Bus-Factor Report · Guide
The shared mailbox only one person uses
A shared mailbox with one active sender has a bus factor of one. How to find orphaned mailboxes, add a real backup in Microsoft 365, and set delegation rules.
The vendor mailbox problem
Most small firms have a few shared mailboxes: orders@, billing@, info@, ap@. They were set up so the work would not depend on one person. Then, over time, one person became the only one who actually works them.
The mailbox may list five members. It does not matter. If one person sends every reply, knows which vendor threads are open, and files invoices into folders only they understand, the mailbox has a bus factor of one. When they leave or go on vacation, vendors write in and nobody answers. Late fees, missed deliveries, and held shipments follow.
Finding orphaned mailboxes
An orphaned mailbox is one nobody is clearly responsible for: the person who worked it has left, or the only active sender is about to.
Two signals find them without reading any mail. First, who is sending. Mail metadata shows which people send from each shared address and when. A mailbox with one sender in the last 90 days is a likely single point of failure; confirm who else holds access, and one with no sender at all may be abandoned. Second, who has permission. The Microsoft 365 admin center lists the members of each shared mailbox under Teams & groups > Shared mailboxes. Compare that list with your current staff; former employees often linger.
A note on what the Bus-Factor Report can see here: it reads who sends from a shared mailbox, but it cannot see who owns or holds permissions on one, so it marks mailbox ownership as unknown rather than covered. The admin center check above fills that gap.
Adding a second owner
Shared mailboxes do not have owners the way groups do. They have permissions. Full Access lets someone open the mailbox and work in it. Send As lets them send mail that appears to come from the mailbox itself. Send on Behalf shows the mail as sent by the person on behalf of the mailbox. A backup needs Full Access and one of the send permissions, or they can read the vendor's question but not answer it.
In the Microsoft 365 admin center, go to Teams & groups > Shared mailboxes, select the mailbox, and use Manage mailbox permissions to add the backup. Then have the backup send one real reply from the mailbox the same week, so you know it works.
Delegation rules
Permissions solve access. Rules solve responsibility. Write down a few for each shared mailbox.
- A named primary and a named backup, both with Full Access and Send As.
- A response window, such as one business day, that the backup covers when the primary is out.
- A folder structure the whole team understands, not one person's private system.
- An explicit handoff when the primary is away: the backup is told, not left to notice.
- A quarterly check that the permission list still matches your staff list.