Skip to main content
MicroNet Global

Managed IT

Microsoft 365 when most of your workforce never sits at a desk

How to licence Microsoft 365 across hotel and restaurant teams, covering frontline worker tiers, shared device sign-in, identity, offboarding and backup.

7 min readBy the MicroNet Global team

Microsoft 365 for hospitality works when licensing follows the job rather than the headcount: head office on knowledge-worker plans, venue teams on frontline licences, and shared devices handled properly. MicroNet Global, a Microsoft Gold Partner supporting 745+ hospitality sites across 15+ countries, designs these tenancies around venue reality rather than office assumptions.

A typical operator has 60 head-office staff living in Outlook and Excel all day, and 1,500 venue staff who need a payslip, a rota, a training module and somewhere to be told the gas is off tomorrow. Licensing the second group like the first is avoidable waste.

What is frontline worker licensing?

Frontline worker licensing is a Microsoft licence category designed for staff who do not work at a dedicated PC: kitchen, floor, housekeeping, reception and bar teams. The F-series plans provide identity, Teams, web and mobile versions of the Office apps and a smaller mailbox, at a fraction of a knowledge-worker plan. Head office keeps E-series or Business plans for full desktop applications.

Microsoft changes plan names, inclusions and prices regularly, so check current Microsoft pricing before building a business case. The principle does not change: pay for capability people actually use.

Licence tiers by role

Map every job title in the group to one of these rows before looking at a single price.

RoleTypical licenceWhat they actually
Finance, marketing and HR at head officeE-series or Business PremiumFull desktop Office, large mailbox, advanced security, device management
Directors and senior operationsE-series or Business PremiumFull Office, mobile access, compliance features, travel-ready devices
General managers and head chefsF-series, sometimes BusinessEmail, Teams, rota and document access, on a phone and a shared PC
Duty managers and supervisorsF-seriesTeams, shifts, email, training content, access to shared mailboxes
Floor, bar, kitchen and housekeeping teamsF-series (lower tier)Identity, Teams, rota, payslips, training, internal comms
Reception and reservationsF-series plus shared mailbox accessTeams, shared mailbox, PMS access, no personal mailbox
Kiosk and shared terminalsDevice-based or shared licensingShared sign-in, no per-user assumption, locked-down profile
Contractors and seasonal staffF-series, time-boxedIdentity with a hard expiry date, minimal data access

Shared devices break per-user assumptions

Microsoft's default model assumes one person, one device, one profile. A venue does not work that way: the back-of-house PC in the cellar is used by eleven people across two shifts.

Shared-device sign-in handles that. A user signs in, works, signs out, and the next person gets a clean session with their own identity and no access to the last person's mail. Sessions time out rather than staying open all night.

The alternative is the pattern every hospitality IT team has walked into: one generic login called "bar" or "office", the password written under a shelf, and no way to tell who did what. That account is also a straightforward entry point for an attacker, which is why shared credentials feature in most [[hospitality cyber attack paths]{.underline}](about:blank) worth worrying about.

Identity is the real project

Licensing is where people start. Identity decides whether the tenancy is still secure a year later. Hospitality turnover produces joiners, movers and leavers at a volume most corporate processes are not built for. If that runs on emails to IT, it will not run.

The offboarding gap is the specific failure. Someone leaves on a Sunday, HR updates payroll on Wednesday, IT hears in next week's report, and for ten days a former employee has a live mailbox and whatever documents they could reach. Connect HR to identity provisioning where you can; where you cannot, agree a same-day manual process with the venue GM.

Multi-factor authentication needs proportionate design in a workforce that may not have a company phone. Use authenticator apps on personal devices where staff consent, hardware tokens for shared roles, and conditional access that demands stronger authentication for risky sign-ins and sensitive data rather than every login. Head-office policy applied uniformly to 1,500 frontline staff produces 6am lockouts and workarounds, so the balance is [[IT consultancy and advisory]{.underline}](about:blank) work rather than a switch you flip.

Teams and rotas are where adoption happens

Most rollouts succeed or fail on one question: does the frontline see any benefit? Email does not deliver that. Rotas do. A shift tool that lets a chef de partie check next week's schedule, swap a shift and get it approved on their own phone is what makes a licence worth having.

Comms work the same way. A per-venue Teams channel replaces the WhatsApp group holding three years of operational messages, guest complaints and incident photographs on personal phones, outside any retention or access control.

Where guest data quietly ends up

Guest data does not stay in the PMS. It arrives in Outlook as a note about a dietary requirement, a scanned authorisation form, a VIP list, a spreadsheet of private dining attendees. It settles in SharePoint folders nobody has reviewed since the site opened.

Two habits need attention. The first is retention: decide how long reservation correspondence and event files should be kept, then apply retention policies rather than relying on people to delete things. The second is shared mailboxes. Every group runs reservations@ and events@, and they are the right tool, but access lists only ever grow.

