Microsoft 365 for hotels is almost never the tenant Microsoft imagined. The default guidance assumes one office, one set of named employees, a laptop each and a nine-to-five working pattern. A hotel has a reception desk that never closes, a workforce that turns over faster than any other sector in the UK, a mailbox that strangers email dozens of times a day, and half a dozen supplier systems that all want to send email as the hotel. The licences are the same. The risk profile is not.

That gap is where most hospitality tenants quietly sit, and it is why Microsoft 365 for hotels deserves its own baseline. The subscription is paid, the mail flows, everybody can open a spreadsheet, and nobody has ever opened the security settings. If your estate is residential blocks rather than bedrooms, our guide to Microsoft 365 for property management companies covers the same discipline for a different building type. This article is the hospitality version, and it is written as a checklist you can work through rather than a lecture on zero trust.

What follows is a Microsoft 365 for hotels security checklist of 18 controls across six domains. Each one has a plain evidence test, a note on which licence actually delivers it, and an honest statement of what it costs. There is a scorecard, a licence comparison, a worked example for a three-property group, a 90-day sequence and a mapping to Cyber Essentials, PCI DSS and UK data protection law. None of it needs a security team. It needs somebody to own the tenant.

Why Microsoft 365 for hotels is a different build

microsoft 365 for hotels security checklist b sealed envelope flap

Microsoft 365 for a single-site accountancy practice is a straightforward build: everyone gets a licence, everyone gets a laptop, everyone signs in as themselves, and the leaver process runs through HR. Every one of those assumptions breaks in a hotel, and they break structurally rather than accidentally. Understanding exactly how they break is what turns a generic baseline into a workable Microsoft 365 for hotels configuration.

The front desk is a shared surface, not a personal one

Reception runs 24 hours across three shifts. The pressure to keep a single signed-in session open all day is enormous, and the fastest way to get an agency night porter working at 22:00 is to hand over the login somebody else is already using. Shared credentials are the single most common finding in any Microsoft 365 for hotels review, and they defeat every downstream control: conditional access, audit trails, risk detection and offboarding all assume one human per account.

Turnover makes annual processes meaningless

UK hospitality turnover ran at 67% in the 2025 Pineapple and Sona benchmark, down from 75% the year before but still far above almost any other sector. An annual access review covers a workforce that has already changed twice. Any Microsoft 365 for hotels design has to assume that joiners and leavers are the normal state of the tenant, not an exception handled once a quarter.

The main mailbox is a public inbox by design

A hotel publishes reservations@, events@ and info@ and invites the world to email them with attachments. Those mailboxes are usually shared, usually unlicensed, often have delegated access for half the team, and frequently have a forwarding rule somebody added in 2019. They are the highest-value target in the tenant and typically the least protected part of it.

Suppliers send email as the hotel, and the hotel signs in to theirs

Channel managers, booking engines, marketing platforms, EPOS receipt systems and the property management system all either send mail on the hotel’s behalf or hold credentials belonging to hotel staff. That two-way exposure is why email authentication and identity hygiene carry more weight in a Microsoft 365 for hotels build than in a comparable office tenant.

Default assumptionWhat a hotel tenant actually looks likeControls affected
One person, one accountFront desk, night audit and duty manager logins passed between shifts1, 2, 3, 16
Everyone has a laptopShared PCs, kiosks, EPOS tills and personal phones10, 11, 12
Mail arrives from known contactsUnsolicited attachments from guests, agents and OTAs all day6, 7, 8
Leavers are rare and plannedSeasonal, agency and casual staff joining and leaving weekly4, 5, 15
One organisation sends our emailPMS, channel manager, booking engine and marketing tool all send as us9, 13
IT is available when something breaksA duty manager alone at 03:00 with no escalation path17, 18

The threat to Microsoft 365 for hotels is specific, not generic

Microsoft’s threat intelligence team documented a campaign that began in December 2024 in which the actor it tracks as Storm-1865 impersonated Booking.com in emails to hospitality staff across North America, Oceania, South and Southeast Asia and Europe. The lure was ordinary hotel business: a complaint about a negative review, a prospective booking, an account verification notice. The payload was a fake CAPTCHA page using the ClickFix technique, which instructs the reader to press Win+R and paste a command that runs through mshta.exe and installs credential stealers including XWorm, Lumma, VenomRAT, AsyncRAT, Danabot and NetSupport RAT.

