Microsoft 365 setup for hotels is a different project from the office rollout most IT providers know how to do. An accountancy practice has forty people, forty desks and forty mailboxes. A hotel has a front desk that four people share across three shifts, a housekeeping floor that never touches a keyboard, a reservations inbox that half a dozen staff answer from, a property management system that emails folios, a scanner in the back office that has been relaying mail with a saved password since 2019, and a general manager who wants all of it on a phone.
A Microsoft 365 setup for hotels has to be built around that shape, not retrofitted to it afterwards.
This guide is the build. It covers the decisions you make before you buy a licence, the tenant foundations, the licence mix by role, the identity model for people who share a desk, the conditional access that goes with it, shared mailboxes for reservations and events, the mail flow that keeps the PMS and the scan-to-email working after basic authentication goes away, Teams and Shifts for frontline staff, an information architecture for a hotel group, device profiles for shared front-desk PCs, guest-data retention, and what the whole thing costs.
Our companion piece, the Microsoft 365 security checklist for hotels, audits a tenant that already exists; this one builds it. The equivalent build for a different sector is our Microsoft 365 for property management companies guide.
Everything below is written for a UK operator with a small in-house team or none at all, running one to five properties. There are eight tables, three charts, a fully costed three-property worked example with 314 bedrooms and 294 identities, a 90-day plan and a reference list of primary sources. Prices are UK list, ex VAT, annual commitment, verified from Microsoft’s UK storefront on 18 August 2026. Where a date or a limit matters, it is quoted from Microsoft’s own documentation rather than paraphrased.
Table of contents
- Why a Microsoft 365 setup for hotels is not an office rollout
- The six decisions that shape a Microsoft 365 setup for hotels
- Tenant foundations: domains, DNS and the things you cannot change later
- Licensing a Microsoft 365 setup for hotels role by role
- Identity: building accounts for people who share a desk
- Conditional access and MFA in a Microsoft 365 setup for hotels
- Email: reservations@, info@ and the shared mailbox rules
- Mail flow for the PMS, POS and scan-to-email
- Teams in a Microsoft 365 setup for hotels: channels, Shifts and the frontline experience
- SharePoint and OneDrive in a Microsoft 365 setup for hotels
- Devices and Intune in a Microsoft 365 setup for hotels
- Guest data, retention and compliance in a Microsoft 365 setup for hotels
- Multi-property: one tenant, many hotels
- What a Microsoft 365 setup for hotels costs: a three-property worked example
- A 90-day Microsoft 365 setup for hotels rollout plan
- Mistakes that make a Microsoft 365 setup for hotels fail
- Frequently asked questions about Microsoft 365 setup for hotels
- References and further reading
Why a Microsoft 365 setup for hotels is not an office rollout
The temptation is to treat a hotel as a small business with an unusual address. It is not. Six structural differences change the design of a Microsoft 365 setup for hotels, and every one of them costs money or creates a security hole if you discover it in week nine instead of week one.
Headcount and identity count are different numbers in a Microsoft 365 setup for hotels
In an office they are close enough to be interchangeable. In hospitality they are not. A 142-bedroom hotel might employ 120 people but need only 45 mailboxes, because housekeeping, kitchen and F&B staff communicate through a rota and a WhatsApp group nobody sanctioned. A Microsoft 365 setup for hotels has to count identities in three buckets — full information workers, licensed frontline workers, and shared or functional accounts — because those buckets carry completely different SKUs, and one of them carries no Exchange mailbox at all.
Devices are shared, and shared devices break the standard identity model
Microsoft 365 for a single-site accountancy practice is a straightforward build because one human sits at one machine. A front desk is the opposite. Three receptionists, two duty managers and a night porter use the same PC across 24 hours, and the person leaving the shift must not still be signed in when the next one starts. That single requirement drives licence choice, device enrolment method, session controls and sign-out policy, and it is the fact that most distinguishes a Microsoft 365 setup for hotels from any office build.
A Microsoft 365 setup for hotels carries email no human wrote
The property management system emails confirmations. The point of sale emails receipts. The scanner emails passport copies to the front office. The banqueting system emails function sheets. These are the connections that break first when authentication changes, and the ones nobody documents. A section of this guide is dedicated to them because in a hotel they are not an edge case; they are the daily operating pattern.
The estate never closes
There is no maintenance window at 7pm on a Tuesday. There is a slow Wednesday in February. Every change in a Microsoft 365 setup for hotels has to be reversible within one shift, and the rollout plan has to assume the person who notices a problem is a duty manager at 23:40, not an IT administrator.
