Watch for stale shared mailboxes, persistent delegated send permissions, accounts that remain active after role change, and alerts that show unusual sending behaviour from trusted identities. Those signals usually mean the organisation is protecting the inbox but not the identity behind it.
How to recognise when inbox protection is outpacing identity control
Email identity controls lag when the organisation can secure mailbox content but cannot confidently govern who can act as that mailbox over time. Stale shared mailboxes, unresolved delegation, and active accounts after role change all show the identity boundary has drifted away from the inbox boundary. That is usually a lifecycle and authorisation problem, not just an email administration problem.
One practical clue is persistence. If a mailbox still sends on behalf of former owners, keeps delegated send rights long after a business change, or remains usable when the named user has changed role, the control plane is not keeping its inventory current. In identity terms, the account or mailbox may still exist, but its authority no longer matches the current business need. NHIMG’s NHI Lifecycle Management Guide and the Ultimate Guide to NHIs both reinforce the same operational lesson: identity state must be reviewed as a lifecycle, not as a one-time setup.
A second signal is mismatch between trust and behaviour. When alerts show unusual sending patterns from a trusted identity, the mailbox is still being treated as legitimate by systems and people, but the actual use pattern no longer fits its history. That can reflect poor offboarding, weak review cadence, or a compromised identity that still has valid access. Top 10 NHI Issues is useful here because it highlights the broader governance pattern of stale, shared, and overexposed identities.
Why these signs matter beyond mailbox hygiene
These are not cosmetic housekeeping issues. A mailbox that is still authorised after a role change can preserve access to sensitive conversations, vendor threads, invoice flows, or password reset channels long after the original business reason has expired. If delegation is left in place, an apparently trusted identity can become a standing pathway into systems and workflows that were never meant to survive the person’s change in function. The control failure is often hidden because the mailbox continues to work normally.
The most important distinction is between inbox content security and identity authority. Protecting the mailbox does not help if the delegated send rights, shared mailbox membership, or account ownership model is stale. Identity Security Programme Guide and IAM and Identity Provider Buyer's Guide both point to the same governance issue: the identity system has to know who should still be able to act, not just who used to be able to act.
When the organisation sees repeated exceptions, such as manual approvals to keep access alive or delayed removal of shared mailbox rights, that usually indicates the process depends on human memory instead of authoritative lifecycle events. In that situation, unusual sending behaviour is often the last visible symptom, not the root cause. Active Directory and Entra ID Hardening Guide is relevant where delegated access and hybrid identity create multiple places for stale permissions to survive.
What good monitoring should catch before users notice
Good monitoring should tell you when a mailbox or delegated identity has become structurally inconsistent with the business record. That means watching for inactive owners, unused shared mailboxes that still have send capability, delegation that outlives the team it was created for, and identities that keep generating mail after a role or department change. Alerts should not only flag volume spikes, they should also flag authority spikes, such as a trusted identity starting to send in new patterns, new hours, or new business contexts.
The best signal is a joined view of ownership, permission, and behaviour. If the owner changed but the access did not, or the access changed but the ticketing record did not, you have an identity control gap. If the mailbox appears normal in the user interface but behaves abnormally in telemetry, you likely have hidden privilege or delegated use that was never revalidated. Ultimate Guide to NHIs, Regulatory and Audit Perspectives is a useful reference point for auditability, because the same evidence problem appears whenever access persists without a clear governance trail.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Covers stale credentials and access that outlive the intended user state. |
| AC-2 — Account Management | Applies to active accounts, shared mailboxes, and removal after role change. | |
| AC-6 — Least Privilege | Supports limiting delegated send rights to only the access actually needed. | |
| Recommendation — Rotate and revoke mailbox credentials and delegated access when ownership changes. Review, disable, and remove mail accounts when business need ends. Constrain mailbox permissions to the minimum required send and delegate rights. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Identity ownership and lifecycle are central to stale mailbox and delegation issues. |
| A.5.18 — Access rights | Directly addresses lingering delegated rights and unused mailbox permissions. | |
| Recommendation — Maintain authoritative identity records and remove obsolete mailbox authority promptly. Revoke outdated mailbox access rights when roles or ownership change. | ||
Practitioner Guidance
What to prioritise: Start with identities that can still send mail on behalf of others, especially shared mailboxes, service-style mail access, and delegated send rights that lack a recent business owner review. If you only inspect inbox contents, you will miss the underlying authority problem.
What to verify: Confirm that each active mailbox access path has a current owner, a current business purpose, and a current removal trigger. The control is working only if role changes, offboarding, and delegation removal are reflected in the mailbox state quickly enough to prevent lingering authority.
What good looks like: A trusted identity that starts sending differently should be explainable through a documented change, not an exception handled after the fact. The healthiest state is low surprise, where send rights, ownership, and activity patterns all agree.
Practitioner takeaway: Treat unusual sending from trusted identities as a lifecycle failure first and a content-security issue second; if access outlives the role, the organisation has already lost control of the identity boundary.
Related resources from NHI Mgmt Group
- What are the signs that identity and access controls are not keeping pace with financial-sector threats?
- What are the signs that identity controls are not keeping pace with AI-driven threats?
- What are the signs that machine identity controls are not keeping pace with operational expansion?
- What are the signs that a healthcare organisation’s identity security controls are not keeping pace with HIPAA requirements?