Nearly every small business we meet has one. An address like info@ or billing@ that four people check, protected by a password written on a sticky note, saved in three browsers, and known to at least one person who left years ago. It works. That is the frustrating part. It works well enough that nobody gets around to changing it.
The problem is that a shared password quietly costs you two things at once: security and accountability. And the alternative is not some expensive add on. It is a feature that has been built into business email platforms for years, usually at no extra cost, and most owners simply have not been told it exists. Here is how to do the shared address properly.
A Shared Password Is Two Problems Wearing One Coat
Start with security. A password known by four people has effectively been published. It gets typed on a home laptop, saved in a personal browser, texted to a new hire, and reused elsewhere because it is short and memorable. It cannot be rotated without disrupting everyone at once, so it never gets rotated. Modern sign in protections get awkward too, because a second factor tied to one person’s phone means that person has to be reachable whenever anyone else needs in.
Then there is accountability, which is the one that causes arguments. When four people sign in as the same account, the mailbox has no memory of who did what. Who replied to that customer. Who deleted the message. Who promised the refund. Nobody is lying. The system genuinely cannot tell you. Everyone sees the same undifferentiated activity, so nobody feels responsible for any of it, which is how a message sits unanswered for six days.
This is the same accountability logic that underpins a lot of basic security work, which we made the broader case for in why security stopped being optional for businesses this size.
How a Proper Shared Mailbox Actually Works
The right structure is a mailbox nobody signs into. It has an address and a place to store mail, and named people are granted permission to open it using their own accounts. There is no password for the mailbox, because there is no login for it. Product names and packaging change regularly, so confirm what your plan includes, but the capability is common across major business email platforms.
Microsoft’s documentation on shared mailboxes, which we reviewed in 2026, describes the model clearly. A shared mailbox lets a group of people monitor and send email from a common address, and it comes with a shared calendar. By default, every new shared mailbox has sign in blocked, which Microsoft frames as a security best practice. People reach it through their own accounts, and the mailbox typically appears in their mail app after a restart once permissions are assigned.
- Nobody signs in as info@. Everyone signs in as themselves and sees the shared mailbox alongside their own. One person leaving changes nothing for anyone else.
- Permissions come in distinct flavors. That same Microsoft documentation describes full access, which allows opening the mailbox and managing its contents, and separate send as and send on behalf permissions. Notably, full access alone does not let someone send from the address. Sending is granted deliberately, which is a feature and not an oversight.
- It usually does not need its own license. Microsoft’s 2026 documentation says shared mailboxes generally do not require a license, though a specific Exchange Online plan is needed in certain cases, including when storage in use exceeds roughly 50 GB, when in place archiving is used, or when the mailbox is placed on litigation hold. Thresholds and licensing rules change, so verify against your current subscription.
Because the mailbox usually costs nothing extra, this is one of the few improvements that makes your setup both safer and cheaper. That is rarer than it should be, and it fits a pattern we covered in our review of what neglected subscriptions cost a business.
Sending As the Shared Address, and Where the Copy Lands
There are two ways to send from a shared address. Send as makes the message appear to come from the shared address. Send on behalf shows the recipient something like the individual on behalf of the shared address. For a customer facing address, send as is almost always what you want. Nobody outside your company needs to know which staff member typed the reply.
Now the important part. Microsoft’s Exchange Online documentation, reviewed in 2026, states that by default a message sent using send as or send on behalf is stored only in the sender’s own sent items. Read that again, because it means your shared mailbox has a complete record of what came in and no record of what went out. Somebody asks what we told the customer, and the answer lives in a colleague’s personal mailbox.
That documentation also describes the settings that fix it. There are two mailbox settings, one for copies of messages sent as the mailbox and one for messages sent on behalf of it, and turning them on saves the sent message to the shared mailbox’s sent items as well. Have whoever administers your email turn both on when the mailbox is created.
Somebody Has to Own Triage
The technology is the easy half. A shared mailbox with four people and no owner produces the same outcome as a shared password with four people and no owner: everyone assumes someone else has it.
- Name one owner per mailbox, not a committee. One person is accountable for the mailbox being empty at the end of each day. Others help. One owns.
- Claim a message visibly. A category or flag meaning I have got this stops two people answering the same customer, and stops nobody answering.
- Define done, and move it. Handled mail leaves the inbox for a processed folder. An inbox that doubles as an archive is unreadable within a month.
When the Person Who Ran It Leaves
With a properly built shared mailbox, a departure is a two minute job. Remove that person’s permission. The mailbox, its history, its sent items, and everyone else’s access are untouched. Nobody changes a password. With a shared password, a departure means rotating the credential, updating it in four places, and hoping the copy nobody mentioned does not exist.
There is also the departing person’s own individual address. Microsoft’s guidance on removing a former employee, reviewed in 2026, describes converting that mailbox to a shared mailbox or setting up forwarding so mail from customers and partners still reaches whoever takes over the work. That guidance sequences the steps with preventing sign in first, then preserving and transferring the data, and only afterward removing the license and deleting the account. It also notes that once a license is removed, mail, contacts, and calendar are retained for 30 days before permanent deletion. Retention windows change, so confirm the current rules for your plan.
The Bottom Line
Set it up in this order: create the mailbox with sign in blocked, grant full access plus send as to the specific people who need it, turn on the settings that save sent copies into the shared mailbox, name one owner for triage, and write down two sentences about coverage. That is the whole thing, and it is an afternoon at most for a business with several shared addresses.
If your info@ or billing@ address still runs on a password everyone knows, we can convert it without losing a message or interrupting anyone’s day. We will move the history, set the permissions, get the sent items landing where they belong, and clean up the accounts of anyone who should have lost access a while ago. Contact us today.
Sources:
Comments are closed