"Can you make us a group for the project?" is one of the most common requests an Exchange admin gets, and the right answer depends on what the team actually wants: an address that fans mail out, a shared inbox someone has to answer from, or a workspace with files and a Teams channel. In this post I'll compare distribution groups, dynamic distribution groups, Microsoft 365 Groups and shared mailboxes feature by feature, explain when each is the right pick, show how to upgrade a distribution list and how to answer the recurring questions about send-as, moderation and hiding from the address book.
How it works: what each object really is#
| Capability | Distribution group | Dynamic distribution group | Microsoft 365 Group | Shared mailbox |
|---|---|---|---|---|
| Email to all members | Yes | Yes (membership from a recipient filter) | Yes, and a copy is kept in the group mailbox | Mail lands in one mailbox that members open |
| Shared calendar | No | No | Yes | Yes |
| Files, Planner, OneNote, Teams | No (members can be added to a team, not the group) | No | SharePoint site, Planner, notebook; can be connected to Teams or Viva Engage | No |
| Membership management | Owners (ManagedBy), join/leave restrictions | Attribute rules, refreshed at least every 24 hours | Owners and members, guests allowed if enabled | Permissions, not membership |
| Dynamic membership | No | Exchange recipient filter | Microsoft Entra dynamic membership rules | No |
| External senders | If allowed | If allowed | If allowed | If allowed |
| Send as / send on behalf | Yes, with permission | Yes, with permission | Yes, if enabled by an admin | Yes, with permission |
| Storage | None | None | Group mailbox 50 GB; files 1 TB plus 10 GB per licensed user | 50 GB free; 100 GB with Exchange Online Plan 2 or Plan 1 plus Exchange Online Archiving |
A distribution group is a pure fan-out: nothing is stored, every member gets their own copy, and it's the lightest object for "everyone in Building A". A dynamic distribution group is the same thing with membership computed from attributes such as Department or CustomAttribute1-15. In Exchange Online the member list is calculated when you create or change the rules and refreshed at least once every 24 hours, so a user who changes department can keep receiving (or miss) mail until the next refresh; since late May 2026 groups with 5,000 or fewer matching members populate immediately, larger ones within about two hours. Dynamic groups aren't synced to Microsoft Entra ID, so you can't use them in Conditional Access. A Microsoft 365 Group is a membership object in Entra ID with a mailbox, calendar, SharePoint site and Planner attached; Teams is built on it. A shared mailbox is just a mailbox without its own sign-in that several people open with Full Access, and it's the right answer when someone must answer from the address. Note that you can't convert a shared mailbox into a Microsoft 365 Group; the migration path only exists for distribution lists.
Licensing: any plan that includes Exchange Online and SharePoint supports Microsoft 365 Groups (Business Basic upwards); Exchange-only plans get the shared inbox and calendar but no site or Planner. Shared mailboxes need no licence until you need more than 50 GB, an archive or a hold.
Step 1: Pick the right object#
- Broadcast list, nobody replies "as" the list: distribution group. Use a dynamic group if the audience is defined by an attribute you keep accurate.
- A team working on something together: Microsoft 365 Group, usually created from Teams. Members get conversations, files and a calendar in one place, and the history stays when people leave.
- A functional address such as support@ or invoices@: shared mailbox. Replies go out as the mailbox, the Sent Items can be kept in it, and categories or folders can be used to track work.
- Permissions on SharePoint or apps plus occasional email: mail-enabled security group, which can't be dynamic and can't contain devices.
Step 2: Upgrade a distribution list to a Microsoft 365 Group#
In the Exchange admin center open Recipients › Groups, select the distribution list and choose Upgrade distribution group; the change is permanent. In PowerShell:
Connect-ExchangeOnline
Upgrade-DistributionGroup -DlIdentities hr@contoso.com,finance@contoso.comOnly cloud-managed, simple, non-nested distribution lists qualify. Microsoft's list of blockers: the list is nested (has child groups or is a member of another group); it's managed on-premises; it has more than 100 owners, or members but no owner, or no members; a member isn't a UserMailbox, SharedMailbox, TeamMailbox or MailUser; it's the forwarding address of a shared mailbox; it's used in another list's sender restrictions; its alias contains special characters; it's a mail-enabled security group, a dynamic group, or was converted to a room list. A custom email address policy created with IncludeUnifiedGroupRecipients also makes the cmdlet fail; remove it first and recreate it afterwards.