Staff turnover is high and offboarding is often informal
Hospitality churn is structural. UKHospitality counts 3.6 million people working in the sector, and hotels specifically employ around 383,600 people in the UK. When a seasonal starter leaves without an exit process, an unlicensed but still-enabled account is an open door. The joiner-mover-leaver process is part of the build, not an afterthought — the same principle we set out in our hotel cyber security checklist.
A Microsoft 365 setup for hotels holds more sensitive data than the sector assumes
Passport scans, card tokens, dietary requirements, accessibility notes, allergen records, the names of people staying in the same room. A hotel handles special category data casually and constantly. Any Microsoft 365 setup for hotels has to put retention and access controls on that data at build time, when it costs nothing, rather than after an incident, when it costs everything.
| Design factor | Standard office build | Hotel build |
|---|---|---|
| Identity model | One person, one account, one device | Named accounts plus shared-device sign-in and functional mailboxes |
| Licence mix | Single SKU for almost everyone | Three tiers: Business Premium, F3, F1 |
| Primary device | Assigned laptop | Shared desktop, shared handset, personal phone |
| Mail senders | People | People, PMS, POS, scanner, banqueting, channel manager |
| Change window | Evenings and weekends | No true window; low-occupancy midweek only |
| Joiner/leaver rate | Low, HR-driven | High and seasonal, often verbal |
| Data sensitivity | Commercial | Identity documents, payment tokens, health and dietary notes |
| Who reports faults | The affected user | A duty manager mid-shift, often at night |
The six decisions that shape a Microsoft 365 setup for hotels
Six choices determine everything downstream in a Microsoft 365 setup for hotels. Make them explicitly, write them down, and the rest of the build is mechanical. Skip them and you will rebuild something expensive in month four.
Decision one: one tenant or one per property
One tenant for the whole group, almost always: a single Microsoft 365 setup for hotels beats one tenant per property. Multiple tenants mean multiple domains, duplicate policies, no shared calendar, no cross-property Teams and a licensing mess. The exceptions are genuine ones: a franchised property with a separate legal entity and its own brand domain, or a management contract that ends on a known date. Multi-property separation inside one tenant is a solved problem, covered later in this guide.
Decision two: which domain sends guest email
Guests receive email from the property, from the brand, or from both. Decide before you add a domain, because the answer determines your SPF, DKIM and DMARC records, and those records determine whether the PMS confirmations land in the inbox or the junk folder. A group running brandhotels.co.uk plus three property domains needs authentication records on all four, not one.
Decision three: how far down the org chart licences go
The single biggest cost lever in a Microsoft 365 setup for hotels. Does the room attendant get an account? If yes, does that account need a mailbox? Most operators land on: yes to an identity, no to a mailbox, because Teams and Shifts on a phone are what the role actually needs. That answer is what makes an F1 licence viable at roughly a tenth of the cost of a full seat.
Decision four: what the front desk signs into
Named accounts on a shared PC, a shared kiosk account, or shared device mode on a managed device. The first is correct and slightly slower. The second is convenient and indefensible. The third is the modern answer for tablets and handsets. A Microsoft 365 setup for hotels that gets this wrong produces the single most common audit finding in hospitality: one reception login, password on a sticky note, never rotated.
Decision five: whether the PMS stays on basic authentication
It cannot, for long. Microsoft’s published timeline leaves SMTP AUTH basic authentication unchanged through December 2026, disables it by default for existing tenants at the end of December 2026 with administrators still able to re-enable it, and makes it unavailable by default for tenants created after that. A final removal date will be announced in the second half of 2027. Plan the connector or OAuth migration now, not in the week it stops.
Decision six: who owns the tenant after go-live
Named person, named deputy, written. In a hotel the answer is rarely “the IT company” alone, because someone on site has to create a starter account at 6am. A Microsoft 365 setup for hotels should end with two or three delegated roles scoped to what reception actually needs, not a global administrator credential shared by the management team.
Tenant foundations: domains, DNS and the things you cannot change later
Some settings in a Microsoft 365 setup for hotels are cheap now and expensive forever. Get these right in week one.
The default domain that outlives your Microsoft 365 setup for hotels
Your tenant gets an onmicrosoft.com name at creation and it cannot be changed. Choose the group name, not a property name, and not a name that includes a brand you might lose in a franchise change. It appears in SharePoint URLs for the life of the tenant.
