline
Microsoft currently documents unlicensed shared mailboxes as limited to 50 GB. Larger mailboxes and certain archive or hold capabilities require appropriate licensing.
Conversion
Microsoft's current guidance says a user mailbox must be licensed before conversion to shared. After conversion, license removal depends on size and feature requirements.
Account
Microsoft documents that the associated account remains required for the shared mailbox. Offboarding should block user access without destroying the mailbox relationship the organization still needs.
Hybrid
Hybrid Exchange environments can require on-premises or remote-mailbox changes. Do not apply cloud-only conversion logic to a hybrid-managed object without checking where it is authoritative.
These are different fixes for different problems.
Wrong turn
Forwarding only affects future delivery. Historical access requires recovery, delegation, shared-mailbox access, or another approved content path.
Wrong turn
Mailbox access and sending identity are separate permissions. Define whether the delegate should read, Send As, Send on Behalf, or some combination.
Wrong turn
Reuse of another person's identity creates audit, privacy, security, and attribution problems. Preserve the mailbox separately from the user identity.
Wrong turn
Mailbox size, archive, holds, retention, and conversion state can affect licensing requirements. Verify them before license removal.
Wrong turn
A shared mailbox still depends on its associated account object. Block sign-in as required, but do not delete objects casually when the mailbox must remain.
Wrong turn
Broad mail-flow and compliance changes have a larger blast radius than a single mailbox ticket. Treat them as planned changes.
Use the business outcome to move into the right deeper guide.
Former employee
Use the offboarding path to preserve the mailbox without preserving the former employee's access. Former Employee Mailbox
Delegation
Separate Full Access from Send As and Send on Behalf. Shared Mailbox Permissions
Outlook
Move into propagation, auto-mapping, and Outlook state. Shared Mailbox Not Showing
Archive
Use the deeper Exchange archive investigation rather than changing delegation or forwarding. Investigate Exchange Online archive behavior
Risk
Define approvals, blast radius, rollback, compliance requirements, and verification before acting. Plan the change safely
Recover data when data is missing. Delegate when someone needs access. Forward when future delivery must change. Preserve the identity boundary throughout.
If the request involves executive or legal mail, broad forwarding, retention design, hybrid Exchange, privileged access, or a mailbox lifecycle you cannot safely reverse, bring in experienced help before making the change.