What each Exchange Online mailbox permission allows and which recipients and groups can hold it.
From Ultra Transcenders AB-900 by Tony Rough (coming November 2026)
Three permissions let a delegate use someone else’s mailbox or a group’s address. They’re set in the EAC under Recipients > Mailboxes (or Resources) > select the mailbox > Mailbox delegation, and for groups under Recipients > Groups > group > Settings > Manage delegates.
| Permission | What the delegate can do | What it doesn’t allow | Applies to |
|---|---|---|---|
| Full Access (shown as “Read and manage”) | Open the mailbox and view, add and remove its contents | Sending mail from the mailbox | User, shared and resource mailboxes |
| Send As | Send mail that appears to come directly from the mailbox or group, with no sign of the delegate | Reading the mailbox | Mailboxes and all mail-enabled group types |
| Send on Behalf | Send mail shown as “delegate on behalf of mailbox”; replies go to the mailbox or group | Reading the mailbox | User and resource mailboxes and groups in the EAC; shared mailboxes only through PowerShell |
The permission can be granted to individual users, but also to groups, and here the group type matters:
Add-MailboxPermission and the AutoMapping setting.Common trap: Full Access lets a delegate send replies from the shared mailbox - it doesn’t. Full Access covers reading and managing contents only; sending needs Send As or Send on Behalf as well.
Common trap: Any security group can be given Full Access to a shared mailbox - wrong. The group must be a mail-enabled security group; plain security groups and distribution groups aren’t valid Full Access delegates.
This note is one section of Ultra Transcenders AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · AB-900 terms in the glossary · All AB-900 study notes
Verify explicitly, use least privilege access and assume breach, and the pillars they apply to.
How Conditional Access turns sign-in signals into block or grant decisions, and what licence it needs.
What the score measures, how often it is recalculated and which recommendations raise it.
Sharing-link, permission and Everyone except external users reports for finding oversharing.
How restricted site access limits a site to members of chosen groups, even for users with permission.
What the two built-in reasoning agents are for, how they are deployed and when a custom agent fits.
How billing policies connect metered Copilot Chat and SharePoint agent use to an Azure subscription, and what budgets do.