Microsoft 365

Convert a user mailbox to a shared mailbox and remove the license safely

Keep a leaver's email and calendar in Exchange Online without paying for a license: secure the account, convert the mailbox, grant access, then remove the license in the right order.

11 min read
On this page

To keep a leaver's mailbox without paying for a license, convert the user mailbox to a shared mailbox while it is still licensed, confirm the conversion, and only then remove the license. An unlicensed shared mailbox in Exchange Online holds up to 50 GB and keeps all existing email, calendar items and inbox rules. Never delete the user account: it anchors the shared mailbox, so block its sign-in instead.

Who this is for and what you will have at the end

This guide is for Microsoft 365 and Exchange Online administrators who handle leavers and want to keep the mailbox available to a manager or a team without keeping a paid license on it. It also covers the case where someone already removed the license or deleted the account before converting.

At the end you will have a secured account that can't sign in, a shared mailbox with the leaver's full mailbox content, the right people with access to it, the license removed, and a short set of PowerShell checks that prove each step worked. If the mailbox is in an Exchange hybrid deployment, you will also know the extra on-premises step that stops the mailbox from being reverted later.

How the conversion works

Converting changes the mailbox type, not its content. Everything the user had stays in place; only the access model changes from one person to several delegates.

FactDetail
License before convertingThe mailbox must be licensed, otherwise the convert option isn't shown
License after convertingCan be removed if the mailbox is under 50 GB
Size limit without a license50 GB; Exchange Online Plan 2 raises it to 100 GB
Archive and holdsLitigation Hold or In-Place Hold on a shared mailbox needs Exchange Online Plan 2, or Plan 1 with the Exchange Online Archiving add-on
User accountMust stay; it anchors the shared mailbox
PasswordIf you don't reset it, the original credentials keep working on the shared mailbox
Inbox rulesPreserved after conversion
Who can open itOnly people in your organization who have their own licensed Exchange Online mailbox

Two of these facts decide the order of the procedure. The first is the size limit: when an unlicensed shared mailbox reaches 50 GB it can still receive mail for a while but can't send, and later senders get a non-delivery report. The second is the order of operations: an unlicensed regular user mailbox without a hold can be disconnected, which is exactly what happens if the license is removed before the type change has really taken effect.

Prerequisites

  • An account with a role that can manage users and licenses (for example User Administrator or License Administrator) and Exchange recipient management permissions.
  • The Exchange Online PowerShell module and the Microsoft Graph PowerShell SDK, if you want to script the steps.
  • The leaver's mailbox still licensed. If the account was already deleted, see the troubleshooting section before you start.
  • In a hybrid deployment, access to the on-premises Exchange Management Shell.

Connect to both services:

Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
Connect-Graph -Scopes User.ReadWrite.All, Organization.Read.All

The first scope lets you change license assignments; the second is required to read the licenses available in the tenant.

Step 1: Secure the account before anything else

Microsoft's leaver guidance starts with access, not data. Do this first so the person can't read or send mail while you work.

  1. In the Microsoft 365 admin center, go to Users > Active users, select the user and choose Reset password.
  2. Select the user again and, on the Account tab, choose Sign out of all sessions.
  3. Choose Block sign-in, select Block this user from signing in and save.

Blocking sign-in can take up to 24 hours to take effect, which is why the password reset comes first. Signing out of sessions isn't instant either: access tokens are valid for an hour, and Outlook on the web may keep working until the user refreshes or opens another app. To revoke refresh tokens and browser sessions from PowerShell:

Revoke-MgUserSignInSession -UserId "leaver@contoso.com"

Session revocation and Continuous Access Evaluation are covered in more depth in the zero-trust remote access architecture guide. Keep sign-in blocked permanently. Microsoft's guidance for shared mailboxes is that the associated account isn't meant for direct sign-in and should always stay blocked.

Step 2: Check size, archive and holds

Find out whether the mailbox fits in 50 GB and whether a hold applies before you plan to remove the license.

Get-EXOMailboxStatistics -Identity leaver@contoso.com
Get-EXOMailboxStatistics -Identity leaver@contoso.com -Archive
 
Get-Mailbox -Identity leaver@contoso.com | Format-List LitigationHoldEnabled,InPlaceHolds,ComplianceTagHoldApplied
Get-OrganizationConfig | Format-List InPlaceHolds

Read the results like this:

  • TotalItemSize over 50 GB: either clean up large items first or plan to keep an Exchange Online Plan 2 license on the shared mailbox.
  • LitigationHoldEnabled is True, or InPlaceHolds contains values: the mailbox is under a hold or retention policy. A shared mailbox on Litigation Hold needs Exchange Online Plan 2, or Plan 1 with Exchange Online Archiving, so check with whoever owns compliance before removing the license.
  • An empty InPlaceHolds on the mailbox doesn't rule out organization-wide retention policies, which is why the second command reads them from the organization configuration.

