Microsoft 365 for hotels is almost never the tenant Microsoft imagined. The default guidance assumes one office, one set of named employees, a laptop each and a nine-to-five working pattern. A hotel has a reception desk that never closes, a workforce that turns over faster than any other sector in the UK, a mailbox that strangers email dozens of times a day, and half a dozen supplier systems that all want to send email as the hotel. The licences are the same. The risk profile is not.
That gap is where most hospitality tenants quietly sit, and it is why Microsoft 365 for hotels deserves its own baseline. The subscription is paid, the mail flows, everybody can open a spreadsheet, and nobody has ever opened the security settings. If your estate is residential blocks rather than bedrooms, our guide to Microsoft 365 for property management companies covers the same discipline for a different building type. This article is the hospitality version, and it is written as a checklist you can work through rather than a lecture on zero trust.
What follows is a Microsoft 365 for hotels security checklist of 18 controls across six domains. Each one has a plain evidence test, a note on which licence actually delivers it, and an honest statement of what it costs. There is a scorecard, a licence comparison, a worked example for a three-property group, a 90-day sequence and a mapping to Cyber Essentials, PCI DSS and UK data protection law. None of it needs a security team. It needs somebody to own the tenant.
Table of contents
- Why Microsoft 365 for hotels is a different build
- Domain one: identity controls in Microsoft 365 for hotels
- Domain two: email and the booking channel in Microsoft 365 for hotels
- Domain three: devices and kiosks in Microsoft 365 for hotels
- Domain four: guest data and retention in Microsoft 365 for hotels
- Domain five: monitoring Microsoft 365 for hotels and the 3 a.m. problem
- The Microsoft 365 for hotels scorecard
- A worked example: Microsoft 365 for hotels in a three-property group
- The 90-day sequence for Microsoft 365 for hotels
- The basic authentication deadline nobody has diarised
- Mapping the checklist to Cyber Essentials, PCI DSS and UK law
- Who owns Microsoft 365 for hotels in a group
- Frequently asked questions about Microsoft 365 for hotels
- References
Why Microsoft 365 for hotels is a different build
Microsoft 365 for a single-site accountancy practice is a straightforward build: everyone gets a licence, everyone gets a laptop, everyone signs in as themselves, and the leaver process runs through HR. Every one of those assumptions breaks in a hotel, and they break structurally rather than accidentally. Understanding exactly how they break is what turns a generic baseline into a workable Microsoft 365 for hotels configuration.
The front desk is a shared surface, not a personal one
Reception runs 24 hours across three shifts. The pressure to keep a single signed-in session open all day is enormous, and the fastest way to get an agency night porter working at 22:00 is to hand over the login somebody else is already using. Shared credentials are the single most common finding in any Microsoft 365 for hotels review, and they defeat every downstream control: conditional access, audit trails, risk detection and offboarding all assume one human per account.
Turnover makes annual processes meaningless
UK hospitality turnover ran at 67% in the 2025 Pineapple and Sona benchmark, down from 75% the year before but still far above almost any other sector. An annual access review covers a workforce that has already changed twice. Any Microsoft 365 for hotels design has to assume that joiners and leavers are the normal state of the tenant, not an exception handled once a quarter.
The main mailbox is a public inbox by design
A hotel publishes reservations@, events@ and info@ and invites the world to email them with attachments. Those mailboxes are usually shared, usually unlicensed, often have delegated access for half the team, and frequently have a forwarding rule somebody added in 2019. They are the highest-value target in the tenant and typically the least protected part of it.
Suppliers send email as the hotel, and the hotel signs in to theirs
Channel managers, booking engines, marketing platforms, EPOS receipt systems and the property management system all either send mail on the hotel’s behalf or hold credentials belonging to hotel staff. That two-way exposure is why email authentication and identity hygiene carry more weight in a Microsoft 365 for hotels build than in a comparable office tenant.
