---
title: "Using Shared Mailboxes"
manual: "Microsoft Exchange 365 Mailer"
version: "main"
permalink: "https://docs.typo3.org/permalink/oliverkroener/ok-exchange365-mailer:shared-mailboxes@main"
source: "ExchangeSetup/SharedMailboxes.rst"
rendered: "2026-10-04T20:03:13+00:00"
---

# Using Shared Mailboxes {#shared-mailboxes}

> [!WARNING]
> **Attention**
>
> You **cannot** use a shared mailbox directly as the `PolicyScopeGroupId` – it requires a **mail-enabled security group**.

If you see an error like this when creating the policy:

```text
The policy scope "shared@yourdomain.com" is not a valid mail-enabled security group.
```

You need to create a mail-enabled security group and add the shared mailbox to it.

## Create a mail-enabled security group {#create-a-mail-enabled-security-group}

**1\. Create the security group via PowerShell:**

```powershell
New-DistributionGroup -Name "Graph API Shared Mailboxes" -Type Security -PrimarySmtpAddress "graph-mailboxes@yourdomain.com"
```

**2\. Add your shared mailbox to the group:**

```powershell
Add-DistributionGroupMember -Identity "Graph API Shared Mailboxes" -Member "shared@yourdomain.com"
```

**3\. Verify the group was created correctly:**

```powershell
Get-DistributionGroup -Identity "Graph API Shared Mailboxes" | Format-List
Get-DistributionGroupMember -Identity "Graph API Shared Mailboxes"
```

**4\. Now create the Application Access Policy using the group:**

```powershell
New-ApplicationAccessPolicy -AppId "<your-app-id>" -PolicyScopeGroupId "graph-mailboxes@yourdomain.com" -AccessRight RestrictAccess -Description "Allow app to send from shared mailboxes"
```

**5\. Test the policy:**

```powershell
Test-ApplicationAccessPolicy -Identity "shared@yourdomain.com" -AppId "<your-app-id>"
```

You should see `AccessCheckResult: Granted`.

> [!WARNING]
> Policy changes can take **up to 30 minutes** to propagate. If the test shows "Denied" immediately after creating the policy, wait and try again.

## Adding multiple mailboxes {#adding-multiple-mailboxes}

Simply add additional mailboxes to the same security group you already created:

```powershell
Add-DistributionGroupMember -Identity "Graph API Shared Mailboxes" -Member "another-shared@yourdomain.com"
```

The Application Access Policy applies to **all members** of the group – no need to create a new policy.

**Verify it worked:**

```powershell
# List all members of the group
Get-DistributionGroupMember -Identity "Graph API Shared Mailboxes"

# Test the new mailbox
Test-ApplicationAccessPolicy -Identity "another-shared@yourdomain.com" -AppId "<your-app-id>"
```

> [!NOTE]
> Changes can take up to 30 minutes to propagate. If the test doesn't show "Granted" immediately, wait and try again.

## Alternative via Microsoft 365 Admin Center {#alternative-via-microsoft-365-admin-center}

1.  Go to **Admin Center → Teams & Groups → Active teams & groups**
1.  Click **Add a group** and select **Mail-enabled security**
1.  Name the group (e.g., "Graph API Shared Mailboxes")
1.  Add the shared mailbox as a member
1.  Then run the `New-ApplicationAccessPolicy` command with that group's email address