Step 3: Cancel the leaver's future meetings

Meetings the leaver organized stay on attendees' calendars and keep rooms booked until they are cancelled. Remove-CalendarEvents cancels future meetings where the mailbox is the organizer and there is at least one attendee or resource. Because cancellations have to be sent, the mailbox must still be able to send mail, so do this before removing the license.

Preview first, then cancel:

Remove-CalendarEvents -Identity leaver@contoso.com -CancelOrganizedMeetings -QueryWindowInDays 365 -PreviewOnly -Verbose
 
Remove-CalendarEvents -Identity leaver@contoso.com -CancelOrganizedMeetings -QueryWindowInDays 365

If a recurring meeting has an instance in the window, the whole series is cancelled. The maximum window is 1,825 days. The preview output always says meetings are queued for cancellation, but with -PreviewOnly nothing is actually cancelled.

Step 4: Convert the mailbox

You can use any of three tools; the result is the same.

Microsoft 365 admin center. Go to Users > Active users, select the user, open the Mail tab, select Convert to shared mailbox and then Convert.

Exchange admin center. Go to Recipients > Mailboxes, select the mailbox, choose Convert to shared mailbox in the More actions pane and select Confirm. The message "Mailbox converted successfully" confirms the change.

Exchange Online PowerShell.

Set-Mailbox -Identity leaver@contoso.com -Type Shared

Then confirm the type before going further:

Get-Mailbox -Identity leaver@contoso.com | Format-List RecipientTypeDetails

The value must be SharedMailbox. Don't touch the license until it is.

Step 5: Grant access to the people who need it

A shared mailbox is only useful if someone can open it. The three permissions are separate:

Add-MailboxPermission -Identity leaver@contoso.com -User manager@contoso.com -AccessRights FullAccess -InheritanceType All
Add-RecipientPermission -Identity leaver@contoso.com -Trustee manager@contoso.com -AccessRights SendAs -Confirm:$false

Full Access lets the delegate open the mailbox; Send As lets them reply as the leaver's address. Full Access granted to an individual automatically adds the mailbox to that person's Outlook profile; granted through a group it doesn't. The differences between Full Access, Send As and Send on Behalf, including how to audit them, are covered in Full Access, Send As and Send on Behalf in Exchange Online.

If the leaver shared their calendar with colleagues or had delegates, those folder permissions stay with the mailbox. To review or change them, see Calendar permissions in Exchange Online.

Step 6: Remove the license

With the type confirmed as SharedMailbox and the size under 50 GB, remove the license.

Admin center: go to Users > Active users, select the user, select Licenses and Apps in the right pane, expand Licenses, clear the license boxes and select Save changes.

Microsoft Graph PowerShell: look up the SKU, then remove it.

Get-MgUserLicenseDetail -UserId leaver@contoso.com | Select-Object SkuPartNumber, SkuId
 
$sku = Get-MgSubscribedSku -All | Where-Object SkuPartNumber -eq 'SPE_E5'
Set-MgUserLicense -UserId leaver@contoso.com -RemoveLicenses @($sku.SkuId) -AddLicenses @{}

Replace SPE_E5 with the part number shown by the first command.

Group-based licensing. If the license comes from a group, remove the user from that licensed group instead; a user removed from a licensed group is unlicensed once group-based licensing processes the change. The group assignments are visible on the Billing > Licenses page in the Microsoft 365 admin center.

The order matters because of what happens to a regular mailbox: when a license is removed from a user mailbox, its Exchange Online data is held for 30 days and then deleted. A confirmed shared mailbox doesn't depend on a license, so removing it is safe only after the type change.

Don't delete the account afterwards. It is the anchor the shared mailbox depends on; if it is deleted, you have to restore the user and follow the deleted-user procedure in the troubleshooting table.

Hybrid deployments: convert on-premises too

In an Exchange hybrid deployment the mailbox object is managed from on-premises, and synchronization runs from on-premises to Exchange Online. If you convert only in Exchange Online, the on-premises remote mailbox still says "regular". Exchange Online can later revert the shared mailbox to a regular mailbox and, because it is unlicensed and has no hold, disconnect it.

For a mailbox that was migrated to Exchange Online, set the type in both places:

# On-premises Exchange Management Shell
Set-RemoteMailbox -Identity leaver@contoso.com -Type Shared
# Exchange Online PowerShell
Set-Mailbox -Identity leaver@contoso.com -Type Shared

If this has already happened, Microsoft's fix is: temporarily assign a license to reconnect the mailbox, run both commands above, then remove the temporary license. This must be done within 30 days of the disconnection; after that, assigning a license provisions a new, empty mailbox instead. License timing matters in migrations for the same reason; the tenant-to-tenant migration architecture guide explains why an Exchange Online license assigned at the wrong moment provisions a new, empty mailbox.

