Shared Mailbox Offboarding: Remove Full Access and Send As When Users Leave an AD Group
If group membership is your source of truth, offboarding must be part of the same reconciliation loop as onboarding. This guide shows the model and where manual scripts usually fail.
Using an AD or Entra security group as the source of truth for shared mailbox access makes onboarding straightforward. Add the user to the group, reconcile permissions, and the user gets the required access.
The part that often gets missed is the reverse direction: what happens when the user leaves the group?
If your automation only adds missing permissions, stale access can remain in Exchange Online long after a role change. A production workflow needs two-way reconciliation.
The add-only script problem
Most basic scripts implement one condition:
User is in the group
AND
User does not have Exchange permission
-> Add permissionThat helps onboarding, but not offboarding.
You also need:
User has a managed Exchange permission
AND
User is no longer in the group
-> Remove managed permissionUse the group as desired state
AD / Entra security group
↓
Expected users
↓
Compare with Exchange permissions
↓
Add missing managed permissions
↓
Remove stale managed permissionsThe group represents who should have access. Exchange shows who currently has access. Reconciliation aligns the two.
Full Access and Send As removal examples
Full Access and Send As are separate permissions and require separate checks in any script-driven workflow.
Remove-MailboxPermission `
-Identity "[email protected]" `
-User "[email protected]" `
-AccessRights FullAccess `
-Confirm:$false
Remove-RecipientPermission `
-Identity "[email protected]" `
-Trustee "[email protected]" `
-AccessRights SendAs `
-Confirm:$falseRemoval should apply only to permissions owned by the configured reconciliation scope. Do not remove unrelated manual or administrative entries.
Audit checks that matter
- Disabled users with Full Access or Send As
- Delegates that no longer exist
- Group members missing expected permissions
- Exchange delegates outside the managed group
- Failed reconciliation runs
How Tenvero handles this
Tenvero keeps on-prem AD security groups as source of truth and reconciles to explicit Exchange permissions, including additions and managed removals. It also supports existing-access adoption so you can start from current delegation state instead of rebuilding first.
Read related guides: AutoMapping with AD security groups,PowerShell reconciliation architecture,shared mailbox permission audit, andwhat happens to Send As after a user is deleted.
Review architecture scope: Tenvero Security. MSP context:For MSPs.
Try the workflow on one shared mailbox, adopt existing access, and validate offboarding behavior before broader rollout.
Start 30-day trial