Custom domains and the record set
Add every sending domain and verify it. Each needs MX, SPF, DKIM selectors, DMARC and the Autodiscover record. In hospitality, DMARC matters more than in most sectors because brand impersonation of hotels is an active, documented attack pattern that shows up repeatedly in vendor threat intelligence: Microsoft’s security researchers tracked a campaign from December 2024 in which attackers impersonated Booking.com to target hospitality staff, using a fake CAPTCHA that walked the victim through pressing Win+R and pasting a command, delivering XWorm, Lumma, VenomRAT, AsyncRAT, Danabot and NetSupport RAT.
Naming conventions for groups, sites and teams in a Microsoft 365 setup for hotels
Set them in the Microsoft 365 setup for hotels before the first team is created. A workable pattern for a group is PROP-<code>-<function> for property-scoped objects and GRP-<function> for group-wide ones. It takes ten minutes at build time and saves a rename project later. Dynamic membership rules depend on clean attributes, so decide at the same time which Entra ID attributes carry the property code, the department and the employment type.
Regional settings, retention defaults and the audit log
Set the tenant to United Kingdom and Europe/London, set the default document library retention before anyone uploads anything, and confirm audit logging is on and searchable. A Microsoft 365 setup for hotels without audit search is a tenant you cannot investigate, and the first time you need it will be the morning after someone accessed a folio they should not have.
Licensing a Microsoft 365 setup for hotels role by role
Licensing is where the budget for a Microsoft 365 setup for hotels is won and lost. The mistake is uniformity: buying one SKU for everyone because it is simpler. The correct approach is three tiers mapped to three genuinely different jobs.
What each SKU delivers in a Microsoft 365 setup for hotels
Business Premium is the only Business plan that carries Entra ID P1, Intune Plan 1, Defender for Business, Defender for Office 365 Plan 1 and Purview information protection. Business Standard has the apps but none of the security layer. Frontline F1 gives an identity, Entra ID, Teams and SharePoint access, with no Exchange mailbox and shared device licensing by default. F3 adds a 2 GB mailbox, web and mobile Office apps, Windows 11 Enterprise rights, Intune Plan 1 and Entra ID P1.
The F1 trap that decides your whole security design
F1 carries no Entra ID P1. No Entra ID P1 means conditional access policies cannot be scoped to those users. That is the most consequential licensing fact in any Microsoft 365 setup for hotels, and it produces one of two designs: either your F1 population is deliberately restricted to Teams and Shifts on managed shared devices with no mailbox and no document access, or you move the roles that need policy coverage up to F3 and accept the cost. Decide consciously. Do not discover it during a Cyber Essentials assessment.
UK list prices for a Microsoft 365 setup for hotels, verified 18 August 2026
Per user per month, ex VAT, annual commitment: Business Basic £5.40, Business Standard with Copilot £18.10, Business Premium with Copilot £24.60, Apps for business £9.80. Base non-Copilot Business Premium remains £16.90. Frontline F1 is approximately £2.00 and F3 approximately £6.30 to £7.20. All three Business plans are capped at 300 users, which is a real constraint for a group of five full-service properties and not a theoretical one.
| Role group | Recommended SKU | UK price/user/month | Mailbox | Conditional access |
|---|---|---|---|---|
| GM, revenue, sales, finance, head office | Business Premium | £16.90 (£24.60 with Copilot) | 100 GB | Yes (Entra ID P1) |
| Reception, duty managers, supervisors | Frontline F3 | £6.30–£7.20 | 2 GB | Yes (Entra ID P1) |
| Housekeeping, kitchen, F&B, maintenance | Frontline F1 | ~£2.00 | None | No (no Entra ID P1) |
| Reservations, info, events inboxes | Shared mailbox | £0 up to 50 GB | 50 GB | Inherited from the accessing user |
| PMS, POS, scanner senders | Connector or HVE account | £0 (no licence required) | None | Not applicable |
| Break-glass administrators | Business Premium | £16.90 | 100 GB | Excluded by design, phishing-resistant MFA |
Identity: building accounts for people who share a desk
This is the section that separates a working Microsoft 365 setup for hotels from a compliant-looking one. Shared work is the norm in hospitality, and the tenant has to model it honestly.
Named accounts, always — including for the night porter
Every human gets their own account. Not because it is tidy, but because audit search, message trace, sign-in risk and offboarding are all keyed to a user object. A shared frontdesk@ login destroys all four at once. If the objection is that signing in takes too long between guests, the answer is shared device mode and a fast credential, not a shared password.
Shared device mode and Temporary Access Pass
Entra ID shared device mode makes a device a device, not a person’s device. A worker signs in, the apps show their data, they sign out at the end of the shift, and the next worker gets a clean session. It is supported on iOS, Android and Windows and is the correct pattern for housekeeping handsets and front-desk tablets. For onboarding, a Temporary Access Pass gives a new starter a time-limited credential to register a passkey or authenticator without an administrator ever knowing their password.