Verify the result

Run these checks after the license change has been processed:

Get-Mailbox -Identity leaver@contoso.com | Format-List RecipientTypeDetails
Get-EXOMailboxStatistics -Identity leaver@contoso.com
Get-MailboxPermission -Identity leaver@contoso.com | Where-Object {$_.AccessRights -like 'Full*'} | Format-Table User,Deny,IsInherited,AccessRights -AutoSize
Get-RecipientPermission -Identity leaver@contoso.com
Get-MgUserLicenseDetail -UserId leaver@contoso.com

You want SharedMailbox, a size under 50 GB, the expected delegates, and no license details. Then sign in to Outlook on the web as one of the delegates, open the shared mailbox and send a test message from it.

To list every shared mailbox in the tenant, which is useful for a periodic review of leaver mailboxes:

Get-Mailbox -RecipientTypeDetails SharedMailbox -ResultSize Unlimited | Format-Table DisplayName,PrimarySmtpAddress

Troubleshooting

ProblemCauseFix
Convert to shared mailbox doesn't appearThe mailbox has no licenseAssign a license, convert, then remove it
The account was already deletedThe anchor is goneRestore the user, make sure a license is assigned, reset the password, wait up to 24 hours for the mailbox to be re-created, confirm it is a shared mailbox (convert it if it isn't), remove the license, then add members
Shared mailbox can't send and senders get NDRsIt reached the 50 GB limit without a licenseDelete large items or assign Exchange Online Plan 2
Shared mailbox turned back into a user mailbox weeks laterHybrid: the on-premises remote mailbox is still regularRun Set-RemoteMailbox -Type Shared on-premises and Set-Mailbox -Type Shared in Exchange Online
"You do not have the permission to send the message on behalf of the specified user"Replication latency after the change, or the delegate has Full Access but not Send AsWait about an hour; if it persists, grant Send As
Conversion or forwarding has no effectThe mailbox is inactive because of a compliance holdWork with the compliance owner; Microsoft notes conversion doesn't work for inactive mailboxes

Converting back

If the person returns, or the mailbox needs to become a personal mailbox for someone else, go to the Exchange admin center, Recipients > Mailboxes, select the shared mailbox and, on the Others tab, choose Convert to regular mailbox, then Confirm. In the Microsoft 365 admin center, assign a license to the account and reset the password. After a few minutes the mailbox is ready, with the email and calendar items it held as a shared mailbox.

Summary checklist

  • Reset the password, sign out all sessions and block sign-in.
  • Check mailbox size, archive and holds.
  • Cancel future meetings while the mailbox can still send.
  • Convert with the admin center, the EAC or Set-Mailbox -Type Shared.
  • In hybrid, also run Set-RemoteMailbox -Type Shared on-premises.
  • Confirm RecipientTypeDetails is SharedMailbox.
  • Grant Full Access and, if needed, Send As.
  • Remove the license (or the group membership that grants it).
  • Keep the user account; never delete it.

References

Questions people ask

Do I need a license to convert a user mailbox to a shared mailbox?

Yes. Microsoft states that the user mailbox needs a license assigned before you convert it, otherwise the convert option doesn't appear. If you already removed the license, add it back, convert the mailbox, and then remove the license again.

Can I delete the user account after converting the mailbox?

No. Microsoft states that the account is required to anchor the shared mailbox. Keep the account, block its sign-in, and only remove the license once the mailbox shows as a shared mailbox. If the account was already deleted, restore it and follow the deleted-user procedure.

What happens if the shared mailbox is larger than 50 GB?

An unlicensed shared mailbox is limited to 50 GB. If the converted mailbox is larger, either delete large items to bring it under the limit or keep an Exchange Online Plan 2 license on it, which raises the limit to 100 GB.

Will the leaver's old password still open the shared mailbox?

It can. Microsoft notes that if you don't reset the password, the original username and password continue to work on the shared mailbox after conversion. Reset the password and block sign-in for the account as part of the leaver process.

Exchange OnlineShared mailboxMicrosoft 365 licensingExchange Online PowerShell
  1. Calendar permissions in Exchange Online: Add-MailboxFolderPermission guide

    Share calendars, change the organization-wide Default permission and add calendar delegates in Exchange Online with Add-, Set- and Remove-MailboxFolderPermission, including localized folder names.

    Microsoft 3659 min read
  2. EWS retirement in Exchange Online: find EWS apps and set EWSAllowedAppIDs

    Find every app that still calls Exchange Web Services, build an EWSAllowedAppIDs allow list and set EWSEnabled so critical apps keep working while EWS is switched off from October 2026.

    Microsoft 36513 min read
  3. Exchange hybrid remote move migration: endpoints, batches and completion

    Move mailboxes from on-premises Exchange to Exchange Online with remote move migration: enable MRS Proxy, test the endpoint, build batches, schedule completion and clean up.

    Microsoft 36512 min read