Step 3: Dynamic distribution groups done right#
# Pre-canned filter (AND between conditions)
New-DynamicDistributionGroup -Name "Sales - all staff" -IncludedRecipients MailboxUsers -ConditionalDepartment "Sales"
# Custom filter (PowerShell only; no leading wildcards)
New-DynamicDistributionGroup -Name "Full-time employees" `
-RecipientFilter "(RecipientTypeDetails -eq 'UserMailbox') -and (CustomAttribute10 -eq 'FullTimeEmployee')"
# Preview who the filter matches right now, then view the stored member list
$ddg = Get-DynamicDistributionGroup -Identity "Full-time employees"
Get-Recipient -RecipientPreviewFilter $ddg.RecipientFilter -ResultSize 100
Get-DynamicDistributionGroupMember -Identity "Full-time employees"Attribute values must match exactly (they aren't case-sensitive), and the admin center can only build the pre-canned filters.
Common questions#
- Send as or send on behalf. Send As is a recipient permission on all four object types:
Add-RecipientPermission -Identity support@contoso.com -Trustee adele@contoso.com -AccessRights SendAs. Send on behalf is a property:Set-DistributionGroup,Set-UnifiedGrouporSet-Mailboxwith-GrantSendOnBehalfTo. For shared mailboxes addSet-Mailbox -MessageCopyForSentAsEnabled $trueso replies stay in the shared Sent Items. - External senders. All four reject internet mail by default.
Set-DistributionGroup,Set-DynamicDistributionGrouporSet-UnifiedGroup -RequireSenderAuthenticationEnabled $falseopens them up; for a shared mailbox it's the same parameter onSet-Mailbox. - Moderation.
Set-DistributionGroup -ModerationEnabled $true -ModeratedBy "megan@contoso.com", optionally with-BypassModerationFromSendersOrMembersand-SendModerationNotifications. The same parameters exist on dynamic groups and Microsoft 365 Groups. - Hiding from the GAL.
-HiddenFromAddressListsEnabled $trueon any of them; a hidden object still receives mail if someone types the address. Teams-created groups are also hidden from Outlook byHiddenFromExchangeClientsEnabled, which you can flip withSet-UnifiedGroupif the team wants its group mailbox visible. - Who can join a distribution list.
MemberJoinRestriction(Open,Closed,ApprovalRequired) andMemberDepartRestriction(Open,Closed) onSet-DistributionGroup.
Verify#
Get-DistributionGroup -ResultSize Unlimited |
Format-Table Name, RecipientTypeDetails, RequireSenderAuthenticationEnabled, ModerationEnabled, HiddenFromAddressListsEnabled
Get-UnifiedGroup -Identity "Project Falcon" | Format-List AccessType, RequireSenderAuthenticationEnabled, HiddenFromExchangeClientsEnabled, SharePointSiteUrl
Get-UnifiedGroupLinks -Identity "Project Falcon" -LinkType Members
Get-Mailbox -RecipientTypeDetails SharedMailbox -ResultSize Unlimited | Format-Table Name, PrimarySmtpAddress, ProhibitSendReceiveQuota
Get-RecipientPermission -Identity support@contoso.com | Format-Table Trustee, AccessRightsSend one test message to each object from an external account and one from inside; the external one should bounce unless you opened the group, and the internal one should appear in the group mailbox (Microsoft 365 Group) or the shared Inbox.
Tips & gotchas#
- A Microsoft 365 Group can't be a member of a distribution group or a security group; adding a distribution group to a team copies its members rather than linking the group.
- Deleting a cloud distribution list is final, while a deleted Microsoft 365 Group can be restored for 30 days; export the member list before you remove a list.
- A dynamic group that's empty right after creation isn't broken if it has more than 5,000 matches: give the background calculation up to two hours, and use
Get-Recipient -RecipientPreviewFilterin the meantime. - Block sign-in on the account behind every shared mailbox; nobody should authenticate as it.
- Owners matter: a list with members and no owner can't be upgraded, and ownerless Microsoft 365 Groups are the ones that pile up until an expiration policy or an admin deals with them.