| Default assumption | What a hotel tenant actually looks like | Controls affected |
|---|---|---|
| One person, one account | Front desk, night audit and duty manager logins passed between shifts | 1, 2, 3, 16 |
| Everyone has a laptop | Shared PCs, kiosks, EPOS tills and personal phones | 10, 11, 12 |
| Mail arrives from known contacts | Unsolicited attachments from guests, agents and OTAs all day | 6, 7, 8 |
| Leavers are rare and planned | Seasonal, agency and casual staff joining and leaving weekly | 4, 5, 15 |
| One organisation sends our email | PMS, channel manager, booking engine and marketing tool all send as us | 9, 13 |
| IT is available when something breaks | A duty manager alone at 03:00 with no escalation path | 17, 18 |
The threat to Microsoft 365 for hotels is specific, not generic
Microsoft’s threat intelligence team documented a campaign that began in December 2024 in which the actor it tracks as Storm-1865 impersonated Booking.com in emails to hospitality staff across North America, Oceania, South and Southeast Asia and Europe. The lure was ordinary hotel business: a complaint about a negative review, a prospective booking, an account verification notice. The payload was a fake CAPTCHA page using the ClickFix technique, which instructs the reader to press Win+R and paste a command that runs through mshta.exe and installs credential stealers including XWorm, Lumma, VenomRAT, AsyncRAT, Danabot and NetSupport RAT.
The UK loss numbers are already published
Action Fraud recorded 532 reports and roughly £370,000 of losses between June 2023 and September 2024 from people who received messages from a hotel’s own booking platform account after that account had been taken over. Those takeovers were the result of phishing aimed at the accommodation provider, not a breach of the platform. That is a hospitality-specific consequence of weak identity controls, and it is the sharpest argument for treating Microsoft 365 for hotels as a security project rather than an email subscription.
Domain one: identity controls in Microsoft 365 for hotels
Identity is where the money is, and it is where any Microsoft 365 for hotels project should start. Every control below sits in Microsoft Entra ID, and every one of them is available on Microsoft 365 Business Premium without buying anything extra.
Control 1 — Give every human their own account
No shared front-desk login, no “reception1” that four people know the password to, no duty manager account passed on a sticky note. Where a device genuinely must stay signed in, use a device identity and a kiosk profile rather than a human account. This is the foundational control in Microsoft 365 for hotels because nothing else survives without it.
Evidence test: open the Entra ID user list, sort by last sign-in, and pick any three accounts. If you cannot name the single person who uses each one, you have failed this control.
Control 2 — Enforce MFA on every account without exception
Microsoft finished enforcing MFA for sign-ins to the Microsoft 365 admin centre on 9 February 2026, and mandatory MFA has already rolled out across the Azure and Entra admin portals. That covers administrators; it does not cover the reservations manager whose mailbox holds every guest’s card authorisation. Enforce multifactor authentication on all accounts, all locations and all times, and remove the exclusions somebody added during a busy weekend. In Microsoft 365 for hotels there is no account that legitimately sits outside that rule.
Evidence test: run the Entra sign-in log filtered to single-factor successes over the last 30 days. The correct answer is zero.
Control 3 — Move from security defaults to conditional access
Security defaults are a reasonable floor for a very small tenant, but they are all-or-nothing. Business Premium includes Entra ID P1, which unlocks conditional access, and Microsoft now deploys a set of Microsoft-managed policies to raise the baseline automatically. A workable Microsoft 365 for hotels policy set requires MFA for admins, requires MFA for everyone, blocks legacy authentication, and restricts access from countries the group has no business in.
Evidence test: the conditional access blade shows at least four policies in “On” state, not “Report-only”.
Control 4 — Separate and protect administrator access
Administration should not run from the account that reads guest email. Create dedicated admin accounts, keep at least two emergency access accounts excluded from conditional access and stored offline, and remove standing global administrator rights from anybody who does not need them daily. Most Microsoft 365 for hotels tenants turn out to hold three or four more global administrators than anybody thought, usually including a former IT supplier.
Evidence test: count the global administrators. More than four in a group under 300 staff needs a written justification.
Control 5 — Block legacy authentication and device code flow
Legacy protocols bypass MFA entirely, and device code flow is the technique behind a string of recent hospitality-adjacent intrusions. Microsoft’s own managed policies now block device code flow by default for tenants that have not used it in the past 25 days. Verify that yours is blocked rather than assuming it, which is a two-minute check in any Microsoft 365 for hotels tenant, and confirm nothing in the estate still needs basic authentication before you turn it off.
