One account, six people, password on a card by the till. It is the most common thing we find in small businesses, and it is always a decision that made sense on the day. The cost shows up later, in places nobody connects back to it.
It is the single most common thing we find in small businesses. The office staff have proper accounts. Everyone else, the warehouse, the workshop, the fitters, the weekend staff, shares one login. Sometimes it is info@. Sometimes it is the owner's own account. Sometimes it is a former employee's account that was never closed because the password is written on a card by the terminal.
Nobody did this because they are careless. They did it because licences look like a cost with no obvious return, and one shared account solved the problem on the day. It is a rational decision made with incomplete information. Here is the information.
This is the one that costs money, and it is not really about hacking.
A customer disputes an order. A price was changed. A file went missing. A rude email went out. With individual accounts, you look at the audit log and you know. With a shared account, you have six people and one name, and the honest answer to any question is a shrug.
The same applies in the other direction, which matters more than people expect. If a member of staff is accused of something they did not do, a shared login means you cannot clear them either.
You cannot sensibly put multi-factor authentication on an account that six people use. Whose phone gets the prompt? What happens on a Saturday when that person is off?
So MFA gets left off, and the shared account becomes the way in. It is the account with the weakest password, the most people who know it, the highest chance of it being written down, and the least chance of anyone noticing an unusual sign-in.
Since April 2026 this has a direct commercial consequence as well. Under the current Cyber Essentials requirements, multi-factor authentication has to be enabled everywhere it is available, and a missing one is an automatic fail rather than a mark against you. If you are bidding for public sector work or sitting in a larger company's supply chain, a shared login is now a certification problem, not just a security one.
Cyber insurance applications and larger customers' supplier questionnaires now routinely ask whether every user has their own account and whether MFA is enforced. Answering honestly is awkward. Answering optimistically is worse, because it is the answer that gets checked when you claim.
When someone leaves and they were on a shared login, you have two choices. Change the password and disrupt everybody, or do nothing. Most people do nothing, and reason that they were fine, they would not do anything.
That leaves a former employee with working access to your systems for as long as that password stands. Our offboarding checklist is useless in a shared login environment, because there is nothing to switch off.
Here is the bit that changes the decision. Most owners are comparing a shared login against a full Microsoft 365 licence at the price they pay for their office staff. That is not the right comparison, because a warehouse operative does not need what an accounts manager needs.
Microsoft sells frontline licences aimed exactly at this: staff who do not sit at a desk, who mostly need email, Teams and web access rather than the full desktop apps. They cost a fraction of a full business licence. For a lot of shop floor and site staff, that is genuinely all they use.
Two other things are free, which almost nobody realises:
So the real comparison is usually not "one free shared account versus six full licences". It is "one shared account versus a shared mailbox that costs nothing, plus a handful of frontline licences". That is a much smaller number than people are braced for.
Worth checking your current position before you budget, because Microsoft changed its commercial pricing on 1 July 2026 and not every plan moved the same way. Check the current figures on Microsoft's own pricing pages rather than trusting anything you read in an article, including this one.
You do not need to do this all at once, and doing it all at once is usually how it stalls.
Done in that order, most small businesses are through it in a couple of weeks with very little disruption, and the bill goes up by less than they expected.
Microsoft's licensing terms expect a licence to be assigned to a named person rather than passed around a group. Beyond the licensing question, shared logins break your audit trail, make multi-factor authentication impractical and fail Cyber Essentials.
Microsoft's frontline licences are built for staff who do not work at a desk and cost a fraction of a full business licence. Check current pricing on Microsoft's own pages, as commercial pricing changed on 1 July 2026.
No. That is what a shared mailbox is for, and it does not need its own licence. Each person signs in as themselves and the shared inbox appears alongside their own, with the audit log still showing who replied.
Not if it is done in stages. Convert shared mailboxes first, then give individual accounts to anyone handling customer data or money, then work through the rest. Most small businesses are through it in a couple of weeks.
A Security Health Check reviews nine areas including accounts and MFA, and gives you a plain English traffic light report for a fixed price.
See the Security Health CheckMore in this series: all Klariq guides.