LENOX INTERNATIONAL HOLDINGS GROUP
STANDARD OPERATING PROCEDURE
Team Member Setup and Access for Shared Email Accounts
Microsoft 365 / Outlook Shared Mailbox Operating Procedure
|
Document Control Item |
Detail |
|
Document Owner |
Lenox International
Holdings Group / IT & Operations |
|
Applies To |
LIHG, subsidiaries,
brands, team members, contractors, virtual assistants, and approved
administrators |
|
Primary Systems |
Microsoft 365 Admin
Center, Exchange Admin Center, Outlook Desktop, Outlook on the Web, Outlook
Mobile |
|
Version |
v1.0 |
|
Effective Date |
May 11, 2026 |
|
Classification |
Confidential Internal
Operations SOP |
|
Review Cycle |
Quarterly or upon
Microsoft 365 configuration changes |
This SOP
establishes the official LIHG procedure for creating, configuring, securing,
accessing, and managing shared email accounts across the organization. The
purpose is to ensure that departmental and brand-level email communication is
handled through controlled shared mailboxes rather than individual passwords,
uncontrolled forwarding, or personal inbox access.
The procedure
supports centralized intake, proper role-based access, auditability, security,
continuity during staff changes, and consistent email handling across LIHG and
all operating brands.
This SOP
applies to all shared email accounts used for business operations, including
but not limited to info, sales, support, HR, finance, compliance, media, public
relations, partnerships, podcast, events, grants, and executive administration
inboxes.
This SOP covers
setup by an authorized administrator and access by approved team members. It
does not authorize team members to use, request, share, store, or transmit
passwords for shared mailboxes.
This SOP
follows LIHG governance requirements for executive document structure, version
control, secure workflows, professional formatting, and centralized operational
oversight. LIHG governance requires SOPs to include purpose, scope,
responsibilities, procedural steps, and quality-control sections. It also
requires formal naming conventions, version control, and secure storage within
approved LIHG directories.
·
Microsoft guidance confirms that shared
mailboxes are intended for groups of people to monitor and send from a common
email address, such as info@company.com.
·
Microsoft guidance further confirms that shared
mailboxes are not intended for direct sign-in and that sign-in should remain
blocked for the mailbox account.
·
Access must be assigned through user
permissions; the user accesses the shared mailbox by signing into the user’s
own licensed mailbox.
|
Term |
Definition |
|
Shared Mailbox |
A Microsoft 365 mailbox
used by multiple approved users to read, manage, and send email from a common
business address. |
|
Full Access / Read and
Manage |
Permission that allows a
user to open, read, organize, delete, and manage mailbox content. It does not
automatically allow sending. |
|
Send As |
Permission allowing an
approved user to send email so the recipient sees the shared mailbox as the
sender. |
|
Send on Behalf |
Permission allowing an
approved user to send with wording that indicates the message was sent by the
user on behalf of the mailbox. |
|
Automapping |
Microsoft 365 behavior
that can automatically display a shared mailbox in Outlook after the user is
granted direct mailbox access. |
|
Mailbox Owner |
The department head or
approved manager responsible for business use, access approval, cleanup, and
escalation. |
|
Mailbox Administrator |
The IT or Microsoft 365
administrator who creates, configures, secures, and audits the mailbox. |
|
Role |
Responsibilities |
|
LIHG Executive Leadership |
Approves enterprise
mailbox strategy, sensitive mailbox categories, and major access-control
decisions. |
|
IT / Microsoft 365
Administrator |
Creates shared mailboxes,
assigns permissions, blocks sign-in, verifies licensing requirements,
configures delegation, and maintains audit records. |
|
Department or Brand
Manager |
Approves who needs access,
defines folder use, confirms mailbox business purpose, and reviews access
quarterly. |
|
Team Member / VA /
Contractor |
Uses only authorized
access, does not request passwords, does not export confidential content,
follows folder/category rules, and escalates unusual or sensitive messages. |
|
Compliance / Finance
Reviewer |
Reviews sensitive inboxes
such as finance, legal, notices, compliance, and HR when required. |
All shared
mailboxes must use a clear, department-based or brand-based naming format. The
display name should make the mailbox easy to identify in Outlook, Power
Automate, and administrative screens.