Passkeys beat SMS, and the front desk is where you prove it
Phishing-resistant methods — passkeys and FIDO2 security keys — are faster at a front desk than typing a code from a phone that is in a locker. That is a genuine operational argument, not a security lecture. Where a shift worker has no personal device and no key, a hardware token issued per shift and signed in and out at handover is the fallback. Microsoft’s own guidance for hospitality after the Booking.com campaign was explicit: phishing-resistant MFA with no exclusions.
The groups that drive everything else in a Microsoft 365 setup for hotels
Build dynamic groups from Entra ID attributes on day one: property code, department, employment type. Every licence assignment, every conditional access policy, every Teams membership and every Intune profile should target a group, never a person. This is the mechanism that makes a Microsoft 365 setup for hotels survive a 40 per cent annual staff turnover without a single manual reassignment.
Joiners, movers and leavers in a Microsoft 365 setup for hotels
Write the three flows into the Microsoft 365 setup for hotels before go-live. A joiner needs an account, a group, a device and a Temporary Access Pass. A mover — housekeeping to reception is the classic — needs an attribute change and nothing else if your groups are dynamic. A leaver needs the account disabled the same day, sessions revoked, and the mailbox converted to shared if there is anything in it worth keeping.
Conditional access and MFA in a Microsoft 365 setup for hotels
Security in a Microsoft 365 setup for hotels is not a phase that happens after the tenant works. It is a set of policies you create before the first mailbox is used.
Start from the enforced baseline
Microsoft has been enforcing MFA across admin portals since October 2024, reaching all tenants by March 2025, with a Microsoft 365 admin centre deadline of 9 February 2026. Phase 2, covering Azure Resource Manager access through CLI, PowerShell, the SDK and infrastructure-as-code, began on 1 October 2025 and is postponable only to 1 July 2026. Microsoft-managed conditional access policies now block device code flow by default for tenants that have not used it in the past 25 days. Your Microsoft 365 setup for hotels starts above that baseline, not at it.
The five conditional access policies every Microsoft 365 setup for hotels needs
Require MFA for all users, with break-glass accounts excluded and monitored. Block legacy authentication outright. Require compliant or hybrid-joined devices for access to SharePoint and Exchange from unmanaged endpoints. Require phishing-resistant MFA for anyone holding an administrative role. Restrict sign-in from countries the business never operates in, then review that list quarterly rather than never.
Session controls belong at the front desk
Sign-in frequency and persistent browser session settings are the difference between a shared PC that logs out and one that does not. Set sign-in frequency to match the shift pattern and disable persistent browser sessions on unmanaged devices. This is a five-minute policy that closes the single most common physical risk in a hotel: an unattended terminal in a public lobby.
Where the F1 population sits
Because F1 has no Entra ID P1, the policies above cannot target those users. That is why the frontline design in this guide keeps F1 users on managed shared devices with Teams and Shifts only and no mailbox. If any F1 role genuinely needs mail or document access from a personal phone, it is an F3 role. Making that call at design time is one of the quiet marks of a well-planned Microsoft 365 setup for hotels.
Email: reservations@, info@ and the shared mailbox rules
Every Microsoft 365 setup for hotels runs on functional inboxes, and every hotel gets the object type wrong at least once.
Four mail objects, four jobs in a Microsoft 365 setup for hotels
A user mailbox belongs to a person. A shared mailbox is a licence-free inbox up to 50 GB that several people open from their own accounts, with full audit trail intact. A distribution list fans a message out to individuals. A Microsoft 365 group gives a shared inbox plus a SharePoint site, a calendar and a Teams-capable identity. Reservations wants a shared mailbox. All-staff announcements want a distribution list. A wedding-and-events team wants a group.
The shared mailbox limits that catch people out
Licence-free up to 50 GB, with no archive and no litigation hold. Cross any of those three lines and the mailbox needs an Exchange Online Plan 2 licence, which lifts it to 100 GB. Users still need their own licence to open it. A busy reservations inbox at a 140-bedroom property will approach 50 GB faster than anyone expects once ten years of attachments accumulate, so set a retention policy on it at build time.
