logo
search
Others

Fix: Unable to Add Senders to Exchange Mail-Enabled Security Group

Emma BrownEmma Brown Sep 30, 2026 869 views

Question details

The user is unable to add new approved senders to a specific mail-enabled security group using Delivery Management or Exchange Online PowerShell.

Fix: Unable to Add Senders to Exchange Mail-Enabled Security Group
Product
Exchange Online
Device & OS
not provided
Scenario
Attempting to update the approved senders list for a mail-enabled security group in a fully cloud-based Microsoft 365 environment.
Observed behavior
The system fails to add the senders for one specific group, returning an error, while other groups may remain unaffected.
Before you start

Ensure you have Exchange Administrator or Global Administrator privileges in your Microsoft 365 tenant and possess active access to both the Exchange admin center and Exchange Online PowerShell.

Solution 1Recommended

Diagnose Group Configuration and Permissions

Verify the exact errors and the group's properties to identify potential object-level corruption or configuration issues.

When an issue is isolated to a single group in a fully cloud-based environment, the problem usually stems from a corrupted group object or misconfigured ownership attributes.

1
Record the exact error message

Attempt to add the sender in both the Exchange admin center (EAC) and via Exchange Online PowerShell, and copy the specific error codes returned.

2
Verify group ownership

Navigate to the group settings in the EAC and ensure your administrator account is properly listed as an owner of the mail-enabled security group.

3
Compare with a working group

Check the recipient configuration of the affected group against another mail-enabled security group that functions correctly in your tenant.

4
Test with an alternative account

Log in with a different Global Admin or Exchange Admin credential to rule out session or account-specific permission issues.

Diagnose Group Configuration and Permissions
Microsoft 365 Support: If the diagnostic steps confirm the problem is isolated to one group and you cannot fix its properties via PowerShell, consider opening a Microsoft 365 support request to investigate backend sync issues.
Free Microsoft Office alternative

Manage Your IT Documentation with WPS Office

While troubleshooting Exchange Online and network administration issues, use WPS Office to accurately document your procedures, error logs, and group policies. It is a free, lightweight suite offering robust performance and high compatibility with standard document formats.

  1. 1. Download WPS Office: Visit the official WPS website to download the free installation package for your operating system.
  2. 2. Install the Software: Run the installer and follow the on-screen prompts to set up the suite on your device.
  3. 3. Document Your Troubleshooting: Open WPS Writer or Spreadsheet to start logging your Exchange PowerShell scripts, group configurations, and error codes.
Free, lightweight, and powerful Office suite alternativeHigh compatibility with Microsoft Office formats (.docx, .xlsx, .pptx) for sharing IT reportsFamiliar tabbed user interface for seamless workflow migrationBuilt-in PDF tools perfect for securing and archiving technical documentation
microsoft office alternative - wps office

Frequently Asked Questions

Why can I modify other groups but not this specific mail-enabled security group?

This typically indicates corruption or a synchronization error specific to that single group's object within Microsoft Entra ID (formerly Azure AD) or Exchange Online.

Can I use Exchange Online PowerShell to bypass EAC graphical interface errors?

Yes, sometimes the Exchange admin center interface experiences temporary glitches. Using the Set-DistributionGroup cmdlet in PowerShell can force the update or provide a more detailed error message for troubleshooting.

What should I do if recreating the group is not a viable option?

If the group is tied to critical access controls, SharePoint sites, or legacy systems, you should open a support request with Microsoft 365 support from your admin portal so they can repair the backend object directly.