|
Mailbox Type |
Recommended Format |
Example |
|
Parent Company Hub |
LIHG - [Department] |
LIHG - Sales |
|
Brand Department |
[Brand] - [Department] |
Fortune Publishing Group -
Sales |
|
Central Intake |
LIHG - Hub Intake |
LIHG - Hub Intake |
|
Sensitive Department |
LIHG - [Department] Secure |
LIHG - Finance Secure |
|
Event / Campaign Mailbox |
LIHG - [Campaign or Event] |
LIHG - Get Biz Credit
Workshop |
Recommended
enterprise examples include: info@, sales@, support@, hr@, finance@,
compliance@, legal@, media@, pr@, partnerships@, grants@, podcast@, events@,
clientsuccess@, billing@, notices@, vendors@, and executiveadmin@. Sensitive
inboxes should have the smallest practical access group.
·
Do not create shared mailbox passwords for team
use. Shared mailbox access must occur through each approved user’s own
Microsoft 365 login.
·
Do not allow a VA, contractor, or staff member
to access Max Fortune’s personal mailbox unless specifically approved and
documented. Use delegated shared mailbox access instead.
·
Do not forward sensitive mail to personal Gmail,
Yahoo, or non-LIHG accounts unless executive leadership has approved the
workflow in writing.
·
Use least-privilege access. Grant only the
permissions required for the person’s actual duties.
·
Separate access by department. A person who
handles event inquiries should not automatically receive finance, HR,
compliance, or legal mailbox access.
·
Review access at least quarterly and immediately
upon termination, role change, vendor change, or suspected compromise.
Use this
procedure when creating a new Microsoft 365 shared mailbox from the Microsoft
365 Admin Center.
1. Sign
in to the Microsoft 365 Admin Center using an account with the Exchange
Administrator or Global Administrator role.
2. In
the left navigation menu, select Show all if the full menu is not visible.
3. Select
Teams & groups.
4. Select
Shared mailboxes.
5. Select
Add a shared mailbox.
6. Enter
the display name using the approved naming standard. Example: LIHG - Sales.
7. Enter
or confirm the shared email address. Example: sales@reimagineitinc.org or
sales@approvedbranddomain.com.
8. Select
Save changes.
9. Allow
several minutes for Microsoft 365 to provision the mailbox before adding
members or testing access.
10. Open
the newly created mailbox record and confirm that sign-in is blocked. Do not
enable direct sign-in for normal shared mailbox use.
Membership and
permissions must be assigned deliberately. A user may need read/manage access
only, send access only in limited cases, or both read/manage and Send As access
depending on the role.
11. Open
Microsoft 365 Admin Center.
12. Go
to Teams & groups > Shared mailboxes.
13. Select
the shared mailbox to configure.
14. Under
Members, select Edit or Add members.
15. Add
only the approved users listed by the mailbox owner or executive administrator.
16. Under
Manage mailbox permissions, assign the correct permissions: Read and manage /
Full Access, Send As, or Send on Behalf.
17. For
ordinary team inbox handling, assign Read and manage / Full Access. Add Send As
only if the user is authorized to reply from the mailbox address.
18. Save
the changes and record the approved access in the mailbox access log.
