Exchange OnlineDeep dive

Distribution groups vs Microsoft 365 Groups vs shared mailboxes: which one to use and how to convert

A capability-by-capability comparison of distribution groups, dynamic groups, Microsoft 365 Groups and shared mailboxes, when to choose each, how to upgrade a DL and the PowerShell to answer the usual questions.

"Can you make us a group for the project?" is one of the most common requests an Exchange admin gets, and the right answer depends on what the team actually wants: an address that fans mail out, a shared inbox someone has to answer from, or a workspace with files and a Teams channel. In this post I'll compare distribution groups, dynamic distribution groups, Microsoft 365 Groups and shared mailboxes feature by feature, explain when each is the right pick, show how to upgrade a distribution list and how to answer the recurring questions about send-as, moderation and hiding from the address book.

How this guide is organised: How it works → Step-by-step → Common questions → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. How it works. 2. Step-by-step (3 steps: Pick the right object; Upgrade a distribution list to a Microsoft 365 Group; Dynamic distribution groups done right). 3. Common questions. 4. Verify. 5. Tips & gotchas. Toolbox: Set-DistributionGroup, Set-UnifiedGroup, Set-Mailbox, Recipients › Groups, ManagedBy.1How it works2Step-by-step3Commonquestions4Verify5Tips & gotchas1Pick the right object2Upgrade a distributionlist to a Microsoft 365 G…3Dynamic distributiongroups done rightTOOLBOXSet-DistributionGroupSet-UnifiedGroupSet-MailboxRecipients › GroupsManagedByHow this guide is organised: How it works → Step-by-step → Common questions → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. How it works. 2. Step-by-step (3 steps: Pick the right object; Upgrade a distribution list to a Microsoft 365 Group; Dynamic distribution groups done right). 3. Common questions. 4. Verify. 5. Tips & gotchas. Toolbox: Set-DistributionGroup, Set-UnifiedGroup, Set-Mailbox, Recipients › Groups, ManagedBy.1How it works2Step-by-step1Pick the right object2Upgrade a distribution list to a Microsoft 365Group3Dynamic distribution groups done right3Common questions4Verify5Tips & gotchasTOOLBOXSet-DistributionGroupSet-UnifiedGroupSet-MailboxRecipients › GroupsManagedBy
At a glance: how this guide is organised · 3 steps · 5 key settings and tools

How it works: what each object really is#

CapabilityDistribution groupDynamic distribution groupMicrosoft 365 GroupShared mailbox
Email to all membersYesYes (membership from a recipient filter)Yes, and a copy is kept in the group mailboxMail lands in one mailbox that members open
Shared calendarNoNoYesYes
Files, Planner, OneNote, TeamsNo (members can be added to a team, not the group)NoSharePoint site, Planner, notebook; can be connected to Teams or Viva EngageNo
Membership managementOwners (ManagedBy), join/leave restrictionsAttribute rules, refreshed at least every 24 hoursOwners and members, guests allowed if enabledPermissions, not membership
Dynamic membershipNoExchange recipient filterMicrosoft Entra dynamic membership rulesNo
External sendersIf allowedIf allowedIf allowedIf allowed
Send as / send on behalfYes, with permissionYes, with permissionYes, if enabled by an adminYes, with permission
StorageNoneNoneGroup mailbox 50 GB; files 1 TB plus 10 GB per licensed user50 GB free; 100 GB with Exchange Online Plan 2 or Plan 1 plus Exchange Online Archiving

A distribution group is a pure fan-out: nothing is stored, every member gets their own copy, and it's the lightest object for "everyone in Building A". A dynamic distribution group is the same thing with membership computed from attributes such as Department or CustomAttribute1-15. In Exchange Online the member list is calculated when you create or change the rules and refreshed at least once every 24 hours, so a user who changes department can keep receiving (or miss) mail until the next refresh; since late May 2026 groups with 5,000 or fewer matching members populate immediately, larger ones within about two hours. Dynamic groups aren't synced to Microsoft Entra ID, so you can't use them in Conditional Access. A Microsoft 365 Group is a membership object in Entra ID with a mailbox, calendar, SharePoint site and Planner attached; Teams is built on it. A shared mailbox is just a mailbox without its own sign-in that several people open with Full Access, and it's the right answer when someone must answer from the address. Note that you can't convert a shared mailbox into a Microsoft 365 Group; the migration path only exists for distribution lists.

Licensing: any plan that includes Exchange Online and SharePoint supports Microsoft 365 Groups (Business Basic upwards); Exchange-only plans get the shared inbox and calendar but no site or Planner. Shared mailboxes need no licence until you need more than 50 GB, an archive or a hold.

Step 1: Pick the right object#

  • Broadcast list, nobody replies "as" the list: distribution group. Use a dynamic group if the audience is defined by an attribute you keep accurate.
  • A team working on something together: Microsoft 365 Group, usually created from Teams. Members get conversations, files and a calendar in one place, and the history stays when people leave.
  • A functional address such as support@ or invoices@: shared mailbox. Replies go out as the mailbox, the Sent Items can be kept in it, and categories or folders can be used to track work.
  • Permissions on SharePoint or apps plus occasional email: mail-enabled security group, which can't be dynamic and can't contain devices.