| Need | Correct object | Licence | Why |
|---|---|---|---|
| reservations@ | Shared mailbox | Free to 50 GB | Several staff answer from one thread with per-user audit |
| events@ / weddings@ | Microsoft 365 group | Free | Needs files, a calendar and a Teams channel, not just mail |
| allstaff@ | Distribution list | Free | One-way fan-out, no shared storage required |
| noreply@ from the PMS | Connector sender address | Free | No mailbox needed; address only has to be in an accepted domain |
| gm@property | User mailbox | Business Premium | A named person accountable for the property |
| Departed staff member | Convert to shared | Free to 50 GB | Keeps history without paying for a leaver’s seat |
Delegation, send-as and the audit trail
In a Microsoft 365 setup for hotels, grant Full Access plus Send As on shared mailboxes so replies come from the inbox rather than the individual. Avoid Send On Behalf for guest-facing mail; guests find on behalf of confusing and it undermines the brand. Every action still resolves to the individual account in audit search, which is exactly the property a shared password destroys.
Protecting the inbox that receives the attacks
Reservations and events inboxes receive attachments from strangers all day. That is their job. Configure Safe Links with recheck-on-click, Safe Attachments, anti-phishing impersonation protection for your own domains and senior staff, and zero-hour auto purge. In the Booking.com campaign, Microsoft named exactly these controls — phishing-resistant MFA, Safe Links recheck-on-click, ZAP, SmartScreen, network protection and attack surface reduction rules — as the defences that mattered.
Mail flow for the PMS, POS and scan-to-email
Mail flow is the part of a Microsoft 365 setup for hotels that gets skipped and then causes a Saturday outage. In hospitality it is not optional, because the systems that email guests are the systems that take money.
Four sending methods, and only two suit a Microsoft 365 setup for hotels
Microsoft documents four ways for a device or application to send mail: client SMTP submission, SMTP relay through a connector, Direct Send, and High Volume Email. Client SMTP submission needs a licensed mailbox, uses port 587 or 25, requires TLS 1.2 or 1.3, and is throttled at 10,000 recipients per day and 30 messages per minute.
SMTP relay uses port 25, authenticates with a TLS certificate or a static IP, needs no licensed mailbox, and carries higher limits. Direct Send can only deliver to your own domains — and Microsoft states plainly that most customers do not need it and that an option to disable it by default is being developed. High Volume Email uses port 587, is internal-only, and has no recipient or message rate limits.
| Method | Port | Authentication | External recipients | Limits | Hotel use |
|---|---|---|---|---|---|
| Client SMTP submission | 587 or 25 | Mailbox credentials; OAuth recommended | Yes | 10,000 recipients/day, 30 msg/min | Small apps that must save to Sent Items |
| SMTP relay (connector) | 25 | TLS certificate or static IP | Yes | Reasonable-use limits | PMS confirmations, POS receipts — the default choice |
| Direct Send | 25 | None | No | Anonymous-inbound throttling | Legacy scanners only; being deprecated by default |
| High Volume Email | 587 | HVE account or OAuth | No | No recipient or rate limits | Internal bulk notifications, rota alerts |
Build a sender inventory before you change anything
Walk the building before you change the Microsoft 365 setup for hotels. List every device and application that sends mail, the address it sends from, the method it uses, and who notices when it stops. In a typical full-service hotel the list runs to eight or ten entries: PMS, POS, the back-office multifunction device, the banqueting system, the door-lock system, the spa booking tool, the maintenance ticketing app, the digital signage scheduler and the payroll portal. Half of them will be on saved credentials nobody has rotated.
Why the certificate connector beats the static IP connector
Both work. The certificate-based inbound connector authenticates on the subject or SAN field matching one of your accepted domains, and it survives an ISP changing your public address — which happens to hotels more often than to offices, because hospitality broadband contracts change hands. The IP connector needs a static, unshared address; Microsoft states plainly that dynamic addresses are not supported. If you use the IP method, that address must also be added to your SPF record.
The port 465 trap and TLS versions
If a PMS or scanner defaults to port 465, that device does not support the TLS versions Microsoft requires for client SMTP submission. Do not force it. Move it to a connector or replace it. Note too that SMTP AUTH is disabled by default for organisations created after January 2020 and has to be enabled per mailbox — so a brand-new tenant will fail a legacy scanner test that would have passed on an old one.
Teams in a Microsoft 365 setup for hotels: channels, Shifts and the frontline experience
Teams is where the frontline actually meets a Microsoft 365 setup for hotels. Build it deliberately or it becomes 40 abandoned teams within a year.
A Teams structure for a Microsoft 365 setup for hotels that matches the building
One team per property, with channels for the departments that genuinely need a shared thread: Front Office, Housekeeping, Maintenance, F&B, Duty Managers. Then group-wide teams for Revenue, Sales, Finance and Leadership. Resist a team per project. In hospitality the operating unit is the property and the shift, and the structure should say so.
