Browse
On this page

When you connect your shared mailboxes

Mailboxes: one licensed delegate, or a licence for every mailbox

Most shops connect help@, billing@ and training@ by giving each one a Microsoft 365 licence and signing in as each one in turn. There is a cheaper way that is also the way Microsoft expects shared mailboxes to be used: licence one account, grant it rights on every shared mailbox, and authorize each mailbox signed in as that one account. The trap is that the two rights are separate, and the portal can only ever prove one of them at the moment you connect. This walk connects mailboxes the delegate way, reads the line that records it, and ends on the log that shows whether mail is really leaving.

What you will have

  • Connect several shared mailboxes through one licensed account instead of buying a licence for each one.
  • Grant the two Microsoft 365 permissions that matter, and know which one the portal can prove and which one it cannot.
  • Read the via line on an authorized mailbox as the record of which account is carrying the licence.
  • Tell Ready from Held, and know what a held function does with its mail.
  • Prove the send half with a test message, and read what actually left in the Email Log.

Why it works this way

A shared mailbox in Microsoft 365 does not need a licence of its own, and usually cannot sign in interactively at all. That is why the delegate pattern exists: one licensed account signs in on behalf of help@, billing@ and training@, and each mailbox records that account on its own row.

Full Access and Send As are two different grants, and only the first one can be checked when you connect. Authorizing reads the target mailbox's inbox folder and nothing else, which Full Access is enough for. Send As lives in Exchange and is invisible to that read, so a mailbox can read Connected and still refuse every single send.

That gap is the reason this page is written the way it is. A connection once read Connected for eleven days while Microsoft refused every send, the queue treated each refusal like a blipped network and retried it quietly, and nothing anywhere said so. The product now separates the two: Connected still means the read worked, and a second Cannot send badge appears beside it the moment a real send is refused.

When Send As is missing, Microsoft answers with an ErrorSendAsDenied refusal and the portal stops retrying on purpose. The message moves to Paused rather than Failed, because retrying would just re-run the same refusal every cycle. The banner names the mailbox and the account to grant it to, and once any send from that mailbox lands, the paused mail drains on its own without anyone pressing anything.

Sign-in links are the one exception to that queue. They expire in minutes, so instead of waiting behind a blocked mailbox they go out from the platform's own sender.

Held is exactly the opposite of Ready, nothing more. A function is Ready when its switch is on and its mailbox is connected, and Held in every other case. A held function's mail waits for a mailbox rather than quietly going out from a different one.

Send test email and the Email Log are not the same record. A test send is written to the audit log with its result, and it stamps or clears the connection's own send health. The Email Log carries the mail the product itself queued and sent, which is what makes it the honest place to check that ordinary mail is leaving.

Steps

  1. Pick the one account that will hold the licence.

    A service account is the usual choice, because it is not tied to a person who might leave. It is the only account in this arrangement that needs a Microsoft 365 licence. The shared mailboxes it will act for do not need one each.

  2. In Microsoft 365, grant that account Full Access and Send As on every shared mailbox.

    In the Exchange admin center go to Recipients, then Mailboxes, open the shared mailbox and find Manage mailbox delegation. Read and manage is Full Access, and it is what lets the portal read the mailbox. Send as is a separate grant, and it is what lets the portal send from the mailbox; Send on behalf is the other way to give that. Do it on help@, then billing@, then training@.

    Warning: Full Access on its own is not enough. A mailbox with read rights and no Send As connects, reads Connected, and still cannot send a single message.
  3. Open Integrations, then Microsoft Entra ID, and type the shared mailbox into Mailbox to connect.

    The field sits at the top of the Mail Connections card. Type the address of the shared mailbox you want, not the address of the delegate. Leaving it blank connects whichever mailbox you sign in as, which is the other pattern, not this one.

    Open Integrations, then Microsoft Entra ID, and type the shared mailbox into Mailbox to connect.
  4. Read the note under the field before you go to Microsoft.

    It says the next screen is Microsoft's own sign-in, and that you can either sign in with this exact address to connect it directly, or sign in with a different account that has been granted Full Access to this mailbox. It names the Microsoft screen the grant lives on, and it says in the same breath that sending also needs Send As or Send on Behalf, granted the same way and separate from Full Access.

    Read the note under the field before you go to Microsoft.
  5. Press Authorize a Mailbox and sign in as the licensed account.

