Everyday IT · Microsoft 365 & Email

Restore, delegate, forward, or convert? Start with the business outcome.

Mailbox recovery, mailbox access, future mail delivery, and sending identity are different problems. Choosing the wrong action can create licensing, security, privacy, or offboarding mistakes.Do not start with the button. Start with what the business needs to happen next.

What outcome are you actually trying to achieve?

One sentence usually tells you which mailbox path belongs in the ticket.

Recover

“We need the old mailbox or missing data back.”

This is a recovery problem. Determine whether the mailbox, user, deleted items, archive, or retained content still exists before creating forwarding or delegation as a substitute.

Read

“Someone else needs access to the mailbox.”

This is delegation. Full Access allows an approved delegate to open and manage mailbox content, but sending permissions are separate.

Receive

“Future mail should go somewhere else.”

This is mail-flow handling. Forwarding changes where future messages are delivered; it does not grant access to historical mailbox content.

Send

“Someone needs to send from this address.”

This is sending identity. Send As and Send on Behalf are separate from mailbox-reading access and should match the business requirement.

Preserve

“The employee left, but the mailbox must remain available.”

This is an offboarding and lifecycle decision. Shared-mailbox conversion may preserve content while allowing approved users to access it, but retention, holds, licensing, security, and account state still matter.

Replace

“A new person is taking over the role.”

Decide whether the business needs historical access, a shared role address, forwarding, or a clean new mailbox. Do not simply hand the former employee's identity to another person.

The decision tree

Separate data, access, delivery, identity, and lifecycle before changing anything.

1

Does the original mailbox or data still exist?

If the requirement is historical recovery, establish the mailbox state first. Deleted-user recovery, retention, archive, and restore scenarios are not the same as delegation.

2

Does another person need to read historical content?

If yes, evaluate approved delegation or a shared-mailbox model. Full Access controls mailbox access; it does not automatically grant Send As or Send on Behalf.

3

Should future mail continue reaching this address?

If yes, decide whether the address remains an active shared business identity, should forward elsewhere, or should be replaced by another role-based address.

4

Should another user send from the old or shared address?

If yes, explicitly choose the appropriate sending permission. Do not assume mailbox access means sending rights.

5

Is this a former employee or sensitive mailbox?

Apply the organization's offboarding, privacy, legal, retention, and identity-verification requirements before granting access or changing delivery.

6

Is the change broader than one mailbox?

Forwarding policy, retention, legal hold, shared-mailbox design, executive mailboxes, privileged accounts, and tenant-wide mail-flow changes deserve planned review rather than an improvised ticket fix.

What each option actually does

These actions solve different problems.

Restore / recover

Bring back mailbox data or the mailbox object

Use recovery when the required content or mailbox is missing. First identify whether you are dealing with a deleted user, deleted mailbox, deleted items, archive, or retained content.

Full Access

Let an approved delegate open the mailbox

Full Access allows reading and mailbox management. It does not by itself allow the delegate to send as the mailbox.

Send As

Send as the mailbox identity

Messages appear to come directly from the mailbox. This is a stronger identity choice than simply allowing someone to read the mailbox.

Send on Behalf

Make the delegate visible

The sender is shown as acting on behalf of the mailbox. Use it when that distinction matches the organization's communication requirement.

Forwarding

Redirect future messages

Forwarding changes delivery for new mail. It does not restore historical content and does not grant the recipient access to the original mailbox.

Shared mailbox

Keep a mailbox as a shared business resource

Conversion can preserve existing mail and calendar content while allowing approved delegates to access the mailbox. Licensing, mailbox size, archive/hold requirements, and the linked account state must still be checked.

Former employee mailbox: do not confuse preservation with access

Offboarding often needs several separate decisions.

Identity

Block the former user's access

Preserving the mailbox does not mean the former employee should retain the ability to sign in. Follow the organization's offboarding process for account, session, and authentication state.

Content

Decide who needs historical mail

Grant only the approved users the level of mailbox access they need. Executive, HR, legal, finance, and other sensitive mailboxes may require additional approval.

Delivery

Decide what future mail should do

Keep the address active as a shared business identity, forward new messages, use an automatic reply, or retire the address according to business need.

Compliance

Retention is a different requirement

Business continuity access and legal retention are not the same thing. Holds, retention policies, archive licensing, and legal requirements should be handled under the organization's compliance design.

Preserve the mailbox if the business needs the mailbox. Delegate access if someone needs the content. Forward only if future delivery needs to change.

Shared mailbox licensing: check the exceptions

“Shared mailbox means no license” is too simple to use as an operating rule.

Baseline

Size and features matter

Microsoft currently documents unlicensed shared mailboxes as limited to 50 GB. Larger mailboxes and certain archive or hold capabilities require appropriate licensing.

Conversion

The mailbox must exist correctly before conversion

Microsoft's current guidance says a user mailbox must be licensed before conversion to shared. After conversion, license removal depends on size and feature requirements.

Account

Do not casually delete the anchor

Microsoft documents that the associated account remains required for the shared mailbox. Offboarding should block user access without destroying the mailbox relationship the organization still needs.

Hybrid

Directory authority changes the procedure

Hybrid Exchange environments can require on-premises or remote-mailbox changes. Do not apply cloud-only conversion logic to a hybrid-managed object without checking where it is authoritative.

Common wrong turns

These are different fixes for different problems.

Wrong turn

Forwarding because someone needs old mail

Forwarding only affects future delivery. Historical access requires recovery, delegation, shared-mailbox access, or another approved content path.

Wrong turn

Full Access because someone needs to send

Mailbox access and sending identity are separate permissions. Define whether the delegate should read, Send As, Send on Behalf, or some combination.

Wrong turn

Giving the replacement employee the old login

Reuse of another person's identity creates audit, privacy, security, and attribution problems. Preserve the mailbox separately from the user identity.

Wrong turn

Removing licensing before checking mailbox requirements

Mailbox size, archive, holds, retention, and conversion state can affect licensing requirements. Verify them before license removal.

Wrong turn

Deleting the account after conversion

A shared mailbox still depends on its associated account object. Block sign-in as required, but do not delete objects casually when the mailbox must remain.

Wrong turn

Changing tenant-wide forwarding or retention to solve one request

Broad mail-flow and compliance changes have a larger blast radius than a single mailbox ticket. Treat them as planned changes.

Next Test

Use the business outcome to move into the right deeper guide.

Former employee

The mailbox must remain available

Use the offboarding path to preserve the mailbox without preserving the former employee's access. Former Employee Mailbox

Risk

The mailbox is sensitive or the change is broad

Define approvals, blast radius, rollback, compliance requirements, and verification before acting. Plan the change safely

Recover data when data is missing. Delegate when someone needs access. Forward when future delivery must change. Preserve the identity boundary throughout.

If the request involves executive or legal mail, broad forwarding, retention design, hybrid Exchange, privileged access, or a mailbox lifecycle you cannot safely reverse, bring in experienced help before making the change.