Tenvero 2.0.24 — now with real-time sync progress

Keep Microsoft 365 shared-mailbox access under control.

Define who should have access, compare it with what Exchange actually has, and detect permission drift before it becomes an admin problem. Your AD security groups stay the source of truth; Tenvero reconciles the explicit Exchange permissions — including the Full Access that Outlook AutoMapping needs.

  1. Desired stateAD / Entra group
  2. Actual stateExchange permissions
  3. DriftDirect, stale, orphaned
  4. ReconcileManaged changes only

Already have shared mailbox permissions configured? Tenvero can adopt your existing delegations so you can test it without rebuilding your setup.

No credit card required.

30-day trial
Existing-access adoption
Managed additions and removals
Certificate-based Exchange auth
Tenvero Manager — Overview dashboard

From permission changes to permission control

Before
  • Manual permission tickets
  • Scheduled PowerShell scripts
  • Unknown stale delegates
  • Group membership differs from Exchange state
  • Offboarding depends on somebody remembering
  • Existing mailbox access is hard to migrate safely
Tenvero
  • Group = desired state
  • Explicit per-user Exchange permissions
  • Managed additions and removals
  • Existing-access adoption
  • Delegation audit
  • Scheduled reconciliation
  • Visible reconciliation history
After
  • Add/remove users through the group
  • Exchange stays aligned
  • Explicit Full Access remains AutoMapping-aware
  • Stale managed permissions can be removed
  • Disabled or invalid delegates are visible
  • Less custom PowerShell to maintain
Start with one mailbox

Use the 30-day trial to adopt one existing shared mailbox, validate the workflow, and expand only when you're comfortable.

The automation engine

Shared mailbox permissions get messy fast

Direct user permissions work, but become difficult to audit and maintain across many shared mailboxes. Group-based administration is cleaner, but Outlook AutoMapping depends on explicit user assignment. Tenvero connects those two models.

Workflow

How Tenvero manages group-driven delegation

1

Choose the mailbox

Select the shared mailbox Tenvero should manage.

2

Map the security group

Keep your existing on-prem AD security group as the source of truth for who should have access.

3

Reconcile

Tenvero compares group membership with Exchange Online and maintains explicit user permissions.

4

Keep it clean

When users are added or removed from the group, Tenvero reconciles additions and managed removals.

01 · DELEGATION BINDING

AD security group → shared mailbox → AutoMapping

live
AD
Security group
On-prem source of truth
EXO
Shared mailbox
Full Access · Send As · Send on Behalf
OUTLOOK
AutoMapping
Mailbox appears automatically
Full Access
Send As
Send on Behalf
Product demo

See the whole workflow in 90 seconds

Connect the tenant, pick a shared mailbox, compare the intended group delegation with actual Exchange permissions, spot unexpected direct access and see the reconciliation result. Why install Tenvero instead of running another PowerShell command? Because it keeps showing and reconciling the desired state instead of an engineer rediscovering the problem by hand.

02 · SCHEDULED RECONCILIATION

AD stays authoritative; Exchange just follows

GRANT
▤
Scheduled
Plan created
▶
Running
In progress
✓
Healthy
All good
▤
Next run
Today, 02:00 AM
AD MEMBERSHIP CHANGE
Admin adds/removes a user from a mapped security group.
SCHEDULED RUN
"Tenvero Mailbox Sync" task runs on interval.
EXCHANGE ONLINE API
Certificate-based app-only session applies the delta.
GRANT / REVOKE APPLIED
Only Tenvero-owned permissions are touched.
03 · DELEGATION AUDIT

A read-only health scan across every mapping

exportable to CSV
45
FINDINGS
● 5● 12● 28

Review group membership and remove stale managed access in the next reconciliation run.

Confirm ownership state and clean up unresolved delegates that cannot map back to active directory users.

Fix or replace the mapped source-of-truth group before running managed permission changes.

Keep deliberate exceptions unmanaged, and adopt only the entries you want Tenvero to own.

Everything a hybrid mailbox admin needs

One console, one source of truth.

AD-driven delegation
Full Access, Send As and Send on Behalf mapped to on-prem security groups, not individual users.
Safe existing-access takeover
Import current direct delegates and adopt them into Tenvero ownership without removing access.
Delegation Audit
Read-only health scan for disabled accounts, orphaned trustees and unmanaged direct access, exportable to CSV.
Multi-domain SMTP
Primary and secondary addresses across every accepted domain, with AD/Entra hybrid source of authority.
Entra Connect sync
Local, remote or disabled delta-sync modes triggered directly from a reconciliation run.
Certificate-based auth
Unattended Exchange Online authentication for scheduled, unattended reconciliation.
Offboarding

When someone leaves the group, their mailbox access should leave too.

Tenvero reconciles both additions and removals. If a user is removed from the mapped on-prem AD group, Tenvero can remove the managed Exchange delegation as part of the next reconciliation.

That helps reduce stale Full Access, Send As and other delegation entries that can otherwise remain behind after role changes or offboarding.

Delegation Audit

Know who still has access — and whether they should.

Shared mailbox permissions accumulate over time. Role changes, disabled accounts, manual exceptions and incomplete offboarding can leave delegation behind long after it was intended. Delegation Audit helps surface that drift.

Disabled delegate

A disabled AD account still holds Full Access or Send As on a mailbox.

Orphaned trustee

A delegate on the mailbox no longer resolves to an Exchange recipient or an AD account.

Missing mapped group

The group mapped as source of truth is missing, deleted, or no longer security-enabled.

Unmanaged direct access

Full Access, Send As or Send on Behalf exists outside the mapped group entirely.

Audit is read-only. Not every finding is automatically remediated — reconciliation only changes Tenvero-owned permissions.

Common objection

Why not just script it?

You can absolutely build this workflow in PowerShell. The difficult part is not adding one permission. It is maintaining reconciliation, removals, scheduling, auditing, takeover of existing access and visibility into what changed.

Two-way reconciliation

Handle additions and managed removals instead of running an add-only script.

Existing-access adoption

Take over current shared mailbox delegations without rebuilding the mailbox before testing Tenvero.

Auditing

Identify stale, disabled or invalid delegation entries and permission drift.

Scheduling

Run reconciliation consistently without maintaining your own scheduled-script framework.

Visibility

See mappings, managed state, audit results and reconciliation outcomes in one place.

AutoMapping-aware

Use the security group as the source of truth while maintaining explicit Exchange permissions per user.

Ongoing control

Manage the whole delegation lifecycle

1

Adopt

Start from the permissions already in Exchange.

2

Map

Connect the shared mailbox to the intended on-prem AD security group.

3

Reconcile

Maintain explicit managed permissions as group membership changes.

4

Audit

Find stale, disabled or invalid delegation state.

Exchange changes

Exchange changes are a good reason to review your delegation state.

Microsoft begins blocking Exchange Web Services in Exchange Online on October 1, 2026, tenant by tenant, with an app allow-list for organizations that still need it during the transition. EWS migration is its own project — Tenvero does not migrate EWS integrations. But a change window is a natural moment to check who really has access to your shared mailboxes.

Audit shared mailbox delegation

Start small

You do not need to migrate your whole environment at once. Start with one existing shared mailbox, adopt its current access, and validate the reconciliation workflow before expanding.

Start your 30-day Professional trial

Full Professional feature set for your Microsoft 365 tenant.

Start 30-day trial