    The portal hands you to Microsoft, you sign in as the delegate rather than as the mailbox, and Microsoft returns you here. The portal then checks one thing before it saves anything: can that account read the mailbox you named. A failed check saves nothing at all, so a refused grant never leaves a half-connected mailbox behind for someone to find later.

    Note: That check reads the mailbox and nothing else. It proves Full Access. It cannot prove Send As, and it never sends anything to try.
    Press Authorize a Mailbox and sign in as the licensed account.
  6. Do the same for the next mailbox, then read the via line on each row.

    Authorized mailboxes lists every mailbox connected here, each with Connected and, when the account that signed in was not the mailbox itself, via that account. Two mailboxes here, one account named on both, one licence paid for. That via line is the only place the arrangement is written down, so it is the thing to read when someone asks which account is carrying the mail.

    Do the same for the next mailbox, then read the via line on each row.
  7. Point each function at a mailbox.

    Help Desk, Billing and Training each have their own picker and their own switch. Help Desk and Billing read Ready, because each has a connected mailbox and its switch is on. Training reads Held with Not connected beside it, because nothing has been assigned to it yet, so training mail waits instead of going out from the help desk mailbox.

    Point each function at a mailbox.
  8. Prove the send half with Send test email.

    Send test email sits on each authorized mailbox row. It asks for a recipient address and then sends a real message from that mailbox through the same path production mail uses, which is the only thing that can prove Send As is really there. The result comes back on the row, with Microsoft's own error text when it fails, and the attempt is written to the audit log either way. A test that lands also clears a mailbox that was marked as unable to send.

    Prove the send half with Send test email.
  9. Check the same map from Settings, Email, Mailbox & Sending.

    The same three functions appear there read-only, each with Ready or Held and the mailbox it is using. Nothing is authorized on that page any more; Manage on the Microsoft 365 integration is the link back to the card you just used. The rest of that page is the mailbox's own behaviour rather than its identity: Mail From Name, Save to Sent Items, Email Listener, Inbox Cleanup and Unapproved Senders. Inbox Cleanup reads View only: it is set automatically to move a processed message to the Processed folder, not a picker you choose from. Mailbox & Sending is one of three tabs under Settings, Email, alongside Signature & Footer and Email Templates.

    Check the same map from Settings, Email, Mailbox & Sending.
  10. Open System Logs, then Email Log, to see what actually left.

    Email Audit Log lists every outbound message the portal has sent. Search by email or subject narrows it to one recipient or one thread, All Statuses narrows it to Queued, Retrying, Sent, Failed, Suppressed, Paused or Cancelled, and All Templates narrows it to one kind of message. This is where a client saying they never got the notification gets settled.

    Open System Logs, then Email Log, to see what actually left.
  11. Read the newest rows.

    Each row carries the linked ticket, the recipient, the subject, the template, the status, the person who triggered it and the date, and a failed send prints the provider's own error under its status. A day of rows that all read SENT is the delegate arrangement working, because every one of them left through a shared mailbox that one licensed account authorized. Paused is the status to look for when a mailbox can read but cannot send: those messages are held, not lost.

    Read the newest rows.
  12. Licence a mailbox on its own when it has to be more than a mailbox.

    A mailbox that is also a real person's account needs its own licence anyway, so there is nothing to save by delegating it. The same is true of a mailbox that has to sign in somewhere else, or one that lives in a different Microsoft tenant from the account you licensed, because a delegate can only act inside its own tenant. In those cases leave Mailbox to connect blank, or type that mailbox's own address, and sign in as the mailbox itself.

The pages behind each click

Other ways to do this

A licence for every mailbox

Authorize each mailbox signed in as itself, either by leaving Mailbox to connect blank or by typing its own address, with no delegation set up in Microsoft 365 at all.

The mailbox is also a real person's account, it has to sign in elsewhere anyway, or it sits in a different Microsoft tenant from the account you would have delegated to.

Send on behalf instead of Send As

Grant Send on behalf rather than Send as in the same Manage mailbox delegation screen; the portal accepts either one for sending.

You want recipients to see that the delegate sent on behalf of the shared mailbox, rather than seeing the shared mailbox alone.

