LENOX INTERNATIONAL HOLDINGS GROUP
STANDARD OPERATING PROCEDURE
Team Member Setup and Access for Shared Email Accounts
Microsoft 365 / Outlook Shared Mailbox Operating Procedure
|
Document Control Item
|
Detail
|
|
Document Owner
|
Lenox International
Holdings Group / IT & Operations
|
|
Applies To
|
LIHG, subsidiaries,
brands, team members, contractors, virtual assistants, and approved
administrators
|
|
Primary Systems
|
Microsoft 365 Admin
Center, Exchange Admin Center, Outlook Desktop, Outlook on the Web, Outlook
Mobile
|
|
Version
|
v1.0
|
|
Effective Date
|
May 11, 2026
|
|
Classification
|
Confidential Internal
Operations SOP
|
|
Review Cycle
|
Quarterly or upon
Microsoft 365 configuration changes
|
This SOP
establishes the official LIHG procedure for creating, configuring, securing,
accessing, and managing shared email accounts across the organization. The
purpose is to ensure that departmental and brand-level email communication is
handled through controlled shared mailboxes rather than individual passwords,
uncontrolled forwarding, or personal inbox access.
The procedure
supports centralized intake, proper role-based access, auditability, security,
continuity during staff changes, and consistent email handling across LIHG and
all operating brands.
This SOP
applies to all shared email accounts used for business operations, including
but not limited to info, sales, support, HR, finance, compliance, media, public
relations, partnerships, podcast, events, grants, and executive administration
inboxes.
This SOP covers
setup by an authorized administrator and access by approved team members. It
does not authorize team members to use, request, share, store, or transmit
passwords for shared mailboxes.
This SOP
follows LIHG governance requirements for executive document structure, version
control, secure workflows, professional formatting, and centralized operational
oversight. LIHG governance requires SOPs to include purpose, scope,
responsibilities, procedural steps, and quality-control sections. It also
requires formal naming conventions, version control, and secure storage within
approved LIHG directories.
·
Microsoft guidance confirms that shared
mailboxes are intended for groups of people to monitor and send from a common
email address, such as info@company.com.
·
Microsoft guidance further confirms that shared
mailboxes are not intended for direct sign-in and that sign-in should remain
blocked for the mailbox account.
·
Access must be assigned through user
permissions; the user accesses the shared mailbox by signing into the user’s
own licensed mailbox.
|
Term
|
Definition
|
|
Shared Mailbox
|
A Microsoft 365 mailbox
used by multiple approved users to read, manage, and send email from a common
business address.
|
|
Full Access / Read and
Manage
|
Permission that allows a
user to open, read, organize, delete, and manage mailbox content. It does not
automatically allow sending.
|
|
Send As
|
Permission allowing an
approved user to send email so the recipient sees the shared mailbox as the
sender.
|
|
Send on Behalf
|
Permission allowing an
approved user to send with wording that indicates the message was sent by the
user on behalf of the mailbox.
|
|
Automapping
|
Microsoft 365 behavior
that can automatically display a shared mailbox in Outlook after the user is
granted direct mailbox access.
|
|
Mailbox Owner
|
The department head or
approved manager responsible for business use, access approval, cleanup, and
escalation.
|
|
Mailbox Administrator
|
The IT or Microsoft 365
administrator who creates, configures, secures, and audits the mailbox.
|
|
Role
|
Responsibilities
|
|
LIHG Executive Leadership
|
Approves enterprise
mailbox strategy, sensitive mailbox categories, and major access-control
decisions.
|
|
IT / Microsoft 365
Administrator
|
Creates shared mailboxes,
assigns permissions, blocks sign-in, verifies licensing requirements,
configures delegation, and maintains audit records.
|
|
Department or Brand
Manager
|
Approves who needs access,
defines folder use, confirms mailbox business purpose, and reviews access
quarterly.
|
|
Team Member / VA /
Contractor
|
Uses only authorized
access, does not request passwords, does not export confidential content,
follows folder/category rules, and escalates unusual or sensitive messages.
|
|
Compliance / Finance
Reviewer
|
Reviews sensitive inboxes
such as finance, legal, notices, compliance, and HR when required.