Dynamic teams beat manual membership
Microsoft’s frontline dynamic teams experience in the Teams admin centre automates membership from Entra ID attributes, so a starter added to the housekeeping group at Property B appears in the right team with no administrator involved. You can define a naming convention and a consistent channel structure with a team template, then track deployment progress with frontline usage reports. For a group with turnover, this is the single highest-value configuration in the whole Teams build.
Shifts in a Microsoft 365 setup for hotels, and where its edges are
Shifts is the schedule app, built mobile-first. Managers create shifts manually or in bulk through Excel import and copy/paste, create open shifts, build schedule groups by department or job type, retrieve timesheet reports and manage requests. Workers view their own and the team’s schedule, request open shifts, request time off, swap or offer a shift to a coworker on the same team, and clock in and out of shifts and breaks. Open shifts across locations is in preview.
Connecting Shifts to a real workforce management system
If you already run a workforce management system, connect it rather than duplicating it. Microsoft ships a managed connector for Reflexis Workforce Management versions 4.3.2, 4.4 and 4.5, and documents a custom Graph API integration for any other system with one-way or two-way sync. When a connector is in place, shift creation happens in the WFM system and syncs into Shifts — managers cannot create shifts in Shifts itself, which is a design decision to communicate before go-live, not after.
Bookings for the spa, the restaurant and the meeting rooms
Microsoft Bookings handles appointment scheduling with a public page, staff availability and automated reminders. It is a reasonable fit for a spa treatment diary or a small meeting-room booking flow at a property that has no dedicated system. It is not a substitute for a PMS or a channel manager, and it should never hold the room inventory.
SharePoint and OneDrive in a Microsoft 365 setup for hotels
Files are where a Microsoft 365 setup for hotels decays fastest, because the shared drive comes across as-is and nobody ever revisits it.
Hub and spoke, not one giant site, in a Microsoft 365 setup for hotels
A Microsoft 365 setup for hotels starts with a group hub site, then a spoke site per property, plus function sites for Finance, HR, Revenue and Brand. Associate the spokes to the hub so search, navigation and branding roll up. This is the architecture Microsoft documents for exactly this shape of organisation, and it maps cleanly onto a hotel group where each property needs autonomy over its own operational documents.
Metadata over folders, especially for a group
Twelve folders deep is how a hotel loses a fire risk assessment. Use document libraries with columns for property, document type and review date, then build views. A single Policies library filtered by property beats eleven property folders containing eleven copies of the same allergen policy, three of which are out of date.
| Site | Purpose | Membership | Retention |
|---|---|---|---|
| Group hub | Brand standards, group policies, news | All licensed staff, read | Keep current version, review annually |
| Property spoke (one per hotel) | Rotas, handover notes, local suppliers, H&S | Dynamic group by property code | 6 years for H&S, 1 year for operational |
| Revenue | Rate strategy, forecasts, OTA contracts | Named revenue and GM group | 7 years, restricted |
| HR | Contracts, right-to-work, disciplinary | HR only, sensitivity labelled | Per statutory schedule, deletion enforced |
| Guest documents | Passport scans, registration cards | Front office managers only | Statutory minimum, then automatic deletion |
| OneDrive (per user) | Drafts and personal working files | The individual | Deleted 30 days after offboarding unless held |
Storage maths you should do before migration
SharePoint gives 1 TB pooled plus 10 GB per licensed user, with a 25 TB per-site limit and a 250 GB per-file limit. Overage runs at roughly $0.20 per GB per month. A group with 268 licensed users therefore has 1 TB plus 2,680 GB of pooled storage before paying anything extra — usually ample for documents, and usually not ample if somebody decides to store CCTV exports there.
Backup is not included, and hotels assume it is
Microsoft 365 retains and replicates; it does not back up in the sense a hotel finance director means. Microsoft 365 Backup is a paid add-on at $0.15 per GB per month with free restores and restore points every 10 minutes. Decide yes or no during the build. Our guide to hotel disaster recovery planning covers how that decision fits the wider recovery picture.
Devices and Intune in a Microsoft 365 setup for hotels
A hotel device estate is three or four distinct profiles pretending to be one. Build the profiles into the Microsoft 365 setup for hotels, not a single policy.
Front-desk shared PCs in a Microsoft 365 setup for hotels
Enrol through Autopilot so a replacement machine rebuilds itself without an engineer visit — which matters when the property is 90 minutes from your office. Apply a compliance policy requiring BitLocker, a current Windows build and Defender running. Set a short lock timeout, because the screen faces the lobby. Configure the device to sign the user out at shift end rather than relying on a human to remember.