Step 2: Upgrade a distribution list to a Microsoft 365 Group#

In the Exchange admin center open Recipients › Groups, select the distribution list and choose Upgrade distribution group; the change is permanent. In PowerShell:

PowerShell
Connect-ExchangeOnline
Upgrade-DistributionGroup -DlIdentities hr@contoso.com,finance@contoso.com

Only cloud-managed, simple, non-nested distribution lists qualify. Microsoft's list of blockers: the list is nested (has child groups or is a member of another group); it's managed on-premises; it has more than 100 owners, or members but no owner, or no members; a member isn't a UserMailbox, SharedMailbox, TeamMailbox or MailUser; it's the forwarding address of a shared mailbox; it's used in another list's sender restrictions; its alias contains special characters; it's a mail-enabled security group, a dynamic group, or was converted to a room list. A custom email address policy created with IncludeUnifiedGroupRecipients also makes the cmdlet fail; remove it first and recreate it afterwards.

Step 3: Dynamic distribution groups done right#

PowerShell
# Pre-canned filter (AND between conditions)
New-DynamicDistributionGroup -Name "Sales - all staff" -IncludedRecipients MailboxUsers -ConditionalDepartment "Sales"
# Custom filter (PowerShell only; no leading wildcards)
New-DynamicDistributionGroup -Name "Full-time employees" `
    -RecipientFilter "(RecipientTypeDetails -eq 'UserMailbox') -and (CustomAttribute10 -eq 'FullTimeEmployee')"
# Preview who the filter matches right now, then view the stored member list
$ddg = Get-DynamicDistributionGroup -Identity "Full-time employees"
Get-Recipient -RecipientPreviewFilter $ddg.RecipientFilter -ResultSize 100
Get-DynamicDistributionGroupMember -Identity "Full-time employees"

Attribute values must match exactly (they aren't case-sensitive), and the admin center can only build the pre-canned filters.

Common questions#

  • Send as or send on behalf. Send As is a recipient permission on all four object types: Add-RecipientPermission -Identity support@contoso.com -Trustee adele@contoso.com -AccessRights SendAs. Send on behalf is a property: Set-DistributionGroup, Set-UnifiedGroup or Set-Mailbox with -GrantSendOnBehalfTo. For shared mailboxes add Set-Mailbox -MessageCopyForSentAsEnabled $true so replies stay in the shared Sent Items.
  • External senders. All four reject internet mail by default. Set-DistributionGroup, Set-DynamicDistributionGroup or Set-UnifiedGroup -RequireSenderAuthenticationEnabled $false opens them up; for a shared mailbox it's the same parameter on Set-Mailbox.
  • Moderation. Set-DistributionGroup -ModerationEnabled $true -ModeratedBy "megan@contoso.com", optionally with -BypassModerationFromSendersOrMembers and -SendModerationNotifications. The same parameters exist on dynamic groups and Microsoft 365 Groups.
  • Hiding from the GAL. -HiddenFromAddressListsEnabled $true on any of them; a hidden object still receives mail if someone types the address. Teams-created groups are also hidden from Outlook by HiddenFromExchangeClientsEnabled, which you can flip with Set-UnifiedGroup if the team wants its group mailbox visible.
  • Who can join a distribution list. MemberJoinRestriction (Open, Closed, ApprovalRequired) and MemberDepartRestriction (Open, Closed) on Set-DistributionGroup.

Verify#

PowerShell
Get-DistributionGroup -ResultSize Unlimited |
    Format-Table Name, RecipientTypeDetails, RequireSenderAuthenticationEnabled, ModerationEnabled, HiddenFromAddressListsEnabled
Get-UnifiedGroup -Identity "Project Falcon" | Format-List AccessType, RequireSenderAuthenticationEnabled, HiddenFromExchangeClientsEnabled, SharePointSiteUrl
Get-UnifiedGroupLinks -Identity "Project Falcon" -LinkType Members
Get-Mailbox -RecipientTypeDetails SharedMailbox -ResultSize Unlimited | Format-Table Name, PrimarySmtpAddress, ProhibitSendReceiveQuota
Get-RecipientPermission -Identity support@contoso.com | Format-Table Trustee, AccessRights

Send one test message to each object from an external account and one from inside; the external one should bounce unless you opened the group, and the internal one should appear in the group mailbox (Microsoft 365 Group) or the shared Inbox.

Tips & gotchas#

  • A Microsoft 365 Group can't be a member of a distribution group or a security group; adding a distribution group to a team copies its members rather than linking the group.
  • Deleting a cloud distribution list is final, while a deleted Microsoft 365 Group can be restored for 30 days; export the member list before you remove a list.
  • A dynamic group that's empty right after creation isn't broken if it has more than 5,000 matches: give the background calculation up to two hours, and use Get-Recipient -RecipientPreviewFilter in the meantime.
  • Block sign-in on the account behind every shared mailbox; nobody should authenticate as it.
  • Owners matter: a list with members and no owner can't be upgraded, and ownerless Microsoft 365 Groups are the ones that pile up until an expiration policy or an admin deals with them.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)