Evidence test: conditional access shows an enabled policy blocking legacy client apps and an enabled policy blocking device code flow.
A three-property group usually sits in the medium band, where roughly two in three organisations reported a breach or attack, and that is the population most Microsoft 365 for hotels work is aimed at. The same survey put formal incident response plans at 25% and board-level ownership at 31%, which is the gap this checklist is trying to close.
Domain two: email and the booking channel in Microsoft 365 for hotels
Email is the attack surface that pays, and it is the part of Microsoft 365 for hotels that guests, suppliers and criminals all touch every day. A hotel’s inbox is the one place where a stranger’s attachment is expected, and the one place where a changed bank detail turns into a payment.
Control 6 — Turn on Defender for Office 365 properly
Business Premium includes Microsoft Defender for Office 365 Plan 1. Turning it on is not the same as configuring it, and most Microsoft 365 for hotels tenants stop at the licence. Enable Safe Links with the setting that rechecks URLs at the moment of click, enable Safe Attachments, and confirm zero-hour auto purge is active so that mail already delivered can be pulled back when it is later found to be malicious. Microsoft named exactly these three settings in its guidance following the Booking.com impersonation campaign.
Control 7 — Configure impersonation protection for the names that matter
Anti-phishing policies let you protect specific users and specific domains against impersonation. In Microsoft 365 for hotels the list is short and obvious: the general manager, the finance contact, the reservations mailbox, the group’s own domain, and the domains of the booking platforms and channel managers the property actually uses. Without this, a message from a lookalike domain lands looking entirely normal.
Control 8 — Put a payment-change rule in front of the finance mailbox
Bank-detail fraud does not need malware. Add an external sender warning to inbound mail, and a transport rule that flags messages to the accounts mailbox containing phrases about changed bank details, new remittance instructions or updated payment information. Pair it with a written rule that no bank change is ever actioned from email alone. The same failure pattern is examined in detail in our analysis of business email compromise and hijacked supplier payments.
Control 9 — Fix SPF, DKIM and DMARC across every sender
List every system that sends email as the hotel: Microsoft 365 itself, the property management system, the booking engine, the channel manager, the marketing platform, the EPOS receipt sender and any scan-to-email device. Publish an SPF record that covers all of them, sign with DKIM, and move DMARC from none to quarantine once the reports are clean. A hotel that has not done this cannot credibly tell a guest that a fraudulent message did not come from it. Email authentication is the part of Microsoft 365 for hotels that protects people who are not your staff.
| Capability | Business Basic | Business Standard | Business Premium |
|---|---|---|---|
| Entra ID plan | Free | Free | P1 (conditional access) |
| Defender for Office 365 | No | No | Plan 1 |
| Defender for Business (endpoint) | No | No | Yes |
| Intune device management | No | No | Plan 1 |
| Purview information protection and DLP | No | No | Yes |
| Desktop Office apps | No | Yes | Yes |
| UK list price per user per month | £5.40 | £18.10 with Copilot | £24.60 with Copilot |
The row that decides everything is the first one. Conditional access, Intune, Defender for Business and Purview all arrive together with Business Premium, which is why almost every serious Microsoft 365 for hotels design ends up there for its office-based staff. Costing a Microsoft 365 for hotels rollout starts from that same row. Microsoft’s UK storefront now leads with Copilot-bundled pricing; the base Business Premium rate without Copilot is £16.90 per user per month on an annual commitment, ex VAT.
Domain three: devices and kiosks in Microsoft 365 for hotels
Control 10 — Enrol every hotel-owned PC in Intune
Front-desk PCs, back-office machines and duty-manager laptops should all be enrolled, because an unmanaged device is a blind spot in any Microsoft 365 for hotels estate. Enrolment gives you disk encryption status, patch state, a remote wipe path and the ability to require a compliant device in conditional access. Cyber Essentials treats an organisation-owned device as in scope even when a customer is the one using it, which catches the lobby PC and the business-centre machine most hotels forget.