The UK loss numbers are already published

Action Fraud recorded 532 reports and roughly £370,000 of losses between June 2023 and September 2024 from people who received messages from a hotel’s own booking platform account after that account had been taken over. Those takeovers were the result of phishing aimed at the accommodation provider, not a breach of the platform. That is a hospitality-specific consequence of weak identity controls, and it is the sharpest argument for treating Microsoft 365 for hotels as a security project rather than an email subscription.

Domain one: identity controls in Microsoft 365 for hotels

microsoft 365 for hotels security checklist c key card wall slot

Identity is where the money is, and it is where any Microsoft 365 for hotels project should start. Every control below sits in Microsoft Entra ID, and every one of them is available on Microsoft 365 Business Premium without buying anything extra.

Control 1 — Give every human their own account

No shared front-desk login, no “reception1” that four people know the password to, no duty manager account passed on a sticky note. Where a device genuinely must stay signed in, use a device identity and a kiosk profile rather than a human account. This is the foundational control in Microsoft 365 for hotels because nothing else survives without it.

Evidence test: open the Entra ID user list, sort by last sign-in, and pick any three accounts. If you cannot name the single person who uses each one, you have failed this control.

Control 2 — Enforce MFA on every account without exception

Microsoft finished enforcing MFA for sign-ins to the Microsoft 365 admin centre on 9 February 2026, and mandatory MFA has already rolled out across the Azure and Entra admin portals. That covers administrators; it does not cover the reservations manager whose mailbox holds every guest’s card authorisation. Enforce multifactor authentication on all accounts, all locations and all times, and remove the exclusions somebody added during a busy weekend. In Microsoft 365 for hotels there is no account that legitimately sits outside that rule.

Evidence test: run the Entra sign-in log filtered to single-factor successes over the last 30 days. The correct answer is zero.

Control 3 — Move from security defaults to conditional access

Security defaults are a reasonable floor for a very small tenant, but they are all-or-nothing. Business Premium includes Entra ID P1, which unlocks conditional access, and Microsoft now deploys a set of Microsoft-managed policies to raise the baseline automatically. A workable Microsoft 365 for hotels policy set requires MFA for admins, requires MFA for everyone, blocks legacy authentication, and restricts access from countries the group has no business in.

Evidence test: the conditional access blade shows at least four policies in “On” state, not “Report-only”.

Control 4 — Separate and protect administrator access

Administration should not run from the account that reads guest email. Create dedicated admin accounts, keep at least two emergency access accounts excluded from conditional access and stored offline, and remove standing global administrator rights from anybody who does not need them daily. Most Microsoft 365 for hotels tenants turn out to hold three or four more global administrators than anybody thought, usually including a former IT supplier.

Evidence test: count the global administrators. More than four in a group under 300 staff needs a written justification.

Control 5 — Block legacy authentication and device code flow

Legacy protocols bypass MFA entirely, and device code flow is the technique behind a string of recent hospitality-adjacent intrusions. Microsoft’s own managed policies now block device code flow by default for tenants that have not used it in the past 25 days. Verify that yours is blocked rather than assuming it, which is a two-minute check in any Microsoft 365 for hotels tenant, and confirm nothing in the estate still needs basic authentication before you turn it off.

Evidence test: conditional access shows an enabled policy blocking legacy client apps and an enabled policy blocking device code flow.

UK businesses identifying a breach or attack in the last 12 months, by size (Cyber Security Breaches Survey 2025/2026)
Micro (1-9 staff) 42%
Small (10-49 staff) 46%
Medium (50-249 staff) 65%
Large (250+ staff) 69%

A three-property group usually sits in the medium band, where roughly two in three organisations reported a breach or attack, and that is the population most Microsoft 365 for hotels work is aimed at. The same survey put formal incident response plans at 25% and board-level ownership at 31%, which is the gap this checklist is trying to close.

