To keep a leaver's mailbox without paying for a license, convert the user mailbox to a shared mailbox while it is still licensed, confirm the conversion, and only then remove the license. An unlicensed shared mailbox in Exchange Online holds up to 50 GB and keeps all existing email, calendar items and inbox rules. Never delete the user account: it anchors the shared mailbox, so block its sign-in instead.
Who this is for and what you will have at the end
This guide is for Microsoft 365 and Exchange Online administrators who handle leavers and want to keep the mailbox available to a manager or a team without keeping a paid license on it. It also covers the case where someone already removed the license or deleted the account before converting.
At the end you will have a secured account that can't sign in, a shared mailbox with the leaver's full mailbox content, the right people with access to it, the license removed, and a short set of PowerShell checks that prove each step worked. If the mailbox is in an Exchange hybrid deployment, you will also know the extra on-premises step that stops the mailbox from being reverted later.
How the conversion works
Converting changes the mailbox type, not its content. Everything the user had stays in place; only the access model changes from one person to several delegates.
| Fact | Detail |
|---|---|
| License before converting | The mailbox must be licensed, otherwise the convert option isn't shown |
| License after converting | Can be removed if the mailbox is under 50 GB |
| Size limit without a license | 50 GB; Exchange Online Plan 2 raises it to 100 GB |
| Archive and holds | Litigation Hold or In-Place Hold on a shared mailbox needs Exchange Online Plan 2, or Plan 1 with the Exchange Online Archiving add-on |
| User account | Must stay; it anchors the shared mailbox |
| Password | If you don't reset it, the original credentials keep working on the shared mailbox |
| Inbox rules | Preserved after conversion |
| Who can open it | Only people in your organization who have their own licensed Exchange Online mailbox |
Two of these facts decide the order of the procedure. The first is the size limit: when an unlicensed shared mailbox reaches 50 GB it can still receive mail for a while but can't send, and later senders get a non-delivery report. The second is the order of operations: an unlicensed regular user mailbox without a hold can be disconnected, which is exactly what happens if the license is removed before the type change has really taken effect.
Prerequisites
- An account with a role that can manage users and licenses (for example User Administrator or License Administrator) and Exchange recipient management permissions.
- The Exchange Online PowerShell module and the Microsoft Graph PowerShell SDK, if you want to script the steps.
- The leaver's mailbox still licensed. If the account was already deleted, see the troubleshooting section before you start.
- In a hybrid deployment, access to the on-premises Exchange Management Shell.
Connect to both services:
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
Connect-Graph -Scopes User.ReadWrite.All, Organization.Read.AllThe first scope lets you change license assignments; the second is required to read the licenses available in the tenant.
Step 1: Secure the account before anything else
Microsoft's leaver guidance starts with access, not data. Do this first so the person can't read or send mail while you work.
- In the Microsoft 365 admin center, go to Users > Active users, select the user and choose Reset password.
- Select the user again and, on the Account tab, choose Sign out of all sessions.
- Choose Block sign-in, select Block this user from signing in and save.
Blocking sign-in can take up to 24 hours to take effect, which is why the password reset comes first. Signing out of sessions isn't instant either: access tokens are valid for an hour, and Outlook on the web may keep working until the user refreshes or opens another app. To revoke refresh tokens and browser sessions from PowerShell:
Revoke-MgUserSignInSession -UserId "leaver@contoso.com"Session revocation and Continuous Access Evaluation are covered in more depth in the zero-trust remote access architecture guide. Keep sign-in blocked permanently. Microsoft's guidance for shared mailboxes is that the associated account isn't meant for direct sign-in and should always stay blocked.
Step 2: Check size, archive and holds
Find out whether the mailbox fits in 50 GB and whether a hold applies before you plan to remove the license.
Get-EXOMailboxStatistics -Identity leaver@contoso.com
Get-EXOMailboxStatistics -Identity leaver@contoso.com -Archive
Get-Mailbox -Identity leaver@contoso.com | Format-List LitigationHoldEnabled,InPlaceHolds,ComplianceTagHoldApplied
Get-OrganizationConfig | Format-List InPlaceHoldsRead the results like this:
- TotalItemSize over 50 GB: either clean up large items first or plan to keep an Exchange Online Plan 2 license on the shared mailbox.
- LitigationHoldEnabled is True, or InPlaceHolds contains values: the mailbox is under a hold or retention policy. A shared mailbox on Litigation Hold needs Exchange Online Plan 2, or Plan 1 with Exchange Online Archiving, so check with whoever owns compliance before removing the license.