19. Allow
up to 60 minutes for permissions to propagate before treating failed access as
an error.
|
Permission |
Use When |
Risk Control |
|
Read and Manage / Full
Access |
The user must read,
organize, process, archive, categorize, or move messages. |
Does not allow sending by
itself; review deletion privileges carefully. |
|
Send As |
The user must send
messages where the mailbox appears as the direct sender. |
Limit to trained staff;
inappropriate use can create brand, legal, or client confusion. |
|
Send on Behalf |
The user should be visibly
identified as sending on behalf of the mailbox. |
Useful when transparency
is required; not ideal for standardized customer-service replies. |
Use Exchange
Admin Center when a more detailed delegation review is needed or when Microsoft
365 Admin Center permission screens do not display the needed options.
20. Open
the Exchange Admin Center.
21. Go
to Recipients > Mailboxes.
22. Select
the shared mailbox.
23. Select
Edit or open the mailbox details panel.
24. Under
Mailbox permissions, select Manage mailbox delegation.
25. Review
Full Access, Send As, and Send on Behalf permissions.
26. Add
or remove users as approved.
27. Save
changes and update the access log.
After the
administrator grants access, most Microsoft 365 tenants use automapping,
meaning the shared mailbox may appear automatically in Outlook after the user
closes and reopens Outlook.
28. Close
Outlook completely.
29. Reopen
Outlook and sign in with your personal company Microsoft 365 account.
30. Look
in the left folder pane for the shared mailbox display name. Example: LIHG -
Sales.
31. Expand
the shared mailbox to view Inbox, Sent Items, Drafts, Deleted Items, Calendar,
and any configured folders.
32. If
the mailbox does not appear after 60 minutes, notify IT and include the mailbox
name, your user email address, date/time tested, and a screenshot of the
Outlook folder pane.
33. Go
to Outlook on the Web and sign in using your own company Microsoft 365 account.
34. In
the left folder pane, right-click Folders or your mailbox name.
35. Select
Add shared folder or mailbox.
36. Enter
the shared mailbox address or display name.
37. Select
Add.
38. Confirm
that the shared mailbox appears in the folder list.
39. Open
the mailbox and process messages only according to the assigned folder,
category, and response rules.
40. Open
the Outlook mobile app.
41. Tap
the profile or mailbox icon in the upper-left corner.
42. Tap
Add Mail Account or the plus sign, depending on the app version.
43. Select
Add Shared Mailbox.
44. Choose
your company Microsoft 365 account if prompted.
45. Enter
the shared mailbox address.
46. Tap
Add Shared Mailbox and confirm it appears in the mailbox list.
Mobile access
should be limited for sensitive mailboxes such as finance, legal, HR, notices,
and compliance unless business necessity has been approved.
47. Confirm
that you have Send As or Send on Behalf permission. Full Access alone does not
permit sending.
48. Open
a new email or reply to an email from the shared mailbox.
49. Show
the From field if it is not visible.
50. Select
the shared mailbox address from the From dropdown or type the shared mailbox
address.
51. Confirm
the correct From address before sending.
52. Use
the approved signature block, tone, disclaimer, and response template for the
department or brand.
53. Do
not send legal, financial, contractual, refund, compliance, HR, or
sponsor-related responses unless authorized for that category.
Shared
mailboxes must use a consistent folder and category system so messages can be
routed, tracked, and reviewed by team members without confusion.
|
Folder Category |
Purpose |
Examples |
|
00_New / Unprocessed |
Messages not yet reviewed
or assigned. |
New inquiries, unopened
replies, general intake. |
|
10_Intake |
Messages requiring routing
to a department or workflow. |
Sales lead, vendor
inquiry, event invitation. |
|
20_Action Required |
Messages that require a
response or task creation. |
Client question, billing
request, podcast booking inquiry. |
|
30_Waiting / Pending |
Messages awaiting
third-party response, internal review, or document return. |
Awaiting client form,
awaiting executive approval. |
|
40_Completed / Closed |
Messages fully handled and
no longer active. |
Answered support request,
completed invoice request. |
|
50_Archive |
Reference messages
retained for business history or compliance. |
Contracts, confirmations,
notices, long-term records. |
|
Sensitive - Restricted |
Messages requiring limited
access. |
HR, legal, finance,
compliance, tax, personal data. |
Team members
must not create random folders without approval. Folder creation affects
automation, search, retention, and training consistency.