Domain two: email and the booking channel in Microsoft 365 for hotels

microsoft 365 for hotels security checklist d light switch rocker plate

Email is the attack surface that pays, and it is the part of Microsoft 365 for hotels that guests, suppliers and criminals all touch every day. A hotel’s inbox is the one place where a stranger’s attachment is expected, and the one place where a changed bank detail turns into a payment.

Control 6 — Turn on Defender for Office 365 properly

Business Premium includes Microsoft Defender for Office 365 Plan 1. Turning it on is not the same as configuring it, and most Microsoft 365 for hotels tenants stop at the licence. Enable Safe Links with the setting that rechecks URLs at the moment of click, enable Safe Attachments, and confirm zero-hour auto purge is active so that mail already delivered can be pulled back when it is later found to be malicious. Microsoft named exactly these three settings in its guidance following the Booking.com impersonation campaign.

Control 7 — Configure impersonation protection for the names that matter

Anti-phishing policies let you protect specific users and specific domains against impersonation. In Microsoft 365 for hotels the list is short and obvious: the general manager, the finance contact, the reservations mailbox, the group’s own domain, and the domains of the booking platforms and channel managers the property actually uses. Without this, a message from a lookalike domain lands looking entirely normal.

Control 8 — Put a payment-change rule in front of the finance mailbox

Bank-detail fraud does not need malware. Add an external sender warning to inbound mail, and a transport rule that flags messages to the accounts mailbox containing phrases about changed bank details, new remittance instructions or updated payment information. Pair it with a written rule that no bank change is ever actioned from email alone. The same failure pattern is examined in detail in our analysis of business email compromise and hijacked supplier payments.

Control 9 — Fix SPF, DKIM and DMARC across every sender

List every system that sends email as the hotel: Microsoft 365 itself, the property management system, the booking engine, the channel manager, the marketing platform, the EPOS receipt sender and any scan-to-email device. Publish an SPF record that covers all of them, sign with DKIM, and move DMARC from none to quarantine once the reports are clean. A hotel that has not done this cannot credibly tell a guest that a fraudulent message did not come from it. Email authentication is the part of Microsoft 365 for hotels that protects people who are not your staff.

CapabilityBusiness BasicBusiness StandardBusiness Premium
Entra ID planFreeFreeP1 (conditional access)
Defender for Office 365NoNoPlan 1
Defender for Business (endpoint)NoNoYes
Intune device managementNoNoPlan 1
Purview information protection and DLPNoNoYes
Desktop Office appsNoYesYes
UK list price per user per month£5.40£18.10 with Copilot£24.60 with Copilot

The row that decides everything is the first one. Conditional access, Intune, Defender for Business and Purview all arrive together with Business Premium, which is why almost every serious Microsoft 365 for hotels design ends up there for its office-based staff. Costing a Microsoft 365 for hotels rollout starts from that same row. Microsoft’s UK storefront now leads with Copilot-bundled pricing; the base Business Premium rate without Copilot is £16.90 per user per month on an annual commitment, ex VAT.

Domain three: devices and kiosks in Microsoft 365 for hotels

microsoft 365 for hotels security checklist e window frame four panes

Control 10 — Enrol every hotel-owned PC in Intune

Front-desk PCs, back-office machines and duty-manager laptops should all be enrolled, because an unmanaged device is a blind spot in any Microsoft 365 for hotels estate. Enrolment gives you disk encryption status, patch state, a remote wipe path and the ability to require a compliant device in conditional access. Cyber Essentials treats an organisation-owned device as in scope even when a customer is the one using it, which catches the lobby PC and the business-centre machine most hotels forget.

Control 11 — Handle shared devices as shared devices

Microsoft’s frontline worker licensing exists precisely for this pattern: staff who work on shared devices, on the web and on mobile rather than at a desk. Configure automatic sign-out on shared machines, which is the single most visible Microsoft 365 for hotels change reception will notice, use shared device mode where the app supports it, and make the kiosk a kiosk rather than a general-purpose Windows PC left on the reception desk. The physical hardening that goes with it is covered in our wider hotel cyber security checklist.

