You grant someone Full Access to a shared mailbox and it appears in their Outlook a while later. Or it never appears. Or it turns up for an admin with access to dozens of mailboxes, and Outlook starts crawling. All of that comes down to automapping. In this post I'll explain how it works, why groups and new Outlook behave differently, how to control it per user, and how to fix the related "my replies aren't in the shared Sent Items" complaint.
How automapping works#
When you grant a user Full Access to a mailbox, Exchange Online also records that user against the mailbox for automapping. When classic Outlook for Windows runs Autodiscover, it reads that list (the msExchDelegateListBL attribute) and adds every mailbox on it to the user's profile. Nobody has to add anything by hand, which is why it's so convenient.
- It's on by default.
Add-MailboxPermissionuses-AutoMapping $trueunless you say otherwise, and granting Full Access in the admin centers behaves the same way. - It lives inside the user's profile. The mailbox is added to the user's own account, not as a separate account.
- The client can't really undo it. Because Autodiscover adds the mailbox, the fix for an unwanted one belongs on the permission, not in Outlook.
- It isn't instant. The user has to restart Outlook, and it can take a few hours after a permission change before the mailbox appears or disappears.
Why a mailbox doesn't automap#
| How Full Access was granted | Automaps in classic Outlook? |
|---|---|
| Directly to the user, default settings | Yes |
Directly to the user with -AutoMapping $false | No |
| To a mail-enabled security group the user belongs to | No |
The group case catches a lot of people out. Access itself works: members can add the mailbox manually or open it in Outlook on the web. But Autodiscover doesn't expand group membership, so nothing is mapped automatically. If you want automapping, grant Full Access to each user directly. Groups still have their place, because a mailbox can hold at most 500 permission entries and a group counts as one.
Turning automapping off for a user#
There's no switch on an existing permission. Instead you remove the Full Access entry and add it back with automapping disabled:
Connect-ExchangeOnline
Remove-MailboxPermission -Identity support@contoso.com -User adele@contoso.com -AccessRights FullAccess -Confirm:$false
Add-MailboxPermission -Identity support@contoso.com -User adele@contoso.com -AccessRights FullAccess -AutoMapping $falseRun both lines together so the user isn't left without access, and use -AutoMapping $true in the same pair to switch it back on later. To take a mailbox out of automapping for everyone who has Full Access, Exchange Online also offers:
Remove-MailboxPermission -Identity support@contoso.com -ClearAutoMappingThat leaves everyone's permissions intact. If a particular user still gets the mailbox mapped afterwards, use the remove-and-re-add method for that user.
Users who still want the mailbox can add it themselves. In classic Outlook, that's File › Account Settings › Account Settings › Change › More Settings › Advanced, then Add under Open these additional mailboxes.
Sent items: where do replies go?#
By default, a message sent as or on behalf of the shared mailbox is saved in the sender's own Sent Items, so colleagues can't see who replied to what. The fix is a server-side setting on the shared mailbox, and it's the only option that also applies to new Outlook:
Set-Mailbox -Identity support@contoso.com -MessageCopyForSentAsEnabled $true -MessageCopyForSendOnBehalfEnabled $true
Get-Mailbox -Identity support@contoso.com | Format-List MessageCopyForSentAsEnabled, MessageCopyForSendOnBehalfEnabledThe first parameter covers Send As and the second covers Send on Behalf; the sender keeps their own copy too. Don't combine this with the classic Outlook DelegateSentItemsStyle registry value: with both in place, Microsoft documents that Send As messages are saved twice in the shared mailbox.
New Outlook and Outlook on the web#
- New Outlook for Windows lists automapped mailboxes under Shared with me in the folder pane; if one doesn't show up, right-click the account name and use Add shared folder or mailbox. The gotcha: new mail in an automapped shared mailbox's Inbox isn't synced automatically. Users can select the folder or use Sync on the View tab, or go to Settings › Accounts › Shared with me, select the mailbox and choose Convert. As an account, it syncs automatically and supports notifications, rules and automatic replies.
- Outlook on the web users add a mailbox with Add shared folder or mailbox in the folder pane, or open it in its own tab with Open another mailbox from their profile picture. Both need only Full Access, so they also work when access comes from a group.
Verify#
Check who has access and whether it was granted directly:
Get-MailboxPermission -Identity support@contoso.com |
Where-Object { $_.User -notlike "NT AUTHORITY*" } |
Format-Table User, AccessRights, IsInheritedEach user who should automap needs their own FullAccess entry; a group entry means its members won't automap. The output doesn't show the automapping flag itself, so if you're unsure how an entry was created, remove and re-add it with the value you want. Then have the user restart classic Outlook, allow some time, and send a test as the shared mailbox to confirm the copy lands in its Sent Items.
Tips & gotchas#
- Give admin and helpdesk accounts Full Access with
-AutoMapping $false. Outlook opening many automapped mailboxes at start-up is a known cause of slow performance. - Full Access on its own doesn't let anyone send as the mailbox; they also need Send As or Send on Behalf.
- Pick one approach per user: avoid having the same mailbox automapped and also added as a separate account in one profile.
- When you remove someone's Full Access, the automapped mailbox disappears only after Autodiscover refreshes, so the restart-and-wait rule applies in both directions.