Use a shared mailbox when a small team works one inbox together and replies as that address, such as info@ or support@: it holds up to 50 GB without a license and supports up to 25 users. Use a Microsoft 365 group when the team also needs shared files, Planner, a team in Microsoft Teams or guest access, or when more than 25 people need the inbox. Use a distribution list when you only need to deliver mail to each member's own inbox, a mail-enabled security group when the same list must also grant permissions, and a dynamic distribution group when membership should follow user attributes.
Who this is for and what you will have at the end
This guide is for Microsoft 365 and Exchange Online administrators who get requests like "we need a team email address" and want to choose the right recipient type the first time. Changing later is often painful: a shared mailbox can't be migrated to a group, and distribution lists can be upgraded only when they meet strict conditions.
At the end you will have a decision table, the limits and licensing facts for each type, the PowerShell to create each one, and a list of the mistakes that cause most support tickets. The same decision comes up during migrations: the native Google Workspace migration moves users' mail, calendar and contacts, so Google Groups have to be recreated as one of these types, as covered in the Google Workspace to Microsoft 365 migration guide.
The short answer
| Requirement | Choose |
|---|---|
| A team triages one inbox, replies appear to come from the shared address, up to 25 people | Shared mailbox |
| A shared inbox plus a shared calendar, files, Planner or a Teams team | Microsoft 365 group |
| More than 25 people need the same inbox, or guests must take part | Microsoft 365 group |
| Announcements to a fixed set of people, each copy in their own inbox | Distribution list |
| A list that is also used to grant access to SharePoint or other resources | Mail-enabled security group |
| A list whose membership is calculated from attributes like department or location | Dynamic distribution group, or a Microsoft 365 group with dynamic membership in Microsoft Entra ID |
Side-by-side comparison
| Property | Shared mailbox | Microsoft 365 group | Distribution list |
|---|---|---|---|
| Where mail lands | One mailbox that members open | A group mailbox; members can also subscribe to get copies in their inbox | Each member's own mailbox only |
| Reply as the shared address | Yes, with Send As or Send on Behalf | Yes, if the admin enables Send As or Send on Behalf | No (there is no mailbox to send from) |
| License | None up to 50 GB | Follows the license of the person who created the group | None |
| Storage | 50 GB unlicensed; 100 GB with Exchange Online Plan 2 | Group mailbox 50 GB; SharePoint file storage is separate | Not applicable |
| Member limit | Maximum 25 users | More than 1,000; only 1,000 can access group conversations concurrently | 100,000 members |
| External people | No access for external users | Guests can be members, if enabled; external senders allowed if enabled | Can receive external senders, if enabled |
| Shared calendar | Yes | Yes | No |
| Files, Planner, Teams | No | Yes | No (members can be added to a team, but not the list itself) |
| Dynamic membership in Microsoft Entra ID | No | Yes | No |
| Can users be stopped from deleting shared mail | No | Group conversations deleted from a member's inbox stay in the group mailbox | Not applicable |
All of these are mail-enabled. Security groups that aren't mail-enabled can't receive mail at all.
Shared mailboxes in detail
A shared mailbox is a mailbox without its own user. Every shared mailbox has a user account with a system-generated password, and sign-in for that account is blocked by default for new shared mailboxes. Keep it blocked; the mailbox isn't designed for direct sign-in. If you run an Exchange hybrid deployment, create and manage shared mailboxes in the on-premises Exchange admin center instead of the cloud.
Licensing and storage. Without a license, a shared mailbox can store up to 50 GB. When it reaches the limit it can keep receiving for a while but can't send, and eventually senders get a non-delivery report. An Exchange Online Plan 2 license raises the limit to 100 GB. Archiving beyond the default and litigation hold need Exchange Online Plan 2, or Plan 1 with the Exchange Online Archiving add-on. Unlicensed shared mailboxes created before July 2018 have a size of 100 GB.
Who can use it. Only people inside your organization with their own licensed Exchange Online mailboxes. You can't give external users, for example someone with a Gmail account, access to a shared mailbox.
Permissions. There are three:
- Full Access opens the mailbox and lets the user read, create and delete items. It doesn't allow sending as the mailbox.
- Send As sends mail that appears to come from the shared mailbox itself.
- Send on Behalf sends mail that shows "user on behalf of shared mailbox".