Control 11 — Handle shared devices as shared devices
Microsoft’s frontline worker licensing exists precisely for this pattern: staff who work on shared devices, on the web and on mobile rather than at a desk. Configure automatic sign-out on shared machines, which is the single most visible Microsoft 365 for hotels change reception will notice, use shared device mode where the app supports it, and make the kiosk a kiosk rather than a general-purpose Windows PC left on the reception desk. The physical hardening that goes with it is covered in our wider hotel cyber security checklist.
Control 12 — Enable Defender for Business and attack surface reduction
ClickFix works by persuading a human to run a command. Attack surface reduction rules that block obfuscated scripts, block executable content from email, block JavaScript from launching downloaded content and block credential theft from LSASS break that chain even when the human co-operates. Turn on cloud-delivered protection, network protection and automated investigation in full mode while you are there. Attack surface reduction is the highest-value endpoint setting in Microsoft 365 for hotels because it breaks that chain without needing the user to behave.
The 23 shared and administrative identities are only a tenth of the tenant, and they carry almost all of the risk. Every Microsoft 365 for hotels programme should start there rather than at the bottom of the list.
Domain four: guest data and retention in Microsoft 365 for hotels
Control 13 — Use Purview DLP to stop card numbers moving through email
Guests email card details. Agents email card details. Staff paste card details into a booking note because the phone line was bad. Purview data loss prevention policies detect credit card numbers in mail, chat and files and can block, warn or simply report. Start in report-only mode for a fortnight to see the real volume before you switch on blocking, because the first run is usually a surprise. A first Microsoft 365 for hotels data loss prevention report normally finds card numbers in places nobody predicted.
Control 14 — Set retention that matches the reservation lifecycle
Guest records are personal data under UK data protection law and should not sit in a mailbox forever because nobody set a policy. Define how long reservation correspondence, event enquiries, CCTV requests and HR records are kept, then implement it with Purview retention labels and policies. Retention is also what stops a compromised mailbox from handing over fifteen years of guest history in one export, and it is the quietest control in Microsoft 365 for hotels.
Control 15 — Control external sharing and guest accounts
Agencies, event organisers, marketing agencies and franchise partners all end up with guest accounts or shared links in the tenant. Restrict what guest users can see in the directory, set links to expire, review the guest list quarterly, and remove suppliers whose contract ended. Guest accounts accumulate faster in Microsoft 365 for hotels than in any office tenant. This is unglamorous work that quietly closes the door somebody left open two contracts ago.
| Hotel role | Typical need | Sensible licence |
|---|---|---|
| General manager, finance, revenue, sales, HR | Desktop apps, mailbox, managed laptop, conditional access | Business Premium |
| Reservations and events team | Heavy mailbox use, DLP, impersonation protection | Business Premium |
| Duty managers and night audit | Named account, MFA, mobile access, shared PC | Business Premium or F3 |
| Reception, housekeeping, kitchen, F&B | Identity, Teams, rota, no desktop apps | Frontline F1 or F3 |
| reservations@, events@, accounts@ | Shared mailbox with delegated access | No licence under 50 GB |
| PMS, EPOS and scan-to-email senders | Send only, moving off basic authentication | Service account, no interactive sign-in |
Frontline F1 gives identity, Teams, SharePoint access and shift tools without an Exchange mailbox; F3 adds a 2 GB mailbox plus web and mobile Office apps, Windows Enterprise rights, Intune Plan 1 and Entra ID P1. F1 supports shared device licensing by default, which is the practical reason it fits a reception desk better than an enterprise SKU does, and that split is what keeps Microsoft 365 for hotels affordable across a whole estate.
Domain five: monitoring Microsoft 365 for hotels and the 3 a.m. problem
Control 16 — Turn on auditing and actually alert on something
The unified audit log is the record you will need if a mailbox is compromised, and Entra ID Protection surfaces risky sign-ins. Configure diagnostic settings to retain sign-in and audit logs beyond the default window, then create alerts for four events: a new inbox forwarding rule, a mailbox permission change, a new global administrator, and a sign-in from an unusual country. Those four alerts cover most of what actually happens inside a compromised Microsoft 365 for hotels tenant.
