Microsoft 365 Offboarding: How to Find and Remove Stale Shared Mailbox Access
Offboarding is not complete until shared mailbox delegation is verified. Here is how to find what a departed user still has.
Offboarding removes the user, not always their delegation
Disabling or deleting a user account does not automatically clean up the shared mailbox grants they held. A disabled account can still be listed with Full Access; a deleted account can leave an unresolved SID behind (seedeleted users and orphaned Send As). This guide is about delegation only, not mailbox retention, legal hold or eDiscovery.
What to check after a user leaves
- Stale Full Access held by a disabled or removed account.
- Stale Send As, separate from Full Access and easy to forget.
- Stale Send on Behalf entries on the mailbox.
- Direct grants that should have come from a group, so removing the user from the group removed nothing.
- Ownership and review dates: who confirms the mailbox's access is still correct.
Finding it manually
List each trustee, then check whether the account still exists and is enabled. This example assumes an on-premises or hybrid directory with the ActiveDirectory module:
$perms = Get-MailboxPermission -Identity [email protected] |
Where-Object { $_.AccessRights -contains 'FullAccess' -and -not $_.IsInherited -and $_.User -ne 'NT AUTHORITY\SELF' }
foreach ($p in $perms) {
$sam = ($p.User -split '\\')[-1]
$u = Get-ADUser -Filter "SamAccountName -eq '$sam'" -Properties Enabled -ErrorAction SilentlyContinue
if (-not $u) { "$($p.User): account not found" }
elseif (-not $u.Enabled) { "$($p.User): account disabled" }
}Repeat for Send As (Get-RecipientPermission) and Send on Behalf (GrantSendOnBehalfTo), then repeat per mailbox, and again next month.
Why a one-time cleanup isn't enough
The cleanup is correct only until the next departure. If group membership is the intended source of truth, offboarding should be part of the same loop as onboarding: the user leaves the group, the managed grants are removed, and anything granted outside the group shows up as drift. Seethe offboarding reconciliation model.
Where Tenvero fits
Tenvero turns shared-mailbox delegation from a one-time permission change into an auditable desired state that can be checked and reconciled continuously. Its audit surfaces disabled delegates, orphaned trustees and unmanaged direct access, and reconciliation removes only the permissions Tenvero owns. It does not manage mailbox retention or compliance.
Audit stale and orphaned delegation, then keep group and Exchange aligned.
Start 30-day trial