Automapping. When you grant Full Access to an individual user, Outlook adds the shared mailbox to that user's profile automatically after Outlook restarts. Automapping is set on the user's mailbox, not the shared mailbox, so if you grant Full Access through a security group, the mailbox won't automap. If you want automapping, assign permissions to users explicitly.
Limits to know before choosing it:
- A maximum of 25 users. Beyond that, people can see connection failures or duplicated messages.
- You can't prevent members from deleting messages.
- Mail sent from a shared mailbox can't be encrypted with its own key, because the mailbox has no security context of its own.
- Send As and Send on Behalf don't work in Outlook desktop if the mailbox is hidden from address lists, because Outlook needs to find it in the global address list.
Microsoft 365 Groups in detail
A Microsoft 365 group is a membership object in Microsoft Entra ID that grants access to a set of connected resources: a shared Outlook inbox and calendar, a SharePoint document library, a OneNote notebook and Planner, plus a team if the group was created from Microsoft Teams. Adding someone to the group gives them access to all of it.
Roles. Owners manage membership and settings and can manage conversations in the shared inbox. Members use the resources. Guests are external users invited into the group, if guest access is allowed.
Privacy. A public group lets anyone in the organization see its content and join without approval; a private group restricts content to members and requires owner approval to join. Public is the default when you create a group with New-UnifiedGroup.
Limits. 100 owners per group, 250 groups that a regular user can create, membership in up to 7,000 groups per user, and a 50 GB group mailbox. Groups can have more than 1,000 members, but only 1,000 can access group conversations concurrently and Outlook can be slow for very large groups.
Lifecycle. Deleted groups can be restored for 30 days, and an expiration policy can delete groups that owners don't renew; owners get renewal notifications 30 days, 15 days and 1 day before expiry.
Settings you will use often:
-AutoSubscribeNewMembersonSet-UnifiedGroupsubscribes members added after the change to conversations and calendar events, so they also get copies in their own inbox, which makes the group behave more like a distribution list for those users.-HiddenFromExchangeClientsEnabledhides a group from Outlook and the global address list while it can still receive mail.-RequireSenderAuthenticationEnabled $falselets external senders mail the group;$trueaccepts only internal senders.
Group creation can be limited to specific people, and if you limit it, users who aren't allowed also can't create Teams teams, Planner plans or SharePoint sites that depend on groups. Decide that policy before broad rollout.
Distribution lists, mail-enabled security groups and dynamic groups
A distribution list (distribution group) delivers a copy of each message to every member. It is the right tool for announcements such as "Everyone in Building A". Key limits in Exchange Online:
- Up to 100,000 members, counted after nested groups are expanded.
- 100 owners per group.
- Groups with 5,000 or more members must have delivery management or message approval configured.
- The maximum message size is 25 MB for groups with 5,000 to 99,999 members and 5 MB for groups with 100,000 members.
A Microsoft 365 group can't be a member of a distribution list or a security group. Adding a distribution list to a team in Microsoft Teams adds its members, not the list.
A mail-enabled security group behaves like a distribution list but can also be used to grant permissions, for example to a SharePoint site or a shared mailbox. It can't use dynamic membership from Microsoft Entra ID and can't contain devices.
A dynamic distribution group builds its membership from filters you define in Exchange (such as department or location). In Exchange Online the membership list is calculated when the group is created or its rules change, and then refreshed at least once every 24 hours; mail goes to the members in the list at the time it's sent. It needs no membership maintenance, but between refreshes the list can be stale: someone who leaves a department can keep receiving mail until the next refresh. A new group whose rules return 5,000 members or fewer is populated immediately; larger groups are populated by a background process within up to 2 hours.
Create each type with PowerShell
Connect first:
Connect-ExchangeOnline -UserPrincipalName admin@contoso.comShared mailbox
New-Mailbox -Shared -Name "Support" -DisplayName "Contoso Support" -Alias support
Add-MailboxPermission -Identity support -User "Ana Bowman" -AccessRights FullAccess -InheritanceType All
Add-RecipientPermission -Identity support -AccessRights SendAs -Trustee "Ana Bowman"To grant Full Access without automapping, add -AutoMapping $false. To grant Send on Behalf instead of Send As, use Set-Mailbox -Identity support -GrantSendOnBehalfTo "Ana Bowman". In the Microsoft 365 admin center, shared mailboxes are under Teams & groups > Shared mailboxes.
