Everyday IT · Microsoft 365 & Email

Start with the mailbox, then prove the mail flow.

Most everyday Microsoft 365 email tickets become easier when you separate licensing, mailbox type, permissions, and transport.Do not guess where the message went. Check the object, check the permission, then trace the message.

Microsoft 365 licensing basics

A user object existing in the tenant does not mean every service is provisioned.

License

Match the role

Assign the service level the employee actually needs. Compare with similar users, but do not assume every long-term employee has the ideal license.

Service plan

Check what the license enables

Exchange Online, Teams, SharePoint, OneDrive, desktop apps, and security capabilities can depend on different plans or service toggles.

Provisioning

Cloud changes are not always instant

Mailbox creation, license changes, permissions, and directory synchronization can take time. Repeatedly toggling settings can make troubleshooting harder.

User mailbox vs shared mailbox

Choose the mailbox type based on who is using it and how.

User mailbox

Belongs to an individual sign-in

A user mailbox is tied to a licensed user identity and is appropriate for a person's normal email account.

Shared mailbox

Used by a team or role

Shared mailboxes are useful for addresses like billing@, support@, or intake@ where multiple people need access. Users normally access them through delegated permissions rather than signing in as the mailbox.

Permissions

Know Full Access, Send As, and Send on Behalf

Reading a shared mailbox and sending as it are separate permissions. A user may be able to open the mailbox but still be unable to send from that address.

Distribution lists in the real world

Distribution lists route messages. They are not the same thing as shared mailboxes or security groups.

Membership

Who should receive the mail?

Confirm the user is actually a member and whether nested groups or dynamic membership are involved.

Ownership

Someone should own the list

Clear ownership makes membership changes and moderation easier. Old lists often fail operationally because nobody knows who is responsible for them.

Delivery controls

External senders may be blocked

If outside senders cannot reach the list, check delivery management, moderation, transport rules, and anti-spam controls before changing membership.

When email “disappears”

Separate delivery from what Outlook happens to show.

Step 1

Get one exact example

Ask for sender, recipient, subject, and approximate time. “Email has been slow” is not enough evidence to investigate.

Step 2

Run a basic message trace

Determine whether Microsoft 365 received the message, delivered it, rejected it, redirected it, or is still processing it.

Step 3

If delivery is clean, move local

If Exchange shows successful delivery, check Outlook rules, Junk Email, Focused Inbox, cached mode, profile health, local connectivity, add-ins, and synchronization.

Step 4

If transport failed, follow the evidence

Use the trace result, bounce message, connector, rule, policy, or rejection reason to decide the next step instead of changing unrelated settings.

Common daily tickets

Most email issues fall into a few repeatable categories.

Mailbox missing

Check license, provisioning, and Outlook state

For a user's primary mailbox, confirm the Exchange service is assigned. For a shared mailbox, verify delegation and allow time for auto-mapping before forcing manual changes.

Cannot send as

Read permission is not send permission

Verify Send As or Send on Behalf separately and allow for propagation.

Not receiving group mail

Confirm the object and delivery path

Check membership, group type, delivery restrictions, moderation, and message trace.

Mail comes in batches

Prove whether Exchange delayed it

Message trace can show whether Microsoft 365 delivered messages promptly. If cloud delivery is clean but Outlook updates in bursts, investigate the client rather than rewriting mail flow.

What not to touch casually

Mail flow is organization-wide infrastructure.

Red flag

Transport rules

Do not create or disable broad mail flow rules to fix one user's symptom without understanding every sender and recipient they may affect.

Red flag

Connectors and accepted domains

Connector, relay, domain, and routing changes can affect the entire organization and should be handled as planned changes.

Red flag

Security policies

Do not weaken anti-spam, anti-phishing, Defender, or authentication controls simply to make a message pass.

Red flag

Repeated permission toggling

If a delegated permission has just been changed, allow reasonable propagation time and verify the object before removing and re-adding it repeatedly.