Control 12 — Enable Defender for Business and attack surface reduction

ClickFix works by persuading a human to run a command. Attack surface reduction rules that block obfuscated scripts, block executable content from email, block JavaScript from launching downloaded content and block credential theft from LSASS break that chain even when the human co-operates. Turn on cloud-delivered protection, network protection and automated investigation in full mode while you are there. Attack surface reduction is the highest-value endpoint setting in Microsoft 365 for hotels because it breaks that chain without needing the user to behave.

Identity mix in the three-property worked example (237 identities in total)
Frontline staff, 166 70%
Office and management staff, 48 20%
Shared and generic mailboxes, 17 7%
Administrator accounts, 6 3%

The 23 shared and administrative identities are only a tenth of the tenant, and they carry almost all of the risk. Every Microsoft 365 for hotels programme should start there rather than at the bottom of the list.

Domain four: guest data and retention in Microsoft 365 for hotels

microsoft 365 for hotels security checklist f three stepping stones row

Control 13 — Use Purview DLP to stop card numbers moving through email

Guests email card details. Agents email card details. Staff paste card details into a booking note because the phone line was bad. Purview data loss prevention policies detect credit card numbers in mail, chat and files and can block, warn or simply report. Start in report-only mode for a fortnight to see the real volume before you switch on blocking, because the first run is usually a surprise. A first Microsoft 365 for hotels data loss prevention report normally finds card numbers in places nobody predicted.

Control 14 — Set retention that matches the reservation lifecycle

Guest records are personal data under UK data protection law and should not sit in a mailbox forever because nobody set a policy. Define how long reservation correspondence, event enquiries, CCTV requests and HR records are kept, then implement it with Purview retention labels and policies. Retention is also what stops a compromised mailbox from handing over fifteen years of guest history in one export, and it is the quietest control in Microsoft 365 for hotels.

Control 15 — Control external sharing and guest accounts

Agencies, event organisers, marketing agencies and franchise partners all end up with guest accounts or shared links in the tenant. Restrict what guest users can see in the directory, set links to expire, review the guest list quarterly, and remove suppliers whose contract ended. Guest accounts accumulate faster in Microsoft 365 for hotels than in any office tenant. This is unglamorous work that quietly closes the door somebody left open two contracts ago.

Hotel roleTypical needSensible licence
General manager, finance, revenue, sales, HRDesktop apps, mailbox, managed laptop, conditional accessBusiness Premium
Reservations and events teamHeavy mailbox use, DLP, impersonation protectionBusiness Premium
Duty managers and night auditNamed account, MFA, mobile access, shared PCBusiness Premium or F3
Reception, housekeeping, kitchen, F&BIdentity, Teams, rota, no desktop appsFrontline F1 or F3
reservations@, events@, accounts@Shared mailbox with delegated accessNo licence under 50 GB
PMS, EPOS and scan-to-email sendersSend only, moving off basic authenticationService account, no interactive sign-in

Frontline F1 gives identity, Teams, SharePoint access and shift tools without an Exchange mailbox; F3 adds a 2 GB mailbox plus web and mobile Office apps, Windows Enterprise rights, Intune Plan 1 and Entra ID P1. F1 supports shared device licensing by default, which is the practical reason it fits a reception desk better than an enterprise SKU does, and that split is what keeps Microsoft 365 for hotels affordable across a whole estate.

Domain five: monitoring Microsoft 365 for hotels and the 3 a.m. problem

Control 16 — Turn on auditing and actually alert on something

The unified audit log is the record you will need if a mailbox is compromised, and Entra ID Protection surfaces risky sign-ins. Configure diagnostic settings to retain sign-in and audit logs beyond the default window, then create alerts for four events: a new inbox forwarding rule, a mailbox permission change, a new global administrator, and a sign-in from an unusual country. Those four alerts cover most of what actually happens inside a compromised Microsoft 365 for hotels tenant.