- An empty InPlaceHolds on the mailbox doesn't rule out organization-wide retention policies, which is why the second command reads them from the organization configuration.
Step 3: Cancel the leaver's future meetings
Meetings the leaver organized stay on attendees' calendars and keep rooms booked until they are cancelled. Remove-CalendarEvents cancels future meetings where the mailbox is the organizer and there is at least one attendee or resource. Because cancellations have to be sent, the mailbox must still be able to send mail, so do this before removing the license.
Preview first, then cancel:
Remove-CalendarEvents -Identity leaver@contoso.com -CancelOrganizedMeetings -QueryWindowInDays 365 -PreviewOnly -Verbose
Remove-CalendarEvents -Identity leaver@contoso.com -CancelOrganizedMeetings -QueryWindowInDays 365If a recurring meeting has an instance in the window, the whole series is cancelled. The maximum window is 1,825 days. The preview output always says meetings are queued for cancellation, but with -PreviewOnly nothing is actually cancelled.
Step 4: Convert the mailbox
You can use any of three tools; the result is the same.
Microsoft 365 admin center. Go to Users > Active users, select the user, open the Mail tab, select Convert to shared mailbox and then Convert.
Exchange admin center. Go to Recipients > Mailboxes, select the mailbox, choose Convert to shared mailbox in the More actions pane and select Confirm. The message "Mailbox converted successfully" confirms the change.
Exchange Online PowerShell.
Set-Mailbox -Identity leaver@contoso.com -Type SharedThen confirm the type before going further:
Get-Mailbox -Identity leaver@contoso.com | Format-List RecipientTypeDetailsThe value must be SharedMailbox. Don't touch the license until it is.
Step 5: Grant access to the people who need it
A shared mailbox is only useful if someone can open it. The three permissions are separate:
Add-MailboxPermission -Identity leaver@contoso.com -User manager@contoso.com -AccessRights FullAccess -InheritanceType All
Add-RecipientPermission -Identity leaver@contoso.com -Trustee manager@contoso.com -AccessRights SendAs -Confirm:$falseFull Access lets the delegate open the mailbox; Send As lets them reply as the leaver's address. Full Access granted to an individual automatically adds the mailbox to that person's Outlook profile; granted through a group it doesn't. The differences between Full Access, Send As and Send on Behalf, including how to audit them, are covered in Full Access, Send As and Send on Behalf in Exchange Online.
If the leaver shared their calendar with colleagues or had delegates, those folder permissions stay with the mailbox. To review or change them, see Calendar permissions in Exchange Online.
Step 6: Remove the license
With the type confirmed as SharedMailbox and the size under 50 GB, remove the license.
Admin center: go to Users > Active users, select the user, select Licenses and Apps in the right pane, expand Licenses, clear the license boxes and select Save changes.
Microsoft Graph PowerShell: look up the SKU, then remove it.
Get-MgUserLicenseDetail -UserId leaver@contoso.com | Select-Object SkuPartNumber, SkuId
$sku = Get-MgSubscribedSku -All | Where-Object SkuPartNumber -eq 'SPE_E5'
Set-MgUserLicense -UserId leaver@contoso.com -RemoveLicenses @($sku.SkuId) -AddLicenses @{}Replace SPE_E5 with the part number shown by the first command.
Group-based licensing. If the license comes from a group, remove the user from that licensed group instead; a user removed from a licensed group is unlicensed once group-based licensing processes the change. The group assignments are visible on the Billing > Licenses page in the Microsoft 365 admin center.
The order matters because of what happens to a regular mailbox: when a license is removed from a user mailbox, its Exchange Online data is held for 30 days and then deleted. A confirmed shared mailbox doesn't depend on a license, so removing it is safe only after the type change.
Don't delete the account afterwards. It is the anchor the shared mailbox depends on; if it is deleted, you have to restore the user and follow the deleted-user procedure in the troubleshooting table.
Hybrid deployments: convert on-premises too
In an Exchange hybrid deployment the mailbox object is managed from on-premises, and synchronization runs from on-premises to Exchange Online. If you convert only in Exchange Online, the on-premises remote mailbox still says "regular". Exchange Online can later revert the shared mailbox to a regular mailbox and, because it is unlicensed and has no hold, disconnect it.
