Home  /  Guides  /  Why Shared Logins Cost More Than a Licence
O365 Admin

Why shared logins cost more than buying a licence

One account, six people, password on a card by the till. It is the most common thing we find in small businesses, and it is always a decision that made sense on the day. The cost shows up later, in places nobody connects back to it.

It is the single most common thing we find in small businesses. The office staff have proper accounts. Everyone else, the warehouse, the workshop, the fitters, the weekend staff, shares one login. Sometimes it is info@. Sometimes it is the owner's own account. Sometimes it is a former employee's account that was never closed because the password is written on a card by the terminal.

Nobody did this because they are careless. They did it because licences look like a cost with no obvious return, and one shared account solved the problem on the day. It is a rational decision made with incomplete information. Here is the information.

You cannot tell who did what

This is the one that costs money, and it is not really about hacking.

A customer disputes an order. A price was changed. A file went missing. A rude email went out. With individual accounts, you look at the audit log and you know. With a shared account, you have six people and one name, and the honest answer to any question is a shrug.

The same applies in the other direction, which matters more than people expect. If a member of staff is accused of something they did not do, a shared login means you cannot clear them either.

Multi-factor login stops being possible

You cannot sensibly put multi-factor authentication on an account that six people use. Whose phone gets the prompt? What happens on a Saturday when that person is off?

So MFA gets left off, and the shared account becomes the way in. It is the account with the weakest password, the most people who know it, the highest chance of it being written down, and the least chance of anyone noticing an unusual sign-in.

Since April 2026 this has a direct commercial consequence as well. Under the current Cyber Essentials requirements, multi-factor authentication has to be enabled everywhere it is available, and a missing one is an automatic fail rather than a mark against you. If you are bidding for public sector work or sitting in a larger company's supply chain, a shared login is now a certification problem, not just a security one.

The insurance question

Cyber insurance applications and larger customers' supplier questionnaires now routinely ask whether every user has their own account and whether MFA is enforced. Answering honestly is awkward. Answering optimistically is worse, because it is the answer that gets checked when you claim.

Leavers become impossible

When someone leaves and they were on a shared login, you have two choices. Change the password and disrupt everybody, or do nothing. Most people do nothing, and reason that they were fine, they would not do anything.

That leaves a former employee with working access to your systems for as long as that password stands. Our offboarding checklist is useless in a shared login environment, because there is nothing to switch off.

The licence maths people have not seen

Here is the bit that changes the decision. Most owners are comparing a shared login against a full Microsoft 365 licence at the price they pay for their office staff. That is not the right comparison, because a warehouse operative does not need what an accounts manager needs.

Microsoft sells frontline licences aimed exactly at this: staff who do not sit at a desk, who mostly need email, Teams and web access rather than the full desktop apps. They cost a fraction of a full business licence. For a lot of shop floor and site staff, that is genuinely all they use.

Two other things are free, which almost nobody realises:

So the real comparison is usually not "one free shared account versus six full licences". It is "one shared account versus a shared mailbox that costs nothing, plus a handful of frontline licences". That is a much smaller number than people are braced for.

Worth checking your current position before you budget, because Microsoft changed its commercial pricing on 1 July 2026 and not every plan moved the same way. Check the current figures on Microsoft's own pricing pages rather than trusting anything you read in an article, including this one.

How to get off shared logins without a project

You do not need to do this all at once, and doing it all at once is usually how it stalls.

  1. List who actually shares what. Not who is supposed to. Who does.
  2. Split off the mailboxes first. Turn any shared account that exists purely to receive email into a proper shared mailbox. This is free, quick, and removes the most common reason for sharing.
  3. Give individual accounts to anyone who touches customer data or money. If you only do one group, do this one.
  4. Work out the right licence for everyone else rather than defaulting to the plan your office staff are on.
  5. Turn MFA on as you go, account by account, rather than announcing a big switch-on day that everybody dreads.
  6. Close the old shared account properly once nothing depends on it. Do not just leave it sitting there disabled and forgotten.

Done in that order, most small businesses are through it in a couple of weeks with very little disruption, and the bill goes up by less than they expected.

Common questions

Is a shared Microsoft 365 login actually against the rules?

Microsoft's licensing terms expect a licence to be assigned to a named person rather than passed around a group. Beyond the licensing question, shared logins break your audit trail, make multi-factor authentication impractical and fail Cyber Essentials.

What is the cheapest way to give warehouse or site staff email?

Microsoft's frontline licences are built for staff who do not work at a desk and cost a fraction of a full business licence. Check current pricing on Microsoft's own pages, as commercial pricing changed on 1 July 2026.

We only share the account so everyone can see info@. Do we need licences for that?

No. That is what a shared mailbox is for, and it does not need its own licence. Each person signs in as themselves and the shared inbox appears alongside their own, with the audit log still showing who replied.

Will moving off shared logins disrupt the team?

Not if it is done in stages. Convert shared mailboxes first, then give individual accounts to anyone handling customer data or money, then work through the rest. Most small businesses are through it in a couple of weeks.

Not sure what you are actually paying for?

A Security Health Check reviews nine areas including accounts and MFA, and gives you a plain English traffic light report for a fixed price.

See the Security Health Check

Tags: Microsoft 365 · Licensing · Cyber Essentials · MFA · UK SME

More in this series: all Klariq guides.