Fix: Unable to Add Senders to Exchange Mail-Enabled Security Group
Question details
The user is unable to add new approved senders to a specific mail-enabled security group using Delivery Management or Exchange Online PowerShell.

- Product
- Exchange Online
- Device & OS
- not provided
- Scenario
- Attempting to update the approved senders list for a mail-enabled security group in a fully cloud-based Microsoft 365 environment.
- Observed behavior
- The system fails to add the senders for one specific group, returning an error, while other groups may remain unaffected.
Ensure you have Exchange Administrator or Global Administrator privileges in your Microsoft 365 tenant and possess active access to both the Exchange admin center and Exchange Online PowerShell.
Diagnose Group Configuration and Permissions
Verify the exact errors and the group's properties to identify potential object-level corruption or configuration issues.
When an issue is isolated to a single group in a fully cloud-based environment, the problem usually stems from a corrupted group object or misconfigured ownership attributes.
Attempt to add the sender in both the Exchange admin center (EAC) and via Exchange Online PowerShell, and copy the specific error codes returned.
Navigate to the group settings in the EAC and ensure your administrator account is properly listed as an owner of the mail-enabled security group.
Check the recipient configuration of the affected group against another mail-enabled security group that functions correctly in your tenant.
Log in with a different Global Admin or Exchange Admin credential to rule out session or account-specific permission issues.

Recreate the Mail-Enabled Security Group
If the issue is isolated to a single group and backend corruption is confirmed, recreating the group can quickly bypass the problem.
Manage Your IT Documentation with WPS Office
While troubleshooting Exchange Online and network administration issues, use WPS Office to accurately document your procedures, error logs, and group policies. It is a free, lightweight suite offering robust performance and high compatibility with standard document formats.
- 1. Download WPS Office: Visit the official WPS website to download the free installation package for your operating system.
- 2. Install the Software: Run the installer and follow the on-screen prompts to set up the suite on your device.
- 3. Document Your Troubleshooting: Open WPS Writer or Spreadsheet to start logging your Exchange PowerShell scripts, group configurations, and error codes.

Frequently Asked Questions
Why can I modify other groups but not this specific mail-enabled security group?
This typically indicates corruption or a synchronization error specific to that single group's object within Microsoft Entra ID (formerly Azure AD) or Exchange Online.
Can I use Exchange Online PowerShell to bypass EAC graphical interface errors?
Yes, sometimes the Exchange admin center interface experiences temporary glitches. Using the Set-DistributionGroup cmdlet in PowerShell can force the update or provide a more detailed error message for troubleshooting.
What should I do if recreating the group is not a viable option?
If the group is tied to critical access controls, SharePoint sites, or legacy systems, you should open a support request with Microsoft 365 support from your admin portal so they can repair the backend object directly.