Control 17 — Understand what Microsoft does not back up for you

Microsoft protects the platform, not your decisions. Retention and litigation hold are not a backup, and a shared mailbox under 50 GB has no archive and no hold by default. Decide deliberately whether you are buying Microsoft 365 Backup, a third-party product, or accepting the risk in writing. The right answer differs by group; the wrong answer is not having had the conversation. Backup is the one line in a Microsoft 365 for hotels design that is a business decision rather than a technical one.

Control 18 — Write an incident path a duty manager can run at 03:00

Every control above assumes somebody eventually notices. In Microsoft 365 for hotels that person is a duty manager with no IT background, at night, alone. They need one card: who to phone, how to disable an account, how to stop a payment, when to call the bank, and when the ICO clock starts. Test it once. Our IT support model for hotels and hospitality businesses exists mostly because this control is the one that is never in place.

The Microsoft 365 for hotels scorecard

Score each control red, amber or green. Red means the control does not exist. Amber means it exists somewhere but not everywhere, or nobody can produce evidence. Green means you passed the evidence test at every property this quarter. A first honest pass through a Microsoft 365 for hotels scorecard usually produces more red than anybody expects, which is the point of running it.

#ControlDomainEvidence in ten minutes
1One account per humanIdentityName the owner of three random accounts
2MFA everywhere, no exclusionsIdentityZero single-factor successes in 30 days
3Conditional access in placeIdentityFour or more policies set to On
4Admin separation and break-glassIdentityGlobal admin count and owner list
5Legacy auth and device code blockedIdentityTwo enabled blocking policies
6Safe Links, Safe Attachments, ZAPEmailPolicy pages show enabled, not default
7Impersonation protection configuredEmailProtected users and domains listed
8Payment-change rule and warningEmailTransport rule exists and fires
9SPF, DKIM and DMARC completeEmailDNS lookup plus a sender inventory
10Hotel PCs enrolled in IntuneDevicesDevice count matches the asset list
11Shared devices configured as sharedDevicesAuto sign-out demonstrated at reception
12Defender for Business and ASR onDevicesASR rules in block, not audit
13DLP for card dataDataPolicy exists and has recent matches
14Retention matches the record typeDataPublished schedule and live labels
15Guest access reviewedDataGuest list dated within 90 days
16Auditing on with four alertsMonitoringAlert rules exist and have fired
17Backup decision documentedMonitoringA written decision, either way
18Night-time incident card testedMonitoringA duty manager can produce it

A worked example: Microsoft 365 for hotels in a three-property group

Take a group of three hotels with 128, 96 and 64 bedrooms, so 288 bedrooms in total, plus a small head office. It is a realistic shape for Microsoft 365 for hotels in the UK independent market. The group employs 214 named people. Of those, 48 are office and management staff who need desktop applications and a full mailbox, and 166 are frontline staff in reception, housekeeping, kitchen, food and beverage and maintenance. On top of the named people sit 17 shared or generic mailboxes and 6 administrator accounts, giving 237 identities in total.

Twenty-three of those 237 identities are shared or privileged, just under a tenth of the tenant. Those 23 are where a Microsoft 365 for hotels remediation plan starts, because they are the accounts that cannot be tied to one person, cannot easily be MFA-enrolled without planning, and carry the most authority when they are compromised.

What Microsoft 365 for hotels costs at list price

Using the base Business Premium rate of £16.90 for the 48 office and management staff gives £811.20 a month. Licensing the 166 frontline staff on F1 at roughly £2.00 each adds £332.00 a month. The total is £1,143.20 a month, or £13,718.40 a year, which works out at £47.63 per bedroom per year across the 288 bedrooms.

What that buys against what it prevents

Set that £13,718.40 against the £370,000 that Action Fraud recorded across 532 reports in a fifteen-month window, or against a single redirected supplier payment. The arithmetic is not close. The licences are not the expensive part of a Microsoft 365 for hotels programme; the configuration work and the ownership are, and both are one-off in a way the fraud is not.

