Guides · Offboarding

Shared Mailbox Offboarding: Remove Full Access and Send As When Users Leave an AD Group

If group membership is your source of truth, offboarding must be part of the same reconciliation loop as onboarding. This guide shows the model and where manual scripts usually fail.

Updated Aug 2026 · 8 min read

Using an AD or Entra security group as the source of truth for shared mailbox access makes onboarding straightforward. Add the user to the group, reconcile permissions, and the user gets the required access.

The part that often gets missed is the reverse direction: what happens when the user leaves the group?

If your automation only adds missing permissions, stale access can remain in Exchange Online long after a role change. A production workflow needs two-way reconciliation.

The add-only script problem

Most basic scripts implement one condition:

User is in the group
AND
User does not have Exchange permission
-> Add permission

That helps onboarding, but not offboarding.

You also need:

User has a managed Exchange permission
AND
User is no longer in the group
-> Remove managed permission

Use the group as desired state

AD / Entra security group
        ↓
Expected users
        ↓
Compare with Exchange permissions
        ↓
Add missing managed permissions
        ↓
Remove stale managed permissions

The group represents who should have access. Exchange shows who currently has access. Reconciliation aligns the two.

Full Access and Send As removal examples

Full Access and Send As are separate permissions and require separate checks in any script-driven workflow.

Remove-MailboxPermission `
  -Identity "[email protected]" `
  -User "[email protected]" `
  -AccessRights FullAccess `
  -Confirm:$false

Remove-RecipientPermission `
  -Identity "[email protected]" `
  -Trustee "[email protected]" `
  -AccessRights SendAs `
  -Confirm:$false

Removal should apply only to permissions owned by the configured reconciliation scope. Do not remove unrelated manual or administrative entries.

Audit checks that matter

How Tenvero handles this

Tenvero keeps on-prem AD security groups as source of truth and reconciles to explicit Exchange permissions, including additions and managed removals. It also supports existing-access adoption so you can start from current delegation state instead of rebuilding first.

Read related guides: AutoMapping with AD security groups,PowerShell reconciliation architecture,shared mailbox permission audit, andwhat happens to Send As after a user is deleted.

Review architecture scope: Tenvero Security. MSP context:For MSPs.

Start with one mailbox

Try the workflow on one shared mailbox, adopt existing access, and validate offboarding behavior before broader rollout.

Start 30-day trial