Control 17 — Understand what Microsoft does not back up for you
Microsoft protects the platform, not your decisions. Retention and litigation hold are not a backup, and a shared mailbox under 50 GB has no archive and no hold by default. Decide deliberately whether you are buying Microsoft 365 Backup, a third-party product, or accepting the risk in writing. The right answer differs by group; the wrong answer is not having had the conversation. Backup is the one line in a Microsoft 365 for hotels design that is a business decision rather than a technical one.
Control 18 — Write an incident path a duty manager can run at 03:00
Every control above assumes somebody eventually notices. In Microsoft 365 for hotels that person is a duty manager with no IT background, at night, alone. They need one card: who to phone, how to disable an account, how to stop a payment, when to call the bank, and when the ICO clock starts. Test it once. Our IT support model for hotels and hospitality businesses exists mostly because this control is the one that is never in place.
The Microsoft 365 for hotels scorecard
Score each control red, amber or green. Red means the control does not exist. Amber means it exists somewhere but not everywhere, or nobody can produce evidence. Green means you passed the evidence test at every property this quarter. A first honest pass through a Microsoft 365 for hotels scorecard usually produces more red than anybody expects, which is the point of running it.
| # | Control | Domain | Evidence in ten minutes |
|---|---|---|---|
| 1 | One account per human | Identity | Name the owner of three random accounts |
| 2 | MFA everywhere, no exclusions | Identity | Zero single-factor successes in 30 days |
| 3 | Conditional access in place | Identity | Four or more policies set to On |
| 4 | Admin separation and break-glass | Identity | Global admin count and owner list |
| 5 | Legacy auth and device code blocked | Identity | Two enabled blocking policies |
| 6 | Safe Links, Safe Attachments, ZAP | Policy pages show enabled, not default | |
| 7 | Impersonation protection configured | Protected users and domains listed | |
| 8 | Payment-change rule and warning | Transport rule exists and fires | |
| 9 | SPF, DKIM and DMARC complete | DNS lookup plus a sender inventory | |
| 10 | Hotel PCs enrolled in Intune | Devices | Device count matches the asset list |
| 11 | Shared devices configured as shared | Devices | Auto sign-out demonstrated at reception |
| 12 | Defender for Business and ASR on | Devices | ASR rules in block, not audit |
| 13 | DLP for card data | Data | Policy exists and has recent matches |
| 14 | Retention matches the record type | Data | Published schedule and live labels |
| 15 | Guest access reviewed | Data | Guest list dated within 90 days |
| 16 | Auditing on with four alerts | Monitoring | Alert rules exist and have fired |
| 17 | Backup decision documented | Monitoring | A written decision, either way |
| 18 | Night-time incident card tested | Monitoring | A duty manager can produce it |
A worked example: Microsoft 365 for hotels in a three-property group
Take a group of three hotels with 128, 96 and 64 bedrooms, so 288 bedrooms in total, plus a small head office. It is a realistic shape for Microsoft 365 for hotels in the UK independent market. The group employs 214 named people. Of those, 48 are office and management staff who need desktop applications and a full mailbox, and 166 are frontline staff in reception, housekeeping, kitchen, food and beverage and maintenance. On top of the named people sit 17 shared or generic mailboxes and 6 administrator accounts, giving 237 identities in total.
Twenty-three of those 237 identities are shared or privileged, just under a tenth of the tenant. Those 23 are where a Microsoft 365 for hotels remediation plan starts, because they are the accounts that cannot be tied to one person, cannot easily be MFA-enrolled without planning, and carry the most authority when they are compromised.
What Microsoft 365 for hotels costs at list price
Using the base Business Premium rate of £16.90 for the 48 office and management staff gives £811.20 a month. Licensing the 166 frontline staff on F1 at roughly £2.00 each adds £332.00 a month. The total is £1,143.20 a month, or £13,718.40 a year, which works out at £47.63 per bedroom per year across the 288 bedrooms.