|
All shared
mailboxes must use a clear, department-based or brand-based naming format. The
display name should make the mailbox easy to identify in Outlook, Power
Automate, and administrative screens.
|
Mailbox Type
|
Recommended Format
|
Example
|
|
Parent Company Hub
|
LIHG - [Department]
|
LIHG - Sales
|
|
Brand Department
|
[Brand] - [Department]
|
Fortune Publishing Group -
Sales
|
|
Central Intake
|
LIHG - Hub Intake
|
LIHG - Hub Intake
|
|
Sensitive Department
|
LIHG - [Department] Secure
|
LIHG - Finance Secure
|
|
Event / Campaign Mailbox
|
LIHG - [Campaign or Event]
|
LIHG - Get Biz Credit
Workshop
|
Recommended
enterprise examples include: info@, sales@, support@, hr@, finance@,
compliance@, legal@, media@, pr@, partnerships@, grants@, podcast@, events@,
clientsuccess@, billing@, notices@, vendors@, and executiveadmin@. Sensitive
inboxes should have the smallest practical access group.
·
Do not create shared mailbox passwords for team
use. Shared mailbox access must occur through each approved user’s own
Microsoft 365 login.
·
Do not allow a VA, contractor, or staff member
to access Max Fortune’s personal mailbox unless specifically approved and
documented. Use delegated shared mailbox access instead.
·
Do not forward sensitive mail to personal Gmail,
Yahoo, or non-LIHG accounts unless executive leadership has approved the
workflow in writing.
·
Use least-privilege access. Grant only the
permissions required for the person’s actual duties.
·
Separate access by department. A person who
handles event inquiries should not automatically receive finance, HR,
compliance, or legal mailbox access.
·
Review access at least quarterly and immediately
upon termination, role change, vendor change, or suspected compromise.
Use this
procedure when creating a new Microsoft 365 shared mailbox from the Microsoft
365 Admin Center.
1.
Sign
in to the Microsoft 365 Admin Center using an account with the Exchange
Administrator or Global Administrator role.
2.
In
the left navigation menu, select Show all if the full menu is not visible.
3.
Select
Teams & groups.
4.
Select
Shared mailboxes.
5.
Select
Add a shared mailbox.
6.
Enter
the display name using the approved naming standard. Example: LIHG - Sales.
7.
Enter
or confirm the shared email address. Example: sales@reimagineitinc.org or
sales@approvedbranddomain.com.
8.
Select
Save changes.
9.
Allow
several minutes for Microsoft 365 to provision the mailbox before adding
members or testing access.
10.
Open
the newly created mailbox record and confirm that sign-in is blocked. Do not
enable direct sign-in for normal shared mailbox use.
Membership and
permissions must be assigned deliberately. A user may need read/manage access
only, send access only in limited cases, or both read/manage and Send As access
depending on the role.
11.
Open
Microsoft 365 Admin Center.
12.
Go
to Teams & groups > Shared mailboxes.
13.
Select
the shared mailbox to configure.
14.
Under
Members, select Edit or Add members.
15.
Add
only the approved users listed by the mailbox owner or executive administrator.
16.
Under
Manage mailbox permissions, assign the correct permissions: Read and manage /
Full Access, Send As, or Send on Behalf.
17.
For
ordinary team inbox handling, assign Read and manage / Full Access. Add Send As
only if the user is authorized to reply from the mailbox address.
18.
Save
the changes and record the approved access in the mailbox access log.
19.
Allow
up to 60 minutes for permissions to propagate before treating failed access as
an error.
|
Permission
|
Use When
|
Risk Control
|
|
Read and Manage / Full
Access
|
The user must read,
organize, process, archive, categorize, or move messages.
|
Does not allow sending by
itself; review deletion privileges carefully.
|
|
Send As
|
The user must send
messages where the mailbox appears as the direct sender.
|
Limit to trained staff;
inappropriate use can create brand, legal, or client confusion.
|
|
Send on Behalf
|
The user should be visibly
identified as sending on behalf of the mailbox.
|
Useful when transparency
is required; not ideal for standardized customer-service replies.
|
Use Exchange
Admin Center when a more detailed delegation review is needed or when Microsoft
365 Admin Center permission screens do not display the needed options.
20.
Open
the Exchange Admin Center.
21.
Go
to Recipients > Mailboxes.
22. Select