Processes in Microsoft 365 for setting up Office apps, redeeming product keys, and activating licenses.
The practical way to make this work is to keep the security group as the source of truth, but reconcile its members to explicit Exchange permissions underneath.
For each mailbox:
- Read the current members of the AD/mail-enabled security group.
- Compare them with the mailbox’s explicit Full Access / Send As / Send on Behalf permissions.
- Add missing user permissions.
- Remove explicit permissions for users who are no longer in the group.
- Grant Full Access with
-AutoMapping:$truefor users who should have Outlook automapping.
That avoids relying on group-based Full Access alone, because Exchange can grant the access but Outlook AutoMapping does not work directly from a group permission. It also means the process has to be run as a reconciliation job, not just as a one-time provisioning script.
Full disclosure: this is the model we’re implementing in Tenvero. The important part is the ongoing drift detection and cleanup, not just the initial permission assignment.