·
Do not delete messages unless the mailbox owner
has authorized deletion procedures. Move completed items to the approved folder
instead.
·
Do not mark an item completed unless all
required action has been finished or assigned in UHD / CRM / task management
system.
·
Do not respond from a shared mailbox using
personal language, emojis, casual tone, or statements outside approved
authority.
·
Do not open suspicious attachments or links.
Report phishing or malware concerns immediately.
·
Do not forward client documents, financial data,
contracts, or personal information to unauthorized recipients.
·
Do not change rules, automations, signatures,
folder structures, or forwarding settings unless specifically assigned to do
so.
·
Document any major issue, unusual client
complaint, legal threat, payment dispute, refund request, or media inquiry in
the approved internal tracking system.
All access
requests must follow a documented approval path.
54. Requesting
manager identifies the mailbox, user, role, business reason, and required
permission level.
55. Mailbox
owner approves or denies access.
56. For
HR, finance, legal, compliance, executive, and notices mailboxes, executive
approval is required before access is granted.
57. IT
assigns the approved permissions and records the date, requester, approver,
mailbox, permission level, and review date.
58. The
user receives access instructions and must acknowledge the confidentiality and
usage rules before processing messages.
Access removal
must be immediate when a team member, contractor, VA, or vendor no longer needs
mailbox access.
59. Manager
notifies IT of the termination, role change, vendor change, or access removal
request.
60. IT
removes the user from shared mailbox membership and all mailbox delegation
permissions.
61. IT
confirms removal of Full Access, Send As, and Send on Behalf permissions.
62. IT
verifies whether the user also had Power Automate, Outlook rules, forwarding,
Teams, Slack, or CRM access tied to the mailbox.
63. Mailbox
owner reviews recent sent messages and pending drafts for continuity.
64. IT
logs the access removal date and confirms completion to the approving manager.
|
Test Item |
Expected Result |
Pass/Fail |
|
Mailbox appears in
Microsoft 365 Admin Center |
Shared mailbox record
exists with correct display name and email address. |
|
|
Sign-in blocked |
Direct sign-in remains
blocked for the shared mailbox account. |
|
|
User has Full Access |
Approved user can open and
manage the mailbox from Outlook. |
|
|
User has Send As if
approved |
Approved user can send
from the shared mailbox address. |
|
|
Unauthorized user blocked |
A non-approved user cannot
open the mailbox. |
|
|
Folder structure visible |
Approved folders appear
and can be used by assigned users. |
|
|
Signature tested |
Outgoing message uses
approved signature and brand identity. |
|
|
Mobile access tested if
approved |
User can access shared
mailbox on Outlook mobile only if authorized. |
|
|
Audit log updated |
Access log reflects
mailbox, user, permissions, approver, and date. |
|
|
Problem |
Likely Cause |
Corrective Action |
|
Mailbox does not appear in
Outlook Desktop |
Automapping delay or
Outlook has not restarted. |
Wait up to 60 minutes,
restart Outlook, then test Outlook on the Web. |
|
User can read but cannot
send |
Full Access was granted,
but Send As or Send on Behalf was not granted. |
Administrator must add the
proper sending permission. |
|
Send As error appears
after setup |
Microsoft 365 permission
propagation delay. |
Wait up to 60 minutes,
then retest. |
|
Mailbox appears for some
users but not others |
Permissions were assigned
individually for some users or not fully propagated. |
Review membership and
delegation settings in Microsoft 365 Admin Center and Exchange Admin Center. |
|
Too many users experience
syncing issues |
Shared mailbox may have
too many concurrent users. |
Reduce access, create
department groups, or consider Microsoft 365 Group architecture. |
|
Messages are missing or
deleted |
A member moved or deleted
content. |
Check folder history,
Deleted Items, Recover Deleted Items, and access log. Reinforce no-deletion
rule. |
|
Shared mailbox exceeds
storage limit |
Mailbox reached storage
threshold or has retention/archive needs. |
Review licensing,
archiving, retention, and cleanup requirements. |
65. Export
or document all shared mailboxes from Microsoft 365 Admin Center.