If it did not work

  • A message reading that the mailbox was not found in this Microsoft 365 tenant means Microsoft could not match the exact address you typed. It is nearly always a typo or the wrong domain, so check it under Recipients in the Microsoft admin centre, or pick it from the suggestion list instead of typing it by hand.
  • A different message, saying the account you signed in as does not have delegate access, means the address is real and the grant is missing. Add that account under Manage mailbox delegation and try again.
  • Either failure saves nothing, so there is no half-connected row to clean up before you retry.
  • A new grant can take a few minutes to apply in Microsoft. If Authorize fails immediately after you granted it, wait a little and run it again.
  • A mailbox showing Connected and Cannot send together has Full Access but no Send As. Grant Send As to the account named on its via line, then use Send test email to clear it.
  • A function stuck on Held either has no mailbox assigned to it yet, or its own switch is off.

Questions this page answers

Authorizing a mailbox says it "was not found in this Microsoft 365 tenant" - why?

That message comes directly from Microsoft Graph: the exact address typed into the mailbox field doesn't match any mailbox in your tenant. It is almost always a typo, a missing letter or a missing dot in the domain, for example companyca instead of company.ca, or the wrong domain entirely, a mailbox that exists under an older or different domain. Double-check the address in Microsoft 365 admin center > Recipients before retrying, or pick it from the suggestion dropdown when one appears instead of typing it by hand. A different message, "that account does not have delegate access," means the address IS real but the signing-in account hasn't been granted Full Access yet, see the delegate-access help entry.

How do I connect the email system?

Settings → Email → Mailbox & Sending shows a read-only view of which mailbox each mail function (Help Desk, Billing, Training) is connected to. You do not authorize here anymore: connecting or reconnecting a mailbox happens on Admin > Integrations > Microsoft Entra ID, which this page links to. Once a mailbox is connected there, inbound polling and outbound sending for that function are automatic.

What does the Test button do?

The Send test email action is on the Mail Connections rows at Admin > Integrations > Microsoft Entra ID, not on this page. You pick a connected mailbox and type the recipient address, and it sends a real message from that mailbox so you can confirm OAuth and send permissions work. If it fails, the result and the provider error are shown inline and the send is recorded in the logs.

Where can I see email delivery status?

Email delivery status lives under Logs > Email Log (route /admin/logs/email), not on the Settings → Email page. The log tracks every outbound email the portal has sent, ticket notifications, meeting agendas, invoice alerts, and the like. Each row shows the recipient, subject, template used, any linked ticket, the sender who triggered it, and the delivery status, plus the error message when a send fails. Status is more than sent or failed. A row reads Queued or Sending while the message is on its way, Retrying when a send did not land and the portal is still trying, Paused when the mailbox it goes through cannot send at all, Sent when it went out, Suppressed when this instance is set to swallow outbound mail instead of sending it (a test/development setting), so the message never left the portal at all, Cancelled when the portal will not try again, and Failed when the portal gave up. A quote or invoice email lands at Cancelled instead of Retrying when no connected mailbox could carry it at all - you were already told nothing went out, so there is nothing to wait on. So a quote or an invoice you just sent can otherwise sit at Retrying for a while before it turns Sent. Filter by status or template, or search by recipient/subject, to troubleshoot a delivery problem, for example when a client says they never got a notification.

What does the Mailbox & Sending tab control?

The Mailbox & Sending tab controls the mailbox's inbound and outbound behavior; its sibling tabs are Signature & Footer and Email Templates. Email Listener turns the background poller on or off (it checks the shared mailbox for new messages to turn into tickets). Inbox Cleanup shows what happens to a message once it's been processed. It is set automatically and marked View only, not a picker: today every processed message moves to Processed, and no other choice is wired up yet. The tab also sets the outgoing From Name, whether outbound mail is saved to the mailbox's Sent Items, and how mail from unapproved senders is handled. There is no send-as or sign-in-identity field to type anymore; those derive automatically from the mailbox you connect under Admin > Integrations > Microsoft Entra ID.

What is the Mail Connections card?

Each mail function (Help Desk, Billing, Training) is powered by its own delegated Microsoft mailbox, and this page shows their connection status read-only. To connect or reauthorize a mailbox (after a revoked token or a mailbox-owner change), use the link to Admin > Integrations > Microsoft Entra ID, the one place the OAuth sign-in and mailbox delegation live.

Was this helpful?

Last validated 2026-09-18