
Why Sharing a Microsoft 365 Login Costs More Than the License
Here's what's actually happening when a small business shares a single Microsoft 365 account between two or three people. The monthly invoice looks great. The cyber liability policy goes void. And every other system in the stack starts lying about who did what.
That's the trade nobody puts in the spreadsheet.
Sharing M365 accounts is one of the most common and most expensive shortcuts in small-business IT. The cost shows up later, usually all at once, usually when someone least wants to deal with it. So let's walk through what actually breaks when you share, and what to do instead when the underlying problem is real (a kiosk, a shift rotation, a part-time desk, a frontline crew on shared hardware).
What "Sharing an Account" Actually Means
In the wild, account sharing looks like this. Two part-time admins use the same login at the front desk. The shop floor has one M365 user that the four people on shift rotate through. The receptionist's account doubles as the printer's email-to-scan account. The graveyard maintenance crew has a single login on the breakroom terminal.
It works, until it doesn't. Microsoft's licensing terms are clear: each human who accesses M365 services needs an individual license. There are zero exceptions for "we only have three people" or "they're only here twenty hours a week." The policy doesn't bend.
But the licensing problem is the easy one. The harder problems are downstream of it.
What Actually Breaks When You Share
Four things break, in roughly the order you'll find out about them.
1. The audit trail goes blind. Every action in M365 (email sent, file edited, login attempt, permission change, document deleted) gets stamped with a username. Share an account between four people and the log says one user did everything. When something goes wrong (a phishing email forwarded internally, a sensitive file deleted, a download spike right before someone resigns), there is no way to know which person did it. The log is technically intact and operationally useless.
2. Multi-factor authentication breaks down. MFA exists because passwords get stolen. The defense works because only the legitimate user has the second factor (their phone, their security key, their authenticator app). Three people cannot share a phone in any sane way. So shared-account environments quietly disable MFA, or wedge it onto one person's phone and pray nobody else is on shift when she's not. Either way the second factor is now ornamental, and an attacker who steals the password walks straight in.
3. Conditional Access stops making sense. Microsoft's Conditional Access (the system that enforces "no logins from countries we don't operate in," "no logins from unmanaged devices," "step-up auth for admin actions") is built on the assumption that one human equals one identity. Three humans on one identity means the policies you set for the safest user have to apply to all three, or the policies you set for the riskiest user permit the other two. Either way the security model is wrong by design.
4. Cyber insurance walks out the door. This is the one that bites the hardest. Most modern cyber liability policies require individual user accounts with MFA enforced. Some name it explicitly. Most include it as a category in the renewal questionnaire (the section labeled something like "do you enforce least-privilege identity management?"). When you fill that out as "yes" and a breach later reveals shared accounts in production, the insurer can deny the claim. The cost of three M365 licenses is dollars per user per month. The cost of a denied breach claim is six or seven figures. If you do the math on dollars per month versus the worst case, account sharing always loses.
What to Do Instead
Microsoft has thought about every legitimate use case for "more than one human, fewer than [number of humans] licenses." Three patterns cover almost everything.
Device-based licensing for kiosks and shared workstations. When the constraint is genuinely a shared device (a checkout terminal, a kiosk, a back-of-house screen used by whoever's on shift), Microsoft offers per-device licensing through programs like Microsoft 365 Apps for enterprise (device). The license attaches to the computer, not the person. Anyone who logs in gets the apps. Compliant, supported, designed exactly for this case.
Microsoft 365 F3 for frontline workers. F3 is Microsoft's plan for the people who do not sit at a desk all day: warehouse staff, retail workers, field crews, healthcare aides. It runs about a quarter of the price of E3, includes web and mobile versions of Word, Excel, Outlook, Teams, plus Exchange Online and SharePoint, and gives every user their own login. Nobody shares. Nobody pays for tools they do not use. Most of the economics that drive small businesses toward shared accounts disappear the moment F3 is on the table.
Shared device mode through Intune. When the device is shared but each user logs in as themselves (the most common pattern in healthcare, manufacturing, and hospitality), Intune's shared device mode is the right tool. Each shift starts with a clean session. Apps remember nothing user-specific between logins. Cached credentials clear on logout. The hardware is shared; the identities are not.
Pick one of these three. There is a clean answer for every shared-workspace scenario, and none of them require violating Microsoft's terms or your insurer's terms.
What This Looks Like in Practice
If you are running a small business on M365 today and anyone is sharing a login, the playbook is short:
- Audit who is actually sharing what. The list is usually shorter than you think.
- For each shared user, decide which of the three patterns above fits. Most cases land in F3 (frontline workers) or Intune shared device mode (rotating shift workers on the same terminal).
- Migrate the licenses, configure the policies, test the access. A capable MSP can finish this in an afternoon for a typical small business.
- Re-issue your cyber insurance questionnaire honestly. The next renewal will be smoother for it.
The whole transition usually costs less than one billable hour of incident response. And it pays back immediately, because you finally have an audit trail you can trust and an MFA posture that actually works.
The Punchline
Sharing M365 accounts saves money the same way ignoring the check-engine light saves money. The savings are real until they aren't, and when they aren't, they aren't by a lot.
If you are not sure where you stand, or which of the three patterns fits which part of your business, reach out at learnmore@greatservice.com or use our contact form. We will walk through the licensing posture, sort out the legitimate shared-workspace cases, and replace the rest with something that does not put your insurance policy at risk.
Pay the four extra dollars a month. Your insurance underwriter will thank you, and so will whoever has to read your audit log when something goes sideways.