Using mail enabled security groups for access to a shared mailbox

Bakker, Ron 0 Reputation points
2025-01-31T08:46:02.76+00:00

I've been searching for a solution, but until now couldn't find one.

We are using an Exchange 2019 environment which include users and shared mailboxes.

Due to the fact that we would like to use IAM software we would like to have access to a shared mailbox for users using mail enable security groups.

When we add a user directly to a shared mailbox, automapping is enabled and users can see the shared mailbox in their Outlook.

As soon as we only use mail enabled security groups, automapping isn't working and users have to add the mailbox manually to their Outlook profile.

The question is, is there a way that we can set automapping with security groups (what isn't working right now) or is there a possibility that we can use a script that can automatically add the shared mailbox to Outlook based on membership of a security group?

Microsoft 365 and Office | Install, redeem, activate | For business | Windows
Exchange | Other
Exchange | Other

A powerful email and collaboration platform developed by Microsoft, designed to support enterprise-level communication and productivity. Miscellaneous topics that do not fit into specific categories.


6 answers

Sort by: Most helpful
  1. Tenvero 0 Reputation points
    2026-09-24T19:43:55.6533333+00:00

    The practical way to make this work is to keep the security group as the source of truth, but reconcile its members to explicit Exchange permissions underneath.

    For each mailbox:

    1. Read the current members of the AD/mail-enabled security group.
    2. Compare them with the mailbox’s explicit Full Access / Send As / Send on Behalf permissions.
    3. Add missing user permissions.
    4. Remove explicit permissions for users who are no longer in the group.
    5. Grant Full Access with -AutoMapping:$true for users who should have Outlook automapping.

    That avoids relying on group-based Full Access alone, because Exchange can grant the access but Outlook AutoMapping does not work directly from a group permission. It also means the process has to be run as a reconciliation job, not just as a one-time provisioning script.

    Full disclosure: this is the model we’re implementing in Tenvero. The important part is the ongoing drift detection and cleanup, not just the initial permission assignment.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.