LineCountUnit per monthMonthly total
Business Premium, office and management48£16.90£811.20
Frontline F1, shift staff166£2.00£332.00
Shared mailboxes under 50 GB17£0.00£0.00
Break-glass and admin accounts6Included£0.00
Group total237—£1,143.20

The 90-day sequence for Microsoft 365 for hotels

Doing all 18 controls at once fails, because half of them need a change to how reception works and reception is busy. Sequencing is what makes a Microsoft 365 for hotels programme survive a season. Sequence them so the highest-value identity work lands first and the slower cultural changes come last.

Days 1 to 30: stop the bleeding

Controls 1 to 5 plus control 6. Named accounts, MFA everywhere, conditional access, admin separation, legacy authentication and device code blocked, and Defender for Office 365 configured. Seven controls, and they remove most of the paths an attacker actually uses. Anyone running Microsoft 365 for hotels with limited time should stop after this month and still be ahead of the sector.

Days 31 to 60: harden the channel and the endpoints

Controls 7 to 12. Impersonation protection, the payment-change rule, email authentication, Intune enrolment, shared device configuration and Defender for Business with attack surface reduction. That takes cumulative coverage to 13 of the 18 controls, and it is the point at which Microsoft 365 for hotels stops being a licence and starts being a control set.

Days 61 to 90: data, monitoring and the incident card

Controls 13 to 18. DLP, retention, guest access review, auditing and alerts, the backup decision and the night-time incident card. These need conversations with people outside IT, which is exactly why they belong at the end rather than the beginning.

Cumulative control coverage across the 90-day sequence (18 controls)
Day 30, 7 controls 39%
Day 60, 13 controls 72%
Day 90, 18 controls 100%

The basic authentication deadline nobody has diarised

Exchange Online is retiring basic authentication for SMTP client submission. Microsoft’s current position is that basic authentication for SMTP AUTH remains usable until the end of December 2026, after which it is disabled. In Microsoft 365 for hotels that matters far more than it does in an office, because the things still using it are rarely obvious: the property management system sending confirmations, the EPOS emailing receipts, the scan-to-email function on the back-office printer, and an old booking form on the website.

Inventory those senders now and move each one to OAuth, to a supported relay, or to a modern replacement. Doing this discovery late is how a hotel loses its confirmation emails on a bank holiday weekend. It is also a good forcing function for control 9, since one sender inventory answers both questions and both belong to the same Microsoft 365 for hotels owner.

Mapping the checklist to Cyber Essentials, PCI DSS and UK law

Nothing in this Microsoft 365 for hotels checklist is invented. Every control maps to something a certification body, a card scheme or a regulator already expects, which makes it easier to justify the work upstairs.

ControlsCyber EssentialsPCI DSSUK data protection
1-5 IdentityUser access control; MFA on cloud services is an auto-fail questionUnique IDs and MFA for access to cardholder dataAppropriate technical measures
6-9 EmailMalware protection and secure configurationAnti-malware and awarenessConfidentiality of personal data
10-12 DevicesSecure configuration, update management, malware protectionSecure systems and softwareSecurity of processing
13-15 DataScope definition and cloud responsibilityProtect stored account dataStorage limitation and minimisation
16-18 MonitoringNot a technical requirement, but expected evidenceLogging and monitoring72-hour breach reporting to the ICO

Cyber Essentials is worth pursuing alongside this work rather than after it, because the certification questions and a Microsoft 365 for hotels checklist overlap heavily. The scoping detail specific to hotels is set out in our Cyber Essentials certification guide for hotels, including how a segregated guest network is treated. On the network side, the companion pieces on hotel WiFi security and on captive portal attacks against hotel guest networks cover the parts of the estate that sit outside the tenant.

Who owns Microsoft 365 for hotels in a group

The honest answer in most groups is nobody. The general manager assumes head office owns it, head office assumes the supplier owns it, and the supplier is contracted for break-fix. That ambiguity is the reason a good cybersecurity posture decays even in groups that once paid for a review, and it is why Microsoft 365 for hotels needs a named owner rather than a project.

Name one owner per property and one for the group

The property owner does the operational checks: leavers disabled, shared devices signing out, the incident card on the wall. The group owner holds the tenant configuration, the licence position and the evidence pack. Two names, written down, reviewed quarterly, and both of them accountable for Microsoft 365 for hotels rather than for IT in general.

