Guides · Offboarding

Microsoft 365 Offboarding: How to Find and Remove Stale Shared Mailbox Access

Offboarding is not complete until shared mailbox delegation is verified. Here is how to find what a departed user still has.

Sep 2026 · 6 min read

Offboarding removes the user, not always their delegation

Disabling or deleting a user account does not automatically clean up the shared mailbox grants they held. A disabled account can still be listed with Full Access; a deleted account can leave an unresolved SID behind (seedeleted users and orphaned Send As). This guide is about delegation only, not mailbox retention, legal hold or eDiscovery.

What to check after a user leaves

Finding it manually

List each trustee, then check whether the account still exists and is enabled. This example assumes an on-premises or hybrid directory with the ActiveDirectory module:

$perms = Get-MailboxPermission -Identity [email protected] |
  Where-Object { $_.AccessRights -contains 'FullAccess' -and -not $_.IsInherited -and $_.User -ne 'NT AUTHORITY\SELF' }

foreach ($p in $perms) {
  $sam = ($p.User -split '\\')[-1]
  $u = Get-ADUser -Filter "SamAccountName -eq '$sam'" -Properties Enabled -ErrorAction SilentlyContinue
  if (-not $u)             { "$($p.User): account not found" }
  elseif (-not $u.Enabled) { "$($p.User): account disabled" }
}

Repeat for Send As (Get-RecipientPermission) and Send on Behalf (GrantSendOnBehalfTo), then repeat per mailbox, and again next month.

Why a one-time cleanup isn't enough

The cleanup is correct only until the next departure. If group membership is the intended source of truth, offboarding should be part of the same loop as onboarding: the user leaves the group, the managed grants are removed, and anything granted outside the group shows up as drift. Seethe offboarding reconciliation model.

Where Tenvero fits

Tenvero turns shared-mailbox delegation from a one-time permission change into an auditable desired state that can be checked and reconciled continuously. Its audit surfaces disabled delegates, orphaned trustees and unmanaged direct access, and reconciliation removes only the permissions Tenvero owns. It does not manage mailbox retention or compliance.

See who still has access after a user leaves

Audit stale and orphaned delegation, then keep group and Exchange aligned.

Start 30-day trial