Microsoft 365 group
New-UnifiedGroup -DisplayName "Engineering Department" -Alias engineering -AccessType Private
Set-UnifiedGroup -Identity engineering -AutoSubscribeNewMembersDistribution list and mail-enabled security group
New-DistributionGroup -Name "ITDepartment" -Members chris@contoso.com,michelle@contoso.com
New-DistributionGroup -Name "Managers" -Type "Security"-Type Distribution is the default; Security creates a mail-enabled security group. The scope is always Universal.
Dynamic distribution group
New-DynamicDistributionGroup -Name "Marketing Group" -IncludedRecipients "MailboxUsers,MailContacts" -ConditionalDepartment "Marketing","Sales"Changing your mind later
| From | To | Supported? |
|---|---|---|
| User mailbox | Shared mailbox | Yes, convert the mailbox |
| Shared mailbox | Microsoft 365 group | No |
| Distribution list | Microsoft 365 group | Yes, if the list is eligible |
Only cloud-managed, simple, non-nested distribution lists can be upgraded. A list can't be upgraded if it is nested, synced from on-premises Active Directory, has more than 100 owners, has members but no owner, has no members, contains members other than user mailboxes, shared mailboxes, team mailboxes or mail users, is a forwarding address for a shared mailbox, is part of a sender restriction on another list, has special characters in its alias, is a mail-enabled security group or dynamic group, or was converted to a room list. A custom email address policy for Microsoft 365 Groups can also block it.
Check eligibility and upgrade:
Get-EligibleDistributionGroupForMigration
Upgrade-DistributionGroup -DlIdentities hr@contoso.comIn the Exchange admin center, an admin can instead select the list under Recipients > Group > Distribution List and choose Send upgrade request; the owners receive an email and complete the upgrade. The email address doesn't change, and the upgrade takes up to 5 to 10 minutes.
Common mistakes and how to fix them
| Problem | Cause | Fix |
|---|---|---|
The proxy address "smtp:..." is already being used when creating a shared mailbox | The name or alias is already in use, for example info@ in a second domain | Create it with a different name and rename it in the admin center, or create it with Exchange Online PowerShell (Microsoft documents a procedure for the same alias in different domains). |
You do not have the permission to send the message on behalf of the specified user right after setup | Replication latency for new mailboxes or permissions | Wait about an hour and try again. |
| Shared mailbox doesn't appear in Outlook for some users | Full Access was granted through a security group, so automapping doesn't apply | Grant Full Access to the users directly, or have them add the mailbox manually. |
| Duplicated items and connection errors in a busy shared mailbox | More than 25 users | Move the workload to a Microsoft 365 group. |
| External partners can't be given access to the support inbox | Shared mailboxes don't support external users | Use a Microsoft 365 group with guest access. |
| Team needs to stop accidental deletion of shared mail | Not possible in a shared mailbox | Use a Microsoft 365 group. |
| A distribution list grows past 5,000 members | Exchange Online requires delivery management or message approval at that size | Configure allowed senders or moderators for the list. |
Summary
- Shared mailbox: one inbox, reply as the address, 25 users, 50 GB without a license, internal users only.
- Microsoft 365 group: shared inbox, calendar, files, Planner and Teams, guests, dynamic membership, 50 GB group mailbox.
- Distribution list: copies to each member, up to 100,000 members, no shared storage.
- Mail-enabled security group: a distribution list that also grants permissions.
- Dynamic distribution group: membership calculated from Exchange filters and refreshed at least every 24 hours.
- Pick carefully: shared mailboxes can't become groups, and only simple cloud-managed lists can be upgraded.
References
- About shared mailboxes in Microsoft 365
- Create a shared mailbox
- Compare types of groups in Microsoft 365
- Learn about Microsoft 365 Groups
- Exchange Online limits
- Upgrade distribution lists to Microsoft 365 Groups
- Can't upgrade distribution lists to Microsoft 365 Groups
- New-Mailbox
- Add-MailboxPermission
- Add-RecipientPermission
- New-UnifiedGroup
- Set-UnifiedGroup
- New-DistributionGroup
- Manage dynamic distribution groups in Exchange Online
- New-DynamicDistributionGroup
- Upgrade-DistributionGroup