Put the checks in an existing rhythm

Attach the control checks to a meeting that already happens. A ten-minute slot in the monthly heads-of-department meeting covers the operational half, and a quarterly review with your IT provider covers the tenant half. Anything that needs its own new meeting will not survive a busy season, which is why a Microsoft 365 for hotels programme should ride on rhythms the business already keeps.

Decide what part of Microsoft 365 for hotels you outsource

Most independent groups cannot staff conditional access design, DLP tuning and alert triage internally, and should not try. A managed provider can hold the tenant, run the alerts and produce the evidence pack, while the properties keep the operational checks. Our managed IT services and incident response pages set out how that split usually works in practice.

Frequently asked questions about Microsoft 365 for hotels

Is Microsoft 365 Business Premium enough for a hotel group?

For almost all independent and small-group operators, Business Premium is the right answer for Microsoft 365 for hotels. It carries Entra ID P1, Intune, Defender for Business, Defender for Office 365 Plan 1 and Purview information protection, which delivers every control in this checklist. Business plans cap at 300 users, so a group above that moves to enterprise licensing, but capability is rarely the reason.

Can frontline staff be left unlicensed?

Only if they never touch a hotel system. In practice reception, housekeeping and kitchen staff use rotas, checklists and messaging, so they need an identity. An unlicensed person on a shared login is the Microsoft 365 for hotels failure this checklist exists to prevent, and F1 is cheap enough that the argument for shared credentials disappears.

What about the property management system and EPOS?

They sit outside the tenant, but they interact with it constantly through service accounts, email senders and staff credentials. Treat every integration as a supplier relationship with a named owner, an authentication method and an offboarding step, and record it next to your Microsoft 365 for hotels documentation. The wider estate view is covered in our hotel cyber security checklist.

How long does a Microsoft 365 for hotels rollout take?

Ninety days with somebody accountable, working alongside a normal operational load. The first thirty days deliver most of the risk reduction. Groups that try to compress all 18 controls into a fortnight usually break something at reception and lose the internal support they needed.

Does any of this stop a ClickFix attack?

Several controls do, at different points. Safe Links and zero-hour auto purge address the message, attack surface reduction rules address the pasted command, MFA and conditional access limit what stolen credentials achieve, and alerting on new forwarding rules catches what survives. No single control is sufficient, which is the argument for treating Microsoft 365 for hotels as a set rather than a shopping list.

References

Phishing campaign impersonates Booking.com, delivers a suite of credential-stealing malware

ClickFix Phishing Scam Impersonates Booking.com to Target Hospitality

Microsoft Warns of Hospitality Sector Attacks Involving ClickFix

Plan for mandatory Microsoft Entra multifactor authentication

Microsoft-managed Conditional Access policies

Block authentication flows with Conditional Access policy

Security defaults in Microsoft Entra ID

Manage emergency access accounts in Microsoft Entra ID

What is Microsoft Entra ID Protection?

Safe Links in Microsoft Defender for Office 365

Anti-phishing policies in Microsoft 365

Zero-hour auto purge in Exchange Online

What is Microsoft Defender for Business?

Understand frontline worker user types and licensing

Manage devices for frontline workers

Learn about data loss prevention

Learn about retention policies and retention labels

Search the audit log in the Microsoft Purview portal

Restrict guest access permissions in Microsoft Entra ID

Overview of Microsoft 365 Backup

Microsoft Secure Score

Exchange Online to retire Basic auth for Client Submission (SMTP AUTH)

Set up a multifunction device or application to send email using Microsoft 365

Compare all Microsoft 365 Business plans

Cyber Security Breaches Survey 2025/2026

Cyber Essentials overview

IASME guidance on Cyber Essentials scope

NCSC Device Security Guidance

NCSC Incident Management collection

NCSC: Incidents impacting retailers

NCSC phishing guidance

NCSC Small Business Guide to Cyber Security

ICO: A guide to data security

ICO: Report a personal data breach

PCI DSS standards

Verizon Data Breach Investigations Report

UKHospitality

Data Protection Act 2018