For a mailbox that was migrated to Exchange Online, set the type in both places:
# On-premises Exchange Management Shell
Set-RemoteMailbox -Identity leaver@contoso.com -Type Shared# Exchange Online PowerShell
Set-Mailbox -Identity leaver@contoso.com -Type SharedIf this has already happened, Microsoft's fix is: temporarily assign a license to reconnect the mailbox, run both commands above, then remove the temporary license. This must be done within 30 days of the disconnection; after that, assigning a license provisions a new, empty mailbox instead. License timing matters in migrations for the same reason; the tenant-to-tenant migration architecture guide explains why an Exchange Online license assigned at the wrong moment provisions a new, empty mailbox.
Verify the result
Run these checks after the license change has been processed:
Get-Mailbox -Identity leaver@contoso.com | Format-List RecipientTypeDetails
Get-EXOMailboxStatistics -Identity leaver@contoso.com
Get-MailboxPermission -Identity leaver@contoso.com | Where-Object {$_.AccessRights -like 'Full*'} | Format-Table User,Deny,IsInherited,AccessRights -AutoSize
Get-RecipientPermission -Identity leaver@contoso.com
Get-MgUserLicenseDetail -UserId leaver@contoso.comYou want SharedMailbox, a size under 50 GB, the expected delegates, and no license details. Then sign in to Outlook on the web as one of the delegates, open the shared mailbox and send a test message from it.
To list every shared mailbox in the tenant, which is useful for a periodic review of leaver mailboxes:
Get-Mailbox -RecipientTypeDetails SharedMailbox -ResultSize Unlimited | Format-Table DisplayName,PrimarySmtpAddressTroubleshooting
| Problem | Cause | Fix |
|---|---|---|
| Convert to shared mailbox doesn't appear | The mailbox has no license | Assign a license, convert, then remove it |
| The account was already deleted | The anchor is gone | Restore the user, make sure a license is assigned, reset the password, wait up to 24 hours for the mailbox to be re-created, confirm it is a shared mailbox (convert it if it isn't), remove the license, then add members |
| Shared mailbox can't send and senders get NDRs | It reached the 50 GB limit without a license | Delete large items or assign Exchange Online Plan 2 |
| Shared mailbox turned back into a user mailbox weeks later | Hybrid: the on-premises remote mailbox is still regular | Run Set-RemoteMailbox -Type Shared on-premises and Set-Mailbox -Type Shared in Exchange Online |
| "You do not have the permission to send the message on behalf of the specified user" | Replication latency after the change, or the delegate has Full Access but not Send As | Wait about an hour; if it persists, grant Send As |
| Conversion or forwarding has no effect | The mailbox is inactive because of a compliance hold | Work with the compliance owner; Microsoft notes conversion doesn't work for inactive mailboxes |
Converting back
If the person returns, or the mailbox needs to become a personal mailbox for someone else, go to the Exchange admin center, Recipients > Mailboxes, select the shared mailbox and, on the Others tab, choose Convert to regular mailbox, then Confirm. In the Microsoft 365 admin center, assign a license to the account and reset the password. After a few minutes the mailbox is ready, with the email and calendar items it held as a shared mailbox.
Summary checklist
- Reset the password, sign out all sessions and block sign-in.
- Check mailbox size, archive and holds.
- Cancel future meetings while the mailbox can still send.
- Convert with the admin center, the EAC or
Set-Mailbox -Type Shared. - In hybrid, also run
Set-RemoteMailbox -Type Sharedon-premises. - Confirm
RecipientTypeDetailsisSharedMailbox. - Grant Full Access and, if needed, Send As.
- Remove the license (or the group membership that grants it).
- Keep the user account; never delete it.
References
- Convert a user mailbox to a shared mailbox
- About shared mailboxes in Microsoft 365
- Convert a mailbox in Exchange Online
- Remove a former employee: overview
- Step 1: Prevent user sign-in and block access to Microsoft 365
- Step 4: Forward a former employee's email or convert to a shared mailbox
- Shared mailbox in Exchange Online is unexpectedly disconnected
- Remove Microsoft 365 licenses from user accounts with PowerShell
- Assign or unassign licenses to a group in the Microsoft 365 admin center
- How to identify the hold on an Exchange Online mailbox
- Set-Mailbox
- Get-Mailbox
- Get-EXOMailboxStatistics
- Remove-CalendarEvents
- Revoke-MgUserSignInSession
- Connect to Exchange Online PowerShell