Skip to main content

Mon – Fri: 08:00 – 16:00

info@novacloud.africa

NovaCloud Africa

NovaCloud News

Securing Shared Mailboxes with Named Accounts and MFA in M365

Discover how Gauteng SMEs eliminate shared passwords on info@ and accounts@ mailboxes using Microsoft 365 named account delegation and MFA.

5 October 2026 · NovaCloud Africa editorial team

Securing Shared Mailboxes with Named Accounts and MFA in M365 — generated editorial image

Across Gauteng—from busy industrial parks in Midrand to modern office towers in Sandton and executive suites in Highveld, Centurion—one operational habit continues to quietly undermine corporate security. It is the shared mailbox password. Whether it is accounts@company.co.za, orders@company.co.za, or info@company.co.za, dozens of South African firms still have three, five, or ten employees signing into the exact same email account using a single shared password.

While shared inboxes are essential for handling high-volume operational workflows, logging directly into them with a shared password creates a massive blind spot in your identity baseline. It completely circumvents Multi-Factor Authentication (MFA), disables individual audit trails, and opens your organisation to credential harvesting. Upgrading your workspace through managed IT services allows you to modernize this legacy setup into a hardened, compliant Microsoft 365 tenant without disrupting daily communication.

The Shared Password Trap in Gauteng SMEs

In many growing firms, shared mailboxes evolve organically. What starts as a simple setup for two founders dealing with incoming enquiries quickly grows into a central mailbox used by finance, sales, or logistics teams. To give new staff access, administrators often take the path of least resistance: distributing the account password.

This practice introduces several operational and security hazards:

  • Bypassing MFA Safeguards: Because standard MFA apps prompt a specific smartphone during login, firms using shared passwords frequently disable MFA on these general accounts to avoid constant internal phone calls asking for verification codes.
  • Zero Audit Accountability: When an email is permanently deleted, an invoice modified, or a suspicious link clicked from within a shared login, Azure AD (Microsoft Entra ID) unified logs cannot identify which individual performed the action.
  • Uncontrolled Offboarding Risks: When an employee leaves the company, revoking their access requires changing the shared password and redistributing it to every remaining team member—a process that is rarely executed consistently.

Why Direct Logins Breach Identity Governance and POPIA

Under South Africa’s Protection of Personal Information Act (POPIA) Section 19, businesses are legally required to establish and maintain reasonable technical and organisational measures to safeguard personal information. Shared mailboxes regularly process sensitive personal data, including customer identity numbers, bank details, and payment confirmations.

When staff access personal data via shared credentials, your firm cannot prove strict access control or produce clean audit evidence during an Information Regulator enquiry. According to security recommendations on Microsoft Learn, shared mailboxes in Microsoft 365 are explicitly engineered to run without direct interactive sign-in licenses or shared passwords.

Maintaining shared credentials exposes your organisation to severe compliance liabilities. Reviewing your company's alignment with our POPIA governance framework can help identify where unauthenticated access pathways exist in your tenant.

Converting Shared Inboxes to Delegated Named Access

Modernising your operational mailboxes does not require changing how your team collaborates. Instead, Microsoft 365 allows administrators to convert traditional user accounts into dedicated Shared Mailboxes accessed entirely through delegated permissions.

Here is how a structured migration eliminates shared passwords while preserving full operational visibility:

  1. Convert the Mailbox Baseline: Convert the existing user mailbox into a Microsoft 365 Shared Mailbox in the Exchange Admin Center. This action releases the paid user licence while retaining all historical emails and folder structures.
  2. Block Direct Interactive Sign-In: Disable direct login capability on the shared mailbox account and reset its master password to a complex string. No user will ever sign directly into this identity again.
  3. Assign Named User Delegation: Grant specific employees explicit 'Full Access' (Read and Manage) and 'Send As' permissions through their own individual, named Microsoft 365 user accounts.
  4. Enforce Individual MFA and Conditional Access: Every team member accesses the shared inbox using their personal business credentials, which are protected by mandatory MFA and Azure AD Conditional Access policies.

By implementing delegated access, any email sent or managed within accounts@ or sales@ is automatically stamped with the named identity of the staff member responsible. For firms navigating complex tenant setups, engaging expert guidance for an M365 migration in South Africa ensures seamless execution without downtime.