Microsoft's shared responsibility model is not a backup

Microsoft is responsible for the availability of the service and the resilience of its own infrastructure. It is not responsible for recovering your data from a mistake you made, and native retention windows are not built around your recovery requirements.

If a mailbox is deleted, a SharePoint library is wiped by a sync error, or ransomware encrypts files that then sync to the cloud, native recovery is limited and time-bound. Third-party backup for Exchange Online, SharePoint, OneDrive and Teams gives point-in-time restore on your own schedule, and belongs with [[disaster recovery for a multi-site estate]{.underline}](about:blank).

Security tooling sits alongside backup rather than replacing it. Conditional access and phishing protection reduce the chance of an incident; backup determines how bad it is. Running both, usually under a [[managed cyber security]{.underline}](about:blank) arrangement, is the difference between recovering in hours and arguing with a portal for a week.

Getting an inherited tenancy into shape

Most groups inherit a tenancy rather than design one, and nobody has reviewed it since the first site opened. A useful review covers licence assignment against real roles, dormant accounts still being paid for, admin rights and who holds them, and whether any backup exists. It usually pays for itself in reclaimed licences, and a [[24/7 managed IT support]{.underline}](about:blank) partner should run it annually as routine. Operators with [[hotels and resorts]{.underline}](about:blank) alongside restaurants often need two licence models in one tenancy by design.

Frequently asked questions

F-series plans are built for frontline staff who share devices and work mainly on mobile: identity, Teams, web and mobile Office apps and a smaller mailbox. The higher frontline tier adds a larger mailbox and broader app access. E-series plans suit knowledge workers who need full desktop Office. Check current Microsoft pricing before budgeting.

Written by the MicroNet Global team. If you are working through any of this for your own estate, the specialists here are happy to talk it through.

Keep reading

Related insights

All insights
New openings6 min read

The technology checklist for a new hospitality opening

The questions operators should answer before the opening team arrives on site, from connectivity and suppliers to handover and live support.

Read article
Managed IT5 min read

Why hospitality needs a different IT support model

Hospitality does not operate in office hours. A useful support model is built around service, sites and the commercial cost of disruption.

Read article
Cyber security7 min read

A practical guide to hospitality cyber security

A plain-English starting point for protecting guest data, payment systems and the people who keep venues running.

Read article
Managed IT7 min read

What hotel IT support actually covers, and what it doesn't

What hotel IT support covers: systems in scope, who owns the PMS and door locks, contract tiers, exclusions and how response targets really work.

Read article
Managed IT7 min read

Why PMS and EPOS integrations break, and how to catch it early

Why PMS and EPOS integrations fail: stopped interface services, expired certificates, room status and API changes, and the checks that catch silent errors.

Read article
Managed IT7 min read

In-house IT team or hospitality IT partner: an honest comparison

In-house IT team or outsourced hospitality IT partner? An even-handed comparison of cover, cost, breadth, openings and the co-managed middle ground.

Read article
Networks & Wi-Fi7 min read

Why guest Wi-Fi generates complaints, and how to design it out

Why guest Wi-Fi draws complaints in hotels and restaurants, and how to design it out --- surveys, AP placement, captive portals, segmentation and peak load.

Read article
Networks & Wi-Fi7 min read

Wi-Fi 7 and the 6 GHz band: what actually changed for venues in 2026

Ofcom opened the full 6 GHz band in July 2026. What Wi-Fi 7 changes for hotels, restaurants and clubs, what it costs, and when waiting is the better call.

Read article
Managed IT7 min read

Disaster recovery when there are 180 covers booked tonight

Business continuity for hotels and restaurants with covers booked tonight. RTO and RPO explained, the failure scenarios that happen and what restores service.

Read article
Compliance7 min read

PCI DSS for restaurants and hotel groups: the practical checklist

A practical PCI DSS checklist for multi-site restaurants and hotels: who enforces it, scope reduction, segmentation, phone orders and v4.x deadlines.

Read article
Cyber Security7 min read

Hospitality cyber security: the attack paths that actually get used

The attack paths actually used against hotel and restaurant groups, the defences that work, and what to do in the first hour of a suspected incident.

Read article
Compliance7 min read

Martyn's Law for venues: what it requires, and where technology helps

What Martyn's Law means for hospitality operators: the standard and enhanced tiers, the SIA's role, and where technology genuinely supports the duties.

Read article
Openings & Rollouts7 min read

The IT critical path for opening a restaurant, hotel or club

A week-by-week IT timeline for opening a restaurant, hotel or club, from circuit lead times and cabling first fix to soft launch and day-one support.

Read article
Managed IT7 min read

Windows 10 end of support: the estate you cannot see

Windows 10 support ended in October 2025 and ESU Year 1 expires this October. A practical refresh plan for back-office, EPOS-adjacent and AV control PCs.

Read article

Put this into practice

Services and sectors this touches

Secure, scalable and seamless IT wherever hospitality takes you.