Microsoft 365

Full Access, Send As and Send on Behalf in Exchange Online with PowerShell

Grant, remove and audit the three mailbox delegation permissions in Exchange Online with PowerShell, control Outlook automapping, and fix the errors delegates hit most often.

9 min read
On this page

Exchange Online has three separate mailbox delegation permissions: Full Access opens the mailbox, Send As sends mail that appears to come from it, and Send on Behalf sends mail marked "Delegate on behalf of Mailbox". You grant Full Access with Add-MailboxPermission, Send As with Add-RecipientPermission, and Send on Behalf with Set-Mailbox -GrantSendOnBehalfTo. Each is audited with its own command, so a complete review always checks all three.

Who this is for and what you will have at the end

This guide is for Exchange Online administrators who handle requests such as "give the assistant access to the manager's mailbox", "let the support team reply as support@" or "who can send as the CEO?". It assumes you can connect to Exchange Online PowerShell.

At the end you will know exactly what each permission allows, you will have tested commands to grant and remove each one for users and groups, a way to control Outlook automapping, scripts that report every delegation in the tenant, and a troubleshooting table for the errors delegates report. If you are setting up access to a leaver's mailbox, Convert a user mailbox to a shared mailbox covers the steps before permissions.

The three permissions compared

Full AccessSend AsSend on Behalf
What it allowsOpen the mailbox, view, add and remove contentSend mail that appears to come from the mailbox or groupSend mail from the mailbox or group with the delegate shown
Read the mailbox?YesNoNo
Send from it?NoYesYes
What recipients see in FromNot applicableThe mailbox only"Delegate on behalf of Mailbox"
Where replies goNot applicableThe mailboxThe mailbox, not the delegate
PowerShellAdd-MailboxPermissionAdd-RecipientPermission-GrantSendOnBehalfTo on Set-Mailbox and group cmdlets
Applies toUser, shared, resource mailboxesMailboxes and all mail-enabled group typesMailboxes and groups; shared mailboxes only through PowerShell

Three rules sit on top of this table:

  • If a user has both Send As and Send on Behalf, Send As is always used.
  • Full Access granted on a mailbox that is hidden from address lists doesn't let the delegate open it, and Send As or Send on Behalf on a hidden mailbox doesn't let the delegate send from it.
  • In Exchange Online, a user with Full Access can see all items in the mailbox, including calendar items marked as private.

The last point matters for executive mailboxes. If an assistant should manage the calendar but not see private appointments, use calendar folder permissions instead of Full Access; see Calendar permissions in Exchange Online.

Prerequisites

  • The permissions listed under the "Mailbox settings" entry in Microsoft's Feature permissions in Exchange Online article.
  • The Exchange Online PowerShell module.
  • Delegates who are mailbox users, mail users, or mail-enabled security groups. A security group that isn't mail-enabled can be selected but doesn't work.
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com

Grant and remove Full Access

The basic grant:

Add-MailboxPermission -Identity "Terry Adams" -User raymonds@contoso.com -AccessRights FullAccess -InheritanceType All

-InheritanceType All is the default, so the permission applies to every folder in the mailbox. To remove it later, use the same parameters with Remove-MailboxPermission:

Remove-MailboxPermission -Identity "Terry Adams" -User raymonds@contoso.com -AccessRights FullAccess -InheritanceType All

Control automapping

Automapping uses Autodiscover to add a mailbox to the delegate's Outlook profile automatically. It is on by default for individual users. It doesn't work for groups, because Autodiscover doesn't expand security group membership.

To grant Full Access without automapping:

Add-MailboxPermission -Identity support@contoso.com -User ana@contoso.com -AccessRights FullAccess -InheritanceType All -AutoMapping $false

You can't turn automapping off on an existing permission. Remove the permission, then add it again with -AutoMapping $false. Users then add the mailbox manually in Outlook. When a mailbox is added through Outlook's advanced account settings, only the primary mailbox appears; if the delegate also needs the archive, add the mailbox as a second account in the same profile.

Use a group for larger teams

Add-MailboxPermission -Identity "Helpdesk Tickets" -User helpdesk-team@contoso.com -AccessRights FullAccess -InheritanceType All

A single mailbox can hold up to 500 permission entries. A mail-enabled security group counts as one entry however many members it has, so use groups when access needs to scale. The trade-off is that members don't get automapping.