What that buys against what it prevents
Set that £13,718.40 against the £370,000 that Action Fraud recorded across 532 reports in a fifteen-month window, or against a single redirected supplier payment. The arithmetic is not close. The licences are not the expensive part of a Microsoft 365 for hotels programme; the configuration work and the ownership are, and both are one-off in a way the fraud is not.
| Line | Count | Unit per month | Monthly total |
|---|---|---|---|
| Business Premium, office and management | 48 | £16.90 | £811.20 |
| Frontline F1, shift staff | 166 | £2.00 | £332.00 |
| Shared mailboxes under 50 GB | 17 | £0.00 | £0.00 |
| Break-glass and admin accounts | 6 | Included | £0.00 |
| Group total | 237 | — | £1,143.20 |
The 90-day sequence for Microsoft 365 for hotels
Doing all 18 controls at once fails, because half of them need a change to how reception works and reception is busy. Sequencing is what makes a Microsoft 365 for hotels programme survive a season. Sequence them so the highest-value identity work lands first and the slower cultural changes come last.
Days 1 to 30: stop the bleeding
Controls 1 to 5 plus control 6. Named accounts, MFA everywhere, conditional access, admin separation, legacy authentication and device code blocked, and Defender for Office 365 configured. Seven controls, and they remove most of the paths an attacker actually uses. Anyone running Microsoft 365 for hotels with limited time should stop after this month and still be ahead of the sector.
Days 31 to 60: harden the channel and the endpoints
Controls 7 to 12. Impersonation protection, the payment-change rule, email authentication, Intune enrolment, shared device configuration and Defender for Business with attack surface reduction. That takes cumulative coverage to 13 of the 18 controls, and it is the point at which Microsoft 365 for hotels stops being a licence and starts being a control set.
Days 61 to 90: data, monitoring and the incident card
Controls 13 to 18. DLP, retention, guest access review, auditing and alerts, the backup decision and the night-time incident card. These need conversations with people outside IT, which is exactly why they belong at the end rather than the beginning.
The basic authentication deadline nobody has diarised
Exchange Online is retiring basic authentication for SMTP client submission. Microsoft’s current position is that basic authentication for SMTP AUTH remains usable until the end of December 2026, after which it is disabled. In Microsoft 365 for hotels that matters far more than it does in an office, because the things still using it are rarely obvious: the property management system sending confirmations, the EPOS emailing receipts, the scan-to-email function on the back-office printer, and an old booking form on the website.
Inventory those senders now and move each one to OAuth, to a supported relay, or to a modern replacement. Doing this discovery late is how a hotel loses its confirmation emails on a bank holiday weekend. It is also a good forcing function for control 9, since one sender inventory answers both questions and both belong to the same Microsoft 365 for hotels owner.
Mapping the checklist to Cyber Essentials, PCI DSS and UK law
Nothing in this Microsoft 365 for hotels checklist is invented. Every control maps to something a certification body, a card scheme or a regulator already expects, which makes it easier to justify the work upstairs.
| Controls | Cyber Essentials | PCI DSS | UK data protection |
|---|---|---|---|
| 1-5 Identity | User access control; MFA on cloud services is an auto-fail question | Unique IDs and MFA for access to cardholder data | Appropriate technical measures |
| 6-9 Email | Malware protection and secure configuration | Anti-malware and awareness | Confidentiality of personal data |
| 10-12 Devices | Secure configuration, update management, malware protection | Secure systems and software | Security of processing |
| 13-15 Data | Scope definition and cloud responsibility | Protect stored account data | Storage limitation and minimisation |
| 16-18 Monitoring | Not a technical requirement, but expected evidence | Logging and monitoring | 72-hour breach reporting to the ICO |
Cyber Essentials is worth pursuing alongside this work rather than after it, because the certification questions and a Microsoft 365 for hotels checklist overlap heavily. The scoping detail specific to hotels is set out in our Cyber Essentials certification guide for hotels, including how a segregated guest network is treated. On the network side, the companion pieces on hotel WiFi security and on captive portal attacks against hotel guest networks cover the parts of the estate that sit outside the tenant.
Who owns Microsoft 365 for hotels in a group
The honest answer in most groups is nobody. The general manager assumes head office owns it, head office assumes the supplier owns it, and the supplier is contracted for break-fix. That ambiguity is the reason a good cybersecurity posture decays even in groups that once paid for a review, and it is why Microsoft 365 for hotels needs a named owner rather than a project.
