The list
Every mailbox in the tenant — user, shared, room, equipment, and Microsoft 365 group mailboxes — filterable by type. Searching matches the name, the primary address and every alias.
A Microsoft 365 group mailbox appears here too, but its Edit takes you to the group card, because that is where a group's mail settings live. There is a way back to this list from there.
This whole page runs Exchange cmdlets, so it needs Exchange Administrator or the Recipient Management role group. A directory role such as User Administrator does not reach any of it.
The card
Nine sections. Each loads the first time you open it rather than all at once — the whole card would otherwise be a dozen round trips before it became usable — and each keeps its own values once loaded. The status line is cleared whenever you switch section, so a confirmation from one section never lingers over another.
Settings
The mailbox type, whether it is hidden from address lists, the mailbox language and time zone, and current mailbox usage. Localize default folder names renames the built-in folders into the chosen language.
Save writes only what you actually changed, and tells you when there was nothing to write rather than reporting a save that did nothing.
If a mailbox shows its type and address-list flag but reports that the language and time zone are unavailable, the recipient exists in the directory without a live mailbox behind it — unlicensed, inactive, or not yet provisioned. That reading has to be routed to the mailbox itself, unlike everything else in this section, so it is the one that fails first. Blank language and time-zone boxes would read as "not set", which is why the card names what is missing instead.
Converting between regular and shared
Mailbox type is read-only text next to a button naming the destination. Pressing it opens a panel that states the consequences before you convert, and keeps the outstanding work on screen afterwards under a Still to do heading — because in both directions the conversion is not the last step:
- To regular: assign a licence and reset the password. A shared mailbox's account normally has sign-in blocked and a password nobody knows, so stopping at the conversion leaves a mailbox nobody can open. Neither step can be done from this page.
- To shared: block sign-in, then release the licence once the change has replicated.
The result is confirmed by re-reading the mailbox repeatedly, not by a success code: Exchange keeps reporting the old type for a while afterwards, so a single immediate read reports a conversion that did work as a failure. If it still cannot be confirmed, you get a Check again button — not a claim that it was refused, and not an offer to run the conversion a second time.
Only regular ⇄ shared is offered. Room and equipment conversions are deliberately left out: what makes a room mailbox useful is its calendar processing — booking window, delegates, automatic acceptance — and there is no section here for that, so a mailbox converted to Room would be half-configured with no way to finish the job. A room or equipment mailbox is told why the button is absent rather than simply not having one.
Email addresses
Add an alias, remove one, or promote one to primary, over your accepted domains. The primary address is Exchange's to own — this is where it changes, not on the user card.
After a change that moves the primary, the app re-reads the mailbox to confirm it: Exchange can accept a request and quietly ignore an address it could not resolve, so a success code alone is not proof.
Forwarding
Forward incoming mail to an address, with the option to keep a copy in the mailbox.
Automatic replies
Turn replies on or off, with separate internal and external messages and a choice of external audience.
Delivery restrictions
Maximum send and receive size, maximum recipients per message, and lists for accepting mail only from — or rejecting it from — specific senders.
Storage & hold
Enable the online archive and name it, and see or set litigation hold. Worth checking before any cleanup run: a mailbox on hold retains items regardless of what you delete, so a permanent delete may not free the space you expect.
Folder permissions
Per-folder access levels: view, grant and revoke. Default and Anonymous can be edited but not removed. Editing an existing entry changes its level in place rather than removing and re-adding it.
Mailbox permissions
Full Access, Send As and Send on Behalf — view, grant and revoke. Granting Full Access optionally maps the mailbox into the grantee's Outlook profile; the app leaves that off unless you ask for it, because a mailbox granted for an administrative task should not silently appear in someone's Outlook.
This is also the permission the mailbox tools depend on, and the one the Cleanup wizard offers to grant you. A newly granted permission can take a few minutes before the mailbox will actually open.
Both permission sections write immediately, so the card's Save reports that rather than duplicating the work.
Custom attributes
The mailbox's five multi-valued ExtensionCustomAttribute slots,
read-only.
These are not the fifteen you may be thinking of. Exchange calls the directory's
extensionAttribute1–15 "CustomAttribute1–15", and those are single strings
edited on the user card. The five here belong to the
mailbox, hold multiple values each, and are not exposed by Microsoft Graph at
all. Both sections say so, because the naming invites exactly the wrong guess.
Getting here from a user
The user card has an Edit mailbox link that jumps straight to that mailbox's card, and Back returns you to the user rather than dropping you on the mailbox list. If the account has an address but no Exchange mailbox behind it, you get a clear message on arrival — a mail address does not prove a mailbox exists.