Housekeeping and maintenance handsets
Shared device mode, Teams and Shifts only, no mailbox, app protection policy preventing copy-out to personal apps. These are the devices that get left on a linen trolley, so remote wipe has to be tested before go-live, not assumed. This is where an F1 licence earns its place in a Microsoft 365 setup for hotels.
Manager laptops and personal phones in a Microsoft 365 setup for hotels
Compliant-device conditional access for the laptop, app protection policy for the phone. A GM who reads mail on a personal iPhone is normal and acceptable, provided the corporate data in Outlook is containerised and can be wiped without touching their photographs.
| Device profile | Enrolment | Sign-in model | Apps allowed | Key control |
|---|---|---|---|---|
| Front-desk PC | Autopilot, Entra joined | Named account, short session | PMS, Outlook, Teams, browser | Automatic sign-out at shift end |
| Housekeeping handset | Intune, shared device mode | Sign in and out per shift | Teams, Shifts | No mailbox, remote wipe tested |
| Duty manager laptop | Autopilot, Entra joined | Named account | Full Office plus PMS | Compliance required for SharePoint |
| Personal phone (BYOD) | Not enrolled | Named account | Outlook, Teams | App protection policy, selective wipe |
| Back-office multifunction device | Not enrolled | Connector, no user | Scan-to-email only | Certificate connector, SPF entry |
Defender for Business, switched on and actually reviewed
Business Premium includes Defender for Business. Onboarding the endpoints in a Microsoft 365 setup for hotels is twenty minutes; reading the alerts is the part that never happens. Assign the review to a named person with a weekly slot, or accept that you have bought a product you will only look at during an incident.
Guest data, retention and compliance in a Microsoft 365 setup for hotels
Hotels hold identity documents, and UK hotels hold them under a statutory obligation most operators have never read.
The 1972 order that binds every Microsoft 365 setup for hotels
The Immigration (Hotel Records) Order 1972 requires hotels to record particulars of guests aged 16 and over, and to keep those records for at least 12 months. That is a floor, not a ceiling, and it does not authorise keeping passport scans indefinitely. A Microsoft 365 setup for hotels should encode the retention period as a policy in Purview, applied to the library where those scans land, with automatic deletion at the end of it.
Sensitivity labels in a Microsoft 365 setup for hotels
Three labels is usually enough in a Microsoft 365 setup for hotels: Internal, Confidential, and Guest Personal Data. Apply the third automatically to the guest-documents library and restrict it to front office managers. More labels than that and staff stop reading them. Fewer and the distinction that matters — guest identity documents versus everything else — is lost.
Data loss prevention with a hospitality-specific rule set
Configure DLP to detect UK passport numbers, payment card numbers and national insurance numbers leaving the tenant by email. In hospitality the most common breach is not an attacker; it is a duty manager forwarding a booking with a card number in the body to a supplier. A policy tip at the moment of sending prevents more incidents than any amount of annual training. See our hotel PMS cyber security guide for where the PMS side of the same data sits.
Audit search, and the question you will be asked
Sooner or later someone asks who opened a specific folio, or whether a departed employee downloaded the guest list. Audit search answers both, but only if auditing was on at the time. Turn it on and verify it in week one. Retroactive auditing does not exist, and “we assume nothing happened” is not an answer a data protection officer accepts.
Where Cyber Essentials fits
Most of the controls above map directly to Cyber Essentials requirements, which is why building them in is cheaper than certifying afterwards. Our Cyber Essentials for hotels guide sets out the scope questions in detail, and a tenant built to this specification will already satisfy the software, access control and malware protection sections.
Multi-property: one tenant, many hotels
A group-scale Microsoft 365 setup for hotels has one extra dimension: keeping properties separate without splitting the tenant.
Administrative units for delegated control in a Microsoft 365 setup for hotels
Entra ID administrative units let you scope an administrator to a subset of users, so a GM at Property C can reset passwords for Property C staff and nobody else. This is how you give properties day-to-day autonomy without handing out global administrator, and it is the single most useful multi-property feature in the whole platform.
Property codes as the organising attribute of a Microsoft 365 setup for hotels
Put the property code on the user object and the rest of the Microsoft 365 setup for hotels follows: dynamic groups, dynamic teams, licence assignment, conditional access scoping and reporting. Movers between properties become an attribute edit. A group that skips this ends up with 40 manually maintained security groups and no idea which is authoritative.
