Deleting an unlicensed user also deleted it's shared mailbox.

thecomputerguy

Well-Known Member
Reaction score
1,480
Any way around this?

My typical off boarding process for O365 is:

Reset Password
Block Sign-in
Remove from GAL
Revoke sessions
Convert to Shared Mailbox
Remove user License

Sometimes, if a client gets a peek at the admin center they bring up that long old employees still show up under Users > Active users

If I delete the unlicensed user it's shared mailbox along with any forwarding goes with it.

Any way around this aside from filtering out unlicensed users?
 
If you need to keep the shared mailbox...do not delete the licensed user.
When retiring a user, we disconnect all sessions, remove them from all groups, hide their name from the GAL, block any smart phones on the mailbox, remove their license, block sign in...and..leave the user account there ...assigning membership and forwarding to the shared mailbox, and moving their OneDrive content to the Archive Team I create for that purpose.
 
If you need to keep the shared mailbox...do not delete the licensed user.
When retiring a user, we disconnect all sessions, remove them from all groups, hide their name from the GAL, block any smart phones on the mailbox, remove their license, block sign in...and..leave the user account there ...assigning membership and forwarding to the shared mailbox, and moving their OneDrive content to the Archive Team I create for that purpose.

Ok ... that's what I thought ... that's pretty much what I do but when the client asked to purge all unlicensed users .. I had to explain this to him and he still chose to move forward. I just had to double check because it seemed like an uncommon request.

Whatever ... not my rodeo.
 
All objects in M365 must have an identity, mailboxes are no exception.

By deleting the identity you're destroying all associated data.

And yes, shared mailboxes have an account... so do Teams Voice accounts, and service principles... there are a TON of reasons to have unlicensed accounts inside a tenant. And frankly, I would reject the demand to delete the batch as you've been instructed because it can seriously damage the tenant and would also obliterate the admin accounts if you're doing it correctly.

Nope... customer can give me a specific list of accounts to fry, I'm not about to push the big red button on a nuke that big.
 
Back
Top