accounts@ and info@ handle more money-moving email than any personal inbox, and usually nobody owns them. Three checks that take about twenty minutes.
The invoice that actually gets paid rarely lands in anyone's personal inbox. It lands in accounts@ — the mailbox four people can open, that shows up automatically in everyone's Outlook, and that nobody in the building is named as the owner of.
Every small business ends up with a few of these. info@, orders@, support@, reception@. They're a genuinely good idea: Microsoft built shared mailboxes so a team can cover an address without sharing a password, and they don't cost anything extra. The problem isn't the mailbox. It's what happens to it after eighteen months of staff changes.
The risky one is the one that used to be a person
Here's the pattern almost every small business follows when someone leaves: rather than delete their mailbox and lose the client history in it, you convert it to a shared mailbox so whoever takes over the work can still read it. Sensible.
But read what Microsoft's own instructions say about that conversion: "You don't need to reset the account password of the user mailbox. However, if you don't reset the password, the original username and password will continue to work on the shared mailbox after the conversion is finished."
The same page also tells you not to delete the old user account, because the account is what the shared mailbox hangs off. So the account stays. And unless someone specifically reset the password, the credentials your former sales manager chose — and probably still remembers, and probably reused somewhere that has since been breached — still open that mailbox.
One more line from the same page: "Inbox rules are preserved after the user mailbox is converted to a shared mailbox." If that person had set up a rule quietly forwarding a copy of everything to a personal address, that rule survived the conversion and is still running today.
Mailboxes created as shared are fine. Converted ones are the gap.
Microsoft's guidance is blunt: a shared mailbox isn't meant for anyone to sign in to directly, and sign-in should be blocked and kept blocked. Every shared mailbox you create fresh in the admin center today has sign-in blocked automatically.
That default doesn't apply retroactively to a mailbox that started life as an employee's account. So the mailboxes most likely to be sitting there with sign-in still enabled are exactly the ones with the longest history and the most sensitive mail in them.
An account with sign-in enabled and no multi-factor authentication is the softest target in your business. Nobody signs in as accounts@ personally, so nobody ever walked it through setting up an authenticator app. Nobody watches its sign-in activity either. An attacker guessing common passwords against your domain gets no alert and no lockout drama — just a mailbox full of invoices, bank details and vendor conversations, which is the raw material for every invoice-redirection scam there is.
"Who has access?" is a longer list than you think
Access to a shared mailbox is granted person by person, and it accumulates. The temp who covered reception two summers ago. The bookkeeper you replaced last year. The manager who needed it for one week during a handover.
Because Microsoft 365 adds shared mailboxes to people's Outlook automatically, most of them have no idea they still have it. The mailbox is just quietly there in the sidebar, and has been for years.
Three things worth doing this week
Write down every shared mailbox and put a name next to it. Not "the office" — a person. That person is responsible for who has access and for noticing when something looks off. Ten minutes.
Ask your IT provider one question, by name: "Is sign-in blocked on every shared mailbox, including any that were converted from a former employee's account, and was the password reset on those?" A good provider will check and come back with a list. It's a five-minute job on their end.
Review who has Full Access on each one and take off anyone who no longer needs it. When someone leaves, this belongs in your offboarding routine rather than a once-a-year cleanup.
None of this is dramatic work. It's the kind of setting that stays invisible until someone specifically looks at it. A read-only scan from Tenant Strike looks at the ones next door — which accounts have no multi-factor authentication registered, which inbox rules forward mail outside the company — and grades your Microsoft 365 configuration A–F, with the exact fix for anything it finds. It can see settings; it can't change them.
The mailbox nobody owns is the one nobody is watching. Giving it a name is most of the work.
AI-researched from public sources. We label AI-assisted writing — see our trust page.
See your own risk
Want this for your own Microsoft cloud?
Tenant Strike finds the security gaps in your Microsoft 365 and Azure, shows how they chain into a real break-in, and hands you a plain-English fix for every one — read-only, and it never asks for permission to change anything. Start a 7-day Pro trial — no credit card.