A frontline operational hierarchy
Microsoft supports mapping your structure of frontline teams and locations to a hierarchy in the Teams admin centre, which unlocks location-based scenarios such as offering open shifts across properties. For a group with three hotels within driving distance of one another, this turns a staffing problem into a configuration setting.
What stays central and what stays local
Central: identity, security policy, licensing, brand documents, finance. Local: rotas, handover notes, supplier contacts, local health and safety. The line matters because central control of local operational documents makes properties keep a shadow copy on a USB stick, which is exactly the outcome the build is trying to prevent.
What a Microsoft 365 setup for hotels costs: a three-property worked example
Real numbers for a Microsoft 365 setup for hotels, stated arithmetic, no invented benchmarks. Adjust the headcounts and the shape holds.
The estate behind this Microsoft 365 setup for hotels
Three UK properties: 142, 98 and 74 bedrooms, so 314 bedrooms in total. The group employs 268 named staff, split into 62 office, management and head-office roles and 206 frontline roles. On top of the people there are 21 shared and functional mailboxes — reservations, info, events, accounts, groups, careers and one per department per property — and 5 administrative accounts, giving 294 identities in total. Of those, 26 are shared or privileged, which is just under a tenth of the estate.
The licence bill
62 Business Premium seats at £16.90 is £1,047.80 a month. 84 frontline F3 seats at £6.30 is £529.20. 122 frontline F1 seats at £2.00 is £244.00. The 21 shared mailboxes and the connector senders cost nothing. Total: £1,821.00 a month, or £21,852.00 a year. Across 314 bedrooms that is £69.59 per bedroom per year — roughly the revenue of one midweek room night per bedroom, for the entire productivity and security platform.
What a single-SKU approach would have cost
Had the group put all 268 licensed users on Business Premium at £16.90, the bill would be £4,529.20 a month, or £54,350.40 a year. The three-tier design in this Microsoft 365 setup for hotels therefore saves £32,498.40 a year — £2,708.20 a month — while giving the office population a stronger security baseline than a flattened mid-tier plan would have done.
| Line | Count | Unit | Monthly | Annual |
|---|---|---|---|---|
| Business Premium | 62 | £16.90 | £1,047.80 | £12,573.60 |
| Frontline F3 | 84 | £6.30 | £529.20 | £6,350.40 |
| Frontline F1 | 122 | £2.00 | £244.00 | £2,928.00 |
| Shared mailboxes | 21 | £0.00 | £0.00 | £0.00 |
| Connector senders (PMS, POS, MFD) | 8 | £0.00 | £0.00 | £0.00 |
| Total | 294 identities | — | £1,821.00 | £21,852.00 |
Costs in a Microsoft 365 setup for hotels that are not licences
Budget separately for the Microsoft 365 setup for hotels project itself: discovery and design, tenant build, mail-flow migration, device enrolment, data migration from the old file server, and floor-walking during go-live. In a group this size that is typically a four-to-six week engagement. Add the optional Microsoft 365 Backup at $0.15 per GB per month if the finance director wants point-in-time restore, and a hardware refresh line if the front-desk PCs predate Windows 11.
A 90-day Microsoft 365 setup for hotels rollout plan
Thirty tasks, three phases, sequenced so that nothing guest-facing in the Microsoft 365 setup for hotels moves until the foundations are proven.
Days 1–30 of a Microsoft 365 setup for hotels: foundations and pilot
Tenant creation, domain verification and the full DNS record set. Entra ID attributes and dynamic groups. Licence purchase for the pilot property only. The five conditional access policies in report-only mode. Audit logging confirmed on. Sender inventory completed by walking each building. Pilot team of 12 across one property: a GM, three reception, two duty managers, four housekeeping and two head office. Eleven of the thirty tasks complete.
Days 31–60: mail, files and devices
Move the pilot property’s mailboxes. Build the shared mailboxes and groups. Cut the PMS, POS and multifunction device over to a certificate connector and prove delivery to an external address. Stand up the hub and the first spoke site, migrate the property’s documents with metadata rather than folder structure, and enrol the first Autopilot device and the first shared-mode handset. Conditional access moves from report-only to enforced. Twenty-two of thirty complete.
Days 61–90: rollout and handover
Repeat the mail, files and device pattern at properties two and three, one per fortnight. Deploy Teams and Shifts group-wide with dynamic membership. Apply retention and sensitivity labels to the guest-document libraries. Decommission the old file server and the old mail platform. Run the joiner, mover and leaver processes end to end with a real starter. Hand over documented, with named owners and delegated administrative units. All thirty complete.
| Phase | Focus | Exit test | Rollback |
|---|---|---|---|
| Days 1–30 | Tenant, identity, policy in