66. For
each mailbox, list all users with Full Access, Send As, and Send on Behalf
permissions.
67. Confirm
each user still has a valid business need.
68. Remove
inactive, unnecessary, or unauthorized users.
69. Review
sensitive mailbox access separately for HR, finance, legal, compliance,
notices, executive administration, and sponsor/investor communications.
70. Confirm
sign-in remains blocked for shared mailbox accounts.
71. Confirm
folder structure, rules, signatures, and forwarding settings have not been
modified without approval.
72. Save
the audit record in the approved LIHG IT governance folder using the official
file naming convention.
|
Field |
Description |
|
Mailbox Display Name |
Official display name of
the shared mailbox. |
|
Email Address |
Primary mailbox email
address. |
|
Department / Brand |
Business area responsible
for the mailbox. |
|
User Name |
Approved user or team
member. |
|
User Email |
User’s individual
Microsoft 365 account. |
|
Permission Type |
Full Access, Send As, Send
on Behalf, or combination. |
|
Business Reason |
Why access is needed. |
|
Approver |
Manager or executive who
approved access. |
|
Date Granted |
Date access was assigned. |
|
Review Date |
Next required access
review date. |
|
Date Removed |
Date access was removed,
if applicable. |
|
Notes |
Any special restrictions
or escalation rules. |
Shared mailbox
access is a business privilege and must be used only for authorized LIHG
operations. Team members may encounter confidential business information,
client information, financial details, personal data, contracts, legal notices,
account credentials, vendor records, internal strategy, and sensitive
communications. Unauthorized access, forwarding, copying, downloading,
deletion, or disclosure is prohibited.
All team
members must use approved company systems and must not move shared mailbox
content into personal storage locations. Any suspected unauthorized access,
phishing attempt, mistaken disclosure, or sensitive-message handling issue must
be escalated immediately to the mailbox owner and IT administrator.
·
Mailbox name and email address follow the
approved naming standard.
·
Mailbox purpose, owner, and department are
documented.
·
Direct sign-in is blocked.
·
Only approved users have access.
·
Permission type matches business need.
·
Sensitive mailboxes have restricted access and
executive approval.
·
User can access mailbox through Outlook Desktop,
Outlook on the Web, or Outlook Mobile as approved.
·
User understands sending rules, folder rules,
and confidentiality obligations.
·
Access log is updated.
·
Quarterly audit date is scheduled.
Microsoft
Learn, “Create a shared mailbox,” updated February 3, 2026. Key source points
used: shared mailboxes allow a group to monitor and send from a common address;
Microsoft 365 Admin Center path includes Teams & groups > Shared
mailboxes; Full Access, Send As, and Send on Behalf have distinct functions;
permissions may require propagation time.
Microsoft
Learn, “About shared mailboxes in Microsoft 365,” updated March 13, 2026. Key
source points used: licensing and storage limits, access and permissions,
internal user access, blocked sign-in requirement, no direct shared mailbox
password usage, mobile support, and maximum-user considerations.
Microsoft
Learn, “Give mailbox permissions to another user,” updated December 18, 2025.
Key source points used: deciding permission actions, Microsoft 365 Admin Center
permission paths, and propagation timing.
LIHG Governance
Source Files: LIHG Master System Prompt, AI Production Directive, AI Agent
Behavioral Framework, Governance Charter, Brand & Communication Standards,
Enterprise Workflow & Document Creation Protocol, Legal & Compliance
Governance Manual, and Multi-Brand Content Governance Manual.