Purpose: Enabling Secure Collaboration Gateway for Shared Mailboxes will allow users to send Secure Mail from a shared mailbox address. To enable the feature, an M365 admin will need to provide consent to eShare’s Outlook API.
Login to Cloud Web Portal with an eShare administrator account. (Your M365 account should have at minimum application administrator role)
Navigate to Manage Organization > Corporate Cloud Providers and turn ON the “Provide consent to eShare for Outlook API” option.

Review the requested permissions for your organization presented by Microsoft and select Accept when ready. Also keep a note of the application (highlighted in the blue box) name you have created in the Entra.
Note
Please note that these permissions will be appended to your existing service principal created to connect cloud providers

After accepting the permissions, you should see the option “Get access token” as shown in the screenshot below. Right click on the “Get access token” and copy the link

Paste the copied link in a new tab. It would look similar to the below link. Remove amp; and click enter. If successful, you should get back to the cloud providers page with Outlook API consent ON. Now refresh the page and Get access token would disappear.
Once the token is acquired, the application you named while connecting to cloud providers page (eSHARE Commercial Prod in this example) will need to be added as an Exchange Administrator
Head over to https://portal.azure.com and open the Azure Active Directory Service
Under the “Manage” category, select “Roles and administrators”

8 .Find the “Exchange Administrator” role and open the role. When the assignments page opens, select “Add Assignments” at the top of the page, search for your application, select “Add”
.png?sv=2026-02-06&spr=https&st=2026-10-01T08%3A25%3A16Z&se=2026-10-01T08%3A37%3A16Z&sr=c&sp=r&sig=RDfPZEbSHaKeDS%2F3wFyC2JLRZnMrmgfgw4BPH%2FUKT%2F0%3D)
With the token acquired and the Exchange Admin role assigned to the application, eShare is now able to query Outlook/Office for members of shared mailboxes. Next, we need to create a SharePoint site specifically for Shared Mailboxes, this is where the trusted shares will live when sending a Secured mail from any shared mailbox.
Go to SharePoint Home, then select “Create site”

On the create a site page, choose “Team Site”

Call the site name “SharedMailboxes” and select next. You do not need to add any users to the site, then select Finish.

Now you will need go back to the eShare admin console to finish setting up SMG for Shared Mailboxes.
Next go to the eShare admin console, then go to the Secure email tab.
Under Secure email, enter the site name of the Shared Mailboxes site under “SP site name”, then select Save.

You have now successfully enabled SMG for Shared Mailboxes. Whenever a user sends an email from a shared mailbox, the files will be stored in this SharePoint site in an outbox folder.