Managed IT
Microsoft 365 when most of your workforce never sits at a desk
How to licence Microsoft 365 across hotel and restaurant teams, covering frontline worker tiers, shared device sign-in, identity, offboarding and backup.
Microsoft 365 for hospitality works when licensing follows the job rather than the headcount: head office on knowledge-worker plans, venue teams on frontline licences, and shared devices handled properly. MicroNet Global, a Microsoft Gold Partner supporting 745+ hospitality sites across 15+ countries, designs these tenancies around venue reality rather than office assumptions.
A typical operator has 60 head-office staff living in Outlook and Excel all day, and 1,500 venue staff who need a payslip, a rota, a training module and somewhere to be told the gas is off tomorrow. Licensing the second group like the first is avoidable waste.
What is frontline worker licensing?
Frontline worker licensing is a Microsoft licence category designed for staff who do not work at a dedicated PC: kitchen, floor, housekeeping, reception and bar teams. The F-series plans provide identity, Teams, web and mobile versions of the Office apps and a smaller mailbox, at a fraction of a knowledge-worker plan. Head office keeps E-series or Business plans for full desktop applications.
Microsoft changes plan names, inclusions and prices regularly, so check current Microsoft pricing before building a business case. The principle does not change: pay for capability people actually use.
Licence tiers by role
Map every job title in the group to one of these rows before looking at a single price.
| Role | Typical licence | What they actually |
|---|---|---|
| Finance, marketing and HR at head office | E-series or Business Premium | Full desktop Office, large mailbox, advanced security, device management |
| Directors and senior operations | E-series or Business Premium | Full Office, mobile access, compliance features, travel-ready devices |
| General managers and head chefs | F-series, sometimes Business | Email, Teams, rota and document access, on a phone and a shared PC |
| Duty managers and supervisors | F-series | Teams, shifts, email, training content, access to shared mailboxes |
| Floor, bar, kitchen and housekeeping teams | F-series (lower tier) | Identity, Teams, rota, payslips, training, internal comms |
| Reception and reservations | F-series plus shared mailbox access | Teams, shared mailbox, PMS access, no personal mailbox |
| Kiosk and shared terminals | Device-based or shared licensing | Shared sign-in, no per-user assumption, locked-down profile |
| Contractors and seasonal staff | F-series, time-boxed | Identity with a hard expiry date, minimal data access |
Shared devices break per-user assumptions
Microsoft's default model assumes one person, one device, one profile. A venue does not work that way: the back-of-house PC in the cellar is used by eleven people across two shifts.
Shared-device sign-in handles that. A user signs in, works, signs out, and the next person gets a clean session with their own identity and no access to the last person's mail. Sessions time out rather than staying open all night.
The alternative is the pattern every hospitality IT team has walked into: one generic login called "bar" or "office", the password written under a shelf, and no way to tell who did what. That account is also a straightforward entry point for an attacker, which is why shared credentials feature in most [[hospitality cyber attack paths]{.underline}](about:blank) worth worrying about.
Identity is the real project
Licensing is where people start. Identity decides whether the tenancy is still secure a year later. Hospitality turnover produces joiners, movers and leavers at a volume most corporate processes are not built for. If that runs on emails to IT, it will not run.
The offboarding gap is the specific failure. Someone leaves on a Sunday, HR updates payroll on Wednesday, IT hears in next week's report, and for ten days a former employee has a live mailbox and whatever documents they could reach. Connect HR to identity provisioning where you can; where you cannot, agree a same-day manual process with the venue GM.
Multi-factor authentication needs proportionate design in a workforce that may not have a company phone. Use authenticator apps on personal devices where staff consent, hardware tokens for shared roles, and conditional access that demands stronger authentication for risky sign-ins and sensitive data rather than every login. Head-office policy applied uniformly to 1,500 frontline staff produces 6am lockouts and workarounds, so the balance is [[IT consultancy and advisory]{.underline}](about:blank) work rather than a switch you flip.
Teams and rotas are where adoption happens
Most rollouts succeed or fail on one question: does the frontline see any benefit? Email does not deliver that. Rotas do. A shift tool that lets a chef de partie check next week's schedule, swap a shift and get it approved on their own phone is what makes a licence worth having.
Comms work the same way. A per-venue Teams channel replaces the WhatsApp group holding three years of operational messages, guest complaints and incident photographs on personal phones, outside any retention or access control.
Where guest data quietly ends up
Guest data does not stay in the PMS. It arrives in Outlook as a note about a dietary requirement, a scanned authorisation form, a VIP list, a spreadsheet of private dining attendees. It settles in SharePoint folders nobody has reviewed since the site opened.
Two habits need attention. The first is retention: decide how long reservation correspondence and event files should be kept, then apply retention policies rather than relying on people to delete things. The second is shared mailboxes. Every group runs reservations@ and events@, and they are the right tool, but access lists only ever grow.
Microsoft's shared responsibility model is not a backup
Microsoft is responsible for the availability of the service and the resilience of its own infrastructure. It is not responsible for recovering your data from a mistake you made, and native retention windows are not built around your recovery requirements.
If a mailbox is deleted, a SharePoint library is wiped by a sync error, or ransomware encrypts files that then sync to the cloud, native recovery is limited and time-bound. Third-party backup for Exchange Online, SharePoint, OneDrive and Teams gives point-in-time restore on your own schedule, and belongs with [[disaster recovery for a multi-site estate]{.underline}](about:blank).
Security tooling sits alongside backup rather than replacing it. Conditional access and phishing protection reduce the chance of an incident; backup determines how bad it is. Running both, usually under a [[managed cyber security]{.underline}](about:blank) arrangement, is the difference between recovering in hours and arguing with a portal for a week.
Getting an inherited tenancy into shape
Most groups inherit a tenancy rather than design one, and nobody has reviewed it since the first site opened. A useful review covers licence assignment against real roles, dormant accounts still being paid for, admin rights and who holds them, and whether any backup exists. It usually pays for itself in reclaimed licences, and a [[24/7 managed IT support]{.underline}](about:blank) partner should run it annually as routine. Operators with [[hotels and resorts]{.underline}](about:blank) alongside restaurants often need two licence models in one tenancy by design.
Frequently asked questions
F-series plans are built for frontline staff who share devices and work mainly on mobile: identity, Teams, web and mobile Office apps and a smaller mailbox. The higher frontline tier adds a larger mailbox and broader app access. E-series plans suit knowledge workers who need full desktop Office. Check current Microsoft pricing before budgeting.
Written by the MicroNet Global team. If you are working through any of this for your own estate, the specialists here are happy to talk it through.
