Every Microsoft 365 sign-in should belong to one real person. Shared logins such as reception@, accounts@ or a general “office” account feel convenient, but they weaken your security, leave no record of who did what, and usually break Microsoft’s licensing terms.
We see it in almost every new customer we take on. A business starts with a handful of accounts, someone sets up info@yourcompany.co.uk with a password written on a sticky note, and over the years three or four people end up signing in to it. Sometimes the account is named after the job (“reception”, “sales”, “workshop”) so that it can be handed from one employee to the next without any admin.
Microsoft 365 already has proper tools for everything these shared accounts are trying to do. This post explains why the habit is risky and what to use instead.
Shared accounts break multi-factor authentication
Multi-factor authentication (MFA) is the single most effective protection a Microsoft 365 account has, and it only works when the account belongs to one person. MFA relies on something you know (a password) and something you have (your phone, a passkey or a security key). If four people share one account, the “something you have” either sits on one person’s phone, so everyone else has to ask them for the code, or it gets switched off.
In practice, shared accounts are the ones we most often find with MFA disabled, excluded from Conditional Access policies, or protected by a weak password everyone can remember. That makes them the easiest way into your tenant.
Shared passwords also travel. They get written down, texted to a new starter, saved in personal browsers and kept by people who have left. You cannot tell whether a password has leaked when you do not know who has it.
Passkeys and the Microsoft Authenticator app make this sharper still. A passkey is tied to one person’s device and fingerprint or PIN. It is far harder to phish than a password, but it cannot be shared around an office, and nor should it be.
You lose the record of who did what
Microsoft 365 logs almost everything a user does: sign-ins, emails sent, files opened, shared or deleted, and settings changed. Those logs are only useful if each account maps to one person.
With a shared login, every entry reads “reception”. If a customer file is deleted, an invoice email goes to the wrong person or a client’s data is shared outside the business, you cannot say who did it. That matters for:
- Internal disputes, where you need to establish facts fairly rather than guess.
- Security incidents, where you need to know which person’s device or behaviour led to a compromise.
- UK GDPR, which expects you to control and account for access to personal data. “Several of us use that login” is a hard answer to give the ICO after a breach.
- Cyber insurance and Cyber Essentials, both of which ask about individual user accounts and MFA.
Named accounts also protect your staff. When someone is wrongly suspected of a mistake, the audit log can clear them.
Leavers keep access to job-role accounts
Job-role accounts are sold on the idea that they make staff changes easier: the new receptionist simply takes over “reception”. In reality they make leavers harder to deal with.
When a named person leaves, you block their sign-in, and their access ends at that moment. When someone leaves a shared or role account, you have to change the password, re-register MFA and tell everyone else who uses it. That rarely happens on the day, so the leaver can often still sign in weeks later from their own phone or laptop, where the account is still saved.
Role accounts also collect clutter. Each person who uses them adds their own OneDrive files, Teams chats, browser sessions and app sign-ins, and nobody knows which of it still matters. With named accounts, a leaver’s mailbox and OneDrive can be handed to their manager in a controlled way, then retired.
Sharing a licence usually breaks Microsoft’s terms
Microsoft 365 business plans are licensed per user. Each licence is assigned to one person, and that person may install the apps on their own devices. Several people signing in to one licensed account to avoid buying more licences is not permitted, and it can surface in a licensing review.
The better news is that the proper alternative often costs nothing extra. A shared mailbox does not need a licence of its own while it stays under 50 GB, as long as the people who open it each have their own licensed mailbox (Microsoft Learn). It only needs a licence if it grows past 50 GB, needs an online archive, or needs litigation hold (Exchange Online limits).
So converting a shared “accounts” user into a shared mailbox can free up a licence while making the setup more secure.
What to use instead
Each person signs in as themselves, and Microsoft 365 gives them access to the shared resources their job needs. When someone changes role, you change their access, not their login.
| What you need | Use this in Microsoft 365 |
|---|---|
| A team inbox such as info@ or accounts@ | A shared mailbox, with Full Access and Send As granted to the right people |
| An address that forwards to several people | A distribution list or Microsoft 365 group |
| Shared files for a department | A SharePoint site or a Team, with membership controlling access |
| A shared calendar, room or van booking | A shared or resource mailbox |
| A PA or deputy handling someone’s mail | Delegate access to that person’s mailbox |
| A reception PC used by different staff | Each person signs in to Windows with their own account, or a locked-down shared device |
| Emails from a scanner, CRM or website form | A dedicated service setup such as SMTP relay or an app registration, not a person’s login |
Outlook adds shared mailboxes alongside the user’s own inbox automatically, so staff do not have to sign in and out. Emails sent as accounts@ still come from accounts@, and the audit log still records which person sent them.
A quick check for your business
If you answer yes to any of these, it is worth a review:
- Does more than one person know the password to any Microsoft 365 account?
- Is any account named after a job, department or “office” rather than a person?
- Is any account excluded from MFA because “it’s shared”?
- Has a former employee ever used an account that is still active?
- Is a user licence being paid for on an account that only receives email?
Fixing this is usually quick. We convert role accounts into shared mailboxes, give each person their own sign-in with MFA, move files into SharePoint or Teams, and set up any devices that need to send email properly. Staff keep the same email addresses, and in most cases nothing changes for your customers.
If you would like Scanstation Computers to review your Microsoft 365 accounts, get in touch and we will tell you what we find and what it would take to fix.