Name one owner per property and one for the group
The property owner does the operational checks: leavers disabled, shared devices signing out, the incident card on the wall. The group owner holds the tenant configuration, the licence position and the evidence pack. Two names, written down, reviewed quarterly, and both of them accountable for Microsoft 365 for hotels rather than for IT in general.
Put the checks in an existing rhythm
Attach the control checks to a meeting that already happens. A ten-minute slot in the monthly heads-of-department meeting covers the operational half, and a quarterly review with your IT provider covers the tenant half. Anything that needs its own new meeting will not survive a busy season, which is why a Microsoft 365 for hotels programme should ride on rhythms the business already keeps.
Decide what part of Microsoft 365 for hotels you outsource
Most independent groups cannot staff conditional access design, DLP tuning and alert triage internally, and should not try. A managed provider can hold the tenant, run the alerts and produce the evidence pack, while the properties keep the operational checks. Our managed IT services and incident response pages set out how that split usually works in practice.
Frequently asked questions about Microsoft 365 for hotels
Is Microsoft 365 Business Premium enough for a hotel group?
For almost all independent and small-group operators, Business Premium is the right answer for Microsoft 365 for hotels. It carries Entra ID P1, Intune, Defender for Business, Defender for Office 365 Plan 1 and Purview information protection, which delivers every control in this checklist. Business plans cap at 300 users, so a group above that moves to enterprise licensing, but capability is rarely the reason.
Can frontline staff be left unlicensed?
Only if they never touch a hotel system. In practice reception, housekeeping and kitchen staff use rotas, checklists and messaging, so they need an identity. An unlicensed person on a shared login is the Microsoft 365 for hotels failure this checklist exists to prevent, and F1 is cheap enough that the argument for shared credentials disappears.
What about the property management system and EPOS?
They sit outside the tenant, but they interact with it constantly through service accounts, email senders and staff credentials. Treat every integration as a supplier relationship with a named owner, an authentication method and an offboarding step, and record it next to your Microsoft 365 for hotels documentation. The wider estate view is covered in our hotel cyber security checklist.
How long does a Microsoft 365 for hotels rollout take?
Ninety days with somebody accountable, working alongside a normal operational load. The first thirty days deliver most of the risk reduction. Groups that try to compress all 18 controls into a fortnight usually break something at reception and lose the internal support they needed.
Does any of this stop a ClickFix attack?
Several controls do, at different points. Safe Links and zero-hour auto purge address the message, attack surface reduction rules address the pasted command, MFA and conditional access limit what stolen credentials achieve, and alerting on new forwarding rules catches what survives. No single control is sufficient, which is the argument for treating Microsoft 365 for hotels as a set rather than a shopping list.
References
Phishing campaign impersonates Booking.com, delivers a suite of credential-stealing malware
ClickFix Phishing Scam Impersonates Booking.com to Target Hospitality
Microsoft Warns of Hospitality Sector Attacks Involving ClickFix
Plan for mandatory Microsoft Entra multifactor authentication
Microsoft-managed Conditional Access policies
Block authentication flows with Conditional Access policy
Security defaults in Microsoft Entra ID
Manage emergency access accounts in Microsoft Entra ID
What is Microsoft Entra ID Protection?
Safe Links in Microsoft Defender for Office 365
Anti-phishing policies in Microsoft 365
Zero-hour auto purge in Exchange Online
What is Microsoft Defender for Business?
Understand frontline worker user types and licensing
Manage devices for frontline workers
Learn about data loss prevention
Learn about retention policies and retention labels
Search the audit log in the Microsoft Purview portal
Restrict guest access permissions in Microsoft Entra ID
Overview of Microsoft 365 Backup
Exchange Online to retire Basic auth for Client Submission (SMTP AUTH)
Set up a multifunction device or application to send email using Microsoft 365
Compare all Microsoft 365 Business plans
Cyber Security Breaches Survey 2025/2026
IASME guidance on Cyber Essentials scope
NCSC Incident Management collection
NCSC: Incidents impacting retailers
NCSC Small Business Guide to Cyber Security
ICO: Report a personal data breach