Grant and remove Send As

Add-RecipientPermission -Identity support@contoso.com -Trustee ana@contoso.com -AccessRights SendAs -Confirm:$false
Remove-RecipientPermission -Identity support@contoso.com -Trustee ana@contoso.com -AccessRights SendAs -Confirm:$false

SendAs is the only valid value for -AccessRights here. Add-RecipientPermission has a built-in confirmation prompt, which is why scripts need -Confirm:$false. The target can be a mailbox, a mail user, a contact, a distribution group or a dynamic distribution group, and the trustee can be a group:

Add-RecipientPermission -Identity "Contoso Printer Support" -Trustee "Printer Support" -AccessRights SendAs -Confirm:$false

Grant and remove Send on Behalf

Send on Behalf isn't a separate cmdlet; it is the GrantSendOnBehalfTo property on the recipient. Use Set-Mailbox for mailboxes, Set-DistributionGroup for distribution groups and mail-enabled security groups, Set-DynamicDistributionGroup for dynamic groups and Set-UnifiedGroup for Microsoft 365 groups.

The value works in three ways, and mixing them up is the most common mistake:

# Replaces the whole list with one delegate
Set-Mailbox -Identity seanc@contoso.com -GrantSendOnBehalfTo hollyh@contoso.com
 
# Adds or removes delegates without touching the others
Set-Mailbox -Identity "Contoso Executives" -GrantSendOnBehalfTo @{Add="tempassistants@contoso.com"}
Set-Mailbox -Identity "Contoso Executives" -GrantSendOnBehalfTo @{Remove="tempassistants@contoso.com"}
 
# Clears every delegate
Set-Mailbox -Identity seanc@contoso.com -GrantSendOnBehalfTo $null

Always use the @{Add=...} form when a mailbox already has delegates, or you will silently remove them. For shared mailboxes, Send on Behalf isn't available in the Exchange admin center, so PowerShell is the only way to set it.

Keep a copy in the mailbox's Sent Items

By default, a message a delegate sends as or on behalf of a mailbox is saved only in the delegate's own Sent Items. For a shared mailbox or a manager's mailbox that is usually the wrong place. Configure the mailbox (not the delegate) to keep a copy:

Set-Mailbox -Identity support@contoso.com -MessageCopyForSentAsEnabled $true
Set-Mailbox -Identity support@contoso.com -MessageCopyForSendOnBehalfEnabled $true

Set the value back to $false to turn it off.

Grant permissions in the Exchange admin center

For one-off changes, go to Recipients > Mailboxes, select the mailbox and choose Mailbox delegation. The three sections are Send as, Send on behalf and Read and manage (Full Access); select Edit under one of them, then Add members, pick users or groups, and select Save > Confirm. You can also select several mailboxes at once and use Mailbox delegation to add the same delegate with the permission types you pick.

For groups, go to Recipients > Groups, select the group, then Settings > Manage delegates to set Send as or Send on behalf.

Audit permissions

One mailbox

Get-MailboxPermission -Identity support@contoso.com | Where-Object {$_.AccessRights -like 'Full*'} | Format-Table User,Deny,IsInherited,AccessRights -AutoSize
Get-RecipientPermission -Identity support@contoso.com
Get-Mailbox -Identity support@contoso.com | Format-List GrantSendOnBehalfTo

In the Full Access output, NT AUTHORITY\SELF is the mailbox's own entry and is always present. Entries with IsInherited set to True are inherited rather than granted on this mailbox. The entries that matter are the explicit ones.

Everything one user can send as

Get-RecipientPermission -Trustee "Kim Akers"

This lists every recipient the user can send as. Microsoft documents that the -Trustee filter can miss entries when the trustee's security identifiers have changed, so for an important review also run the tenant-wide report below.

Tenant-wide report

Microsoft recommends the Get-EXO* versions of these cmdlets in Exchange Online PowerShell.

$mailboxes = Get-Mailbox -ResultSize Unlimited
 
# Full Access granted by administrators
$fullAccess = foreach ($m in $mailboxes) {
    Get-EXOMailboxPermission -Identity $m.UserPrincipalName |
        Where-Object { $_.AccessRights -like '*FullAccess*' -and -not $_.IsInherited -and $_.User -ne 'NT AUTHORITY\SELF' } |
        Select-Object Identity, User, AccessRights
}
$fullAccess | Export-Csv C:\Temp\FullAccess.csv -NoTypeInformation
 
# Send As
Get-EXORecipientPermission -ResultSize Unlimited -AccessRights SendAs | Export-Csv C:\Temp\SendAs.csv -NoTypeInformation
 
# Send on Behalf
$mailboxes | Where-Object { $_.GrantSendOnBehalfTo } |
    Select-Object DisplayName, @{n='SendOnBehalf';e={$_.GrantSendOnBehalfTo -join '; '}} |
    Export-Csv C:\Temp\SendOnBehalf.csv -NoTypeInformation

The Send As export includes each mailbox's own NT AUTHORITY\SELF entry; filter those rows out when you review it. Run the report before and after a leaver process or a reorganization, and keep the files as evidence of who had access.