Real-World Scenario: Securing a Centurion Logistics Hub

A mid-sized freight and logistics firm headquartered in Highveld, Centurion, relied on a central dispatch@ mailbox managed by seven shift controllers. To keep operations running across 24-hour schedules, all controllers shared the mailbox password. MFA had been turned off because verification codes were directed to an operations manager's personal mobile phone.

To resolve this security gap, NovaCloud Africa restructured the firm's identity architecture:
  • The dispatch@ account was converted into a zero-licence Shared Mailbox with direct sign-in disabled.
  • All seven controllers were assigned individual Microsoft 365 Business Premium licences, securing their primary logins with authenticator-based MFA.
  • Explicit delegate permissions were established, enabling controllers to open dispatch@ side-by-side with their personal inboxes in Outlook and web browsers.

When a night-shift staff member unexpectedly resigned two months later, NovaCloud’s automated offboarding workflow revoked their named Azure AD identity in seconds. Access to the dispatch mailbox was immediately terminated without needing to change passwords or disrupt the remaining six controllers on duty.

Enforcing Zero-Trust MFA Across Your Microsoft 365 Tenant

Remediating shared mailboxes is a critical step in establishing a Zero-Trust security posture across your enterprise. Once direct sign-ins are blocked on general inboxes, your IT leadership can enforce consistent Conditional Access policies across all named accounts.

"Security is never about making work harder for your team; it is about eliminating unmonitored pathways so your business can operate with total confidence."

With structured identity governance, every employee sign-in is evaluated based on real-time risk factors, including user location, device compliance, and network health. If your firm operates across multiple Gauteng sites or supports hybrid working, robust cybersecurity and POPIA compliance controls ensure that unauthorized connections are blocked automatically before reaching your data environment.

Streamlining M365 Operations with NovaCloud Africa

Managing Microsoft 365 licensing, tenant identity, and security protocols requires continuous, practical oversight. As a trusted digital transformation partner based in Centurion, NovaCloud Africa helps South African organisations clean up legacy configurations, reduce redundant licence costs, and enforce ironclad security baselines.

Whether you need to audit your current identity footprint, transition away from shared logins, or optimize your cloud environment, our team delivers modern, business-first solutions. Explore our specialized managed IT operations in Centurion or contact our technical team directly to secure your workspace.

Secure Your Shared Mailboxes and Modernise Your Tenant

Eliminate shared passwords, enforce MFA, and streamline your Microsoft 365 operations with NovaCloud Africa. Contact our Centurion engineering team today. Talk to NovaCloud.

Prefer the primary texts over a blog paraphrase: Create a shared mailbox - Microsoft 365 admin and Information Regulator South Africa.

Frequently asked questions

Straight answers for decision-makers evaluating IT partners in South Africa.

Do shared mailboxes in Microsoft 365 require a paid user licence?

No. Standard Microsoft 365 Shared Mailboxes do not require a paid licence as long as storage remains under 50GB and no direct sign-in is required. Users access the shared inbox using their existing paid named user licences.

How do team members access a shared mailbox without a password?

Administrators grant 'Full Access' and 'Send As' delegate permissions to individual named user accounts in Azure AD/Exchange. The shared mailbox then appears automatically in the user's Outlook client or web interface, secured by their primary login and MFA.

Does delegating access to a shared mailbox help with POPIA compliance?

Yes. Delegating access ensures that every action taken within a shared mailbox is attributed to an individual, named user. This creates clear audit trails required by Section 19 of POPIA.

What happens to a shared mailbox when an employee leaves the company?

When an employee leaves, revoking their primary Microsoft 365 user account instantly cuts off their access to all delegated shared mailboxes. There is no need to change shared passwords or reconfigure access for remaining staff.

Tags

  • Microsoft 365 managed services
  • m365 migration south africa
  • azure ad
  • shared mailbox mfa
  • gauteng managed it
  • teams telephony
  • South Africa
  • Gauteng
  • Centurion
  • managed IT South Africa

More from NovaCloud News

Customised for your space.

Designed around your business.

Connect with us