Troubleshooting

SymptomCauseFix
"You do not have the permission to send the message on behalf of the specified user", sometimes with error [0x80070005-0x0004dc-0x000524]The delegate has Full Access (and maybe Send on Behalf) but not Send As on the shared mailbox; Microsoft documents this when sending from an Outlook profile set up for the shared mailboxGrant Send As with Add-RecipientPermission
The same error right after a correct grant on a new mailboxReplication latencyWait about an hour and try again
A shared mailbox doesn't appear in Outlook for some team membersFull Access was granted through a group, so automapping doesn't applyGrant Full Access to those users directly, or have them add the mailbox manually
A mailbox keeps reappearing in Outlook after the user removes itAutomapping is on for that permissionRemove the permission and add it again with -AutoMapping $false
Delegate can't open or send from a mailbox at allThe mailbox is hidden from address listsUnhide it, or accept that delegation won't work for it
Sent messages are missing from the shared mailbox's Sent ItemsDefault behavior stores them in the delegate's Sent ItemsSet MessageCopyForSentAsEnabled and MessageCopyForSendOnBehalfEnabled on the shared mailbox
Existing Send on Behalf delegates disappeared-GrantSendOnBehalfTo was given a plain value, which replaces the listRe-add them and use @{Add=...} from now on
Add-RecipientPermission waits for input in a scriptIt has a built-in confirmation promptAdd -Confirm:$false

Migrations deserve a separate check, because delegation depends on where both the owner and the delegate live. The tenant-to-tenant migration architecture guide covers how mailbox permissions are handled in cross-tenant moves.

Summary checklist

  • Read the mailbox: Full Access with Add-MailboxPermission.
  • Reply as the mailbox: Send As with Add-RecipientPermission -Confirm:$false.
  • Reply showing the delegate: Send on Behalf with -GrantSendOnBehalfTo @{Add=...}.
  • Groups scale past the 500-entry limit but don't automap.
  • Turn on MessageCopyForSentAsEnabled and MessageCopyForSendOnBehalfEnabled for shared mailboxes.
  • Remember that Full Access exposes private calendar items.
  • Audit all three permissions; one command never shows the whole picture.

References

Questions people ask

What is the difference between Send As and Send on Behalf?

Send As sends a message that appears to come directly from the mailbox, with no sign of the delegate. Send on Behalf shows the delegate in the From address as "Delegate on behalf of Mailbox". If a user has both, Exchange always uses Send As.

Does Full Access let a user send email from the mailbox?

No. Full Access lets the delegate open the mailbox and read, add and delete its contents, but not send from it. To send, the delegate also needs Send As or Send on Behalf. When a delegate sends from an Outlook profile set up for a shared mailbox without Send As, Outlook returns "You do not have the permission to send the message on behalf of the specified user."

How do I stop a shared mailbox from appearing automatically in Outlook?

Grant Full Access with Add-MailboxPermission and -AutoMapping $false. If the user already has Full Access, remove it with Remove-MailboxPermission first and then add it again with -AutoMapping $false, because automapping can't be switched off on an existing permission.

Can I grant mailbox permissions to a group?

Yes, to a mail-enabled security group. It works for Full Access, Send As and Send on Behalf, but Outlook doesn't automap mailboxes granted through a group, so members have to add the mailbox themselves.

Exchange OnlineExchange Online PowerShellMailbox permissionsOutlook
  1. Calendar permissions in Exchange Online: Add-MailboxFolderPermission guide

    Share calendars, change the organization-wide Default permission and add calendar delegates in Exchange Online with Add-, Set- and Remove-MailboxFolderPermission, including localized folder names.

    Microsoft 3659 min read
  2. Control the new Outlook for Windows rollout with policies and toggles

    The admin controls for new Outlook for Windows: hide the toggle, stop automatic migration, block the app or mailbox access, and migrate on your own schedule before the March 2027 opt-out.

    Microsoft 36513 min read
  3. Convert a user mailbox to a shared mailbox and remove the license safely

    Keep a leaver's email and calendar in Exchange Online without paying for a license: secure the account, convert the mailbox, grant access, then remove the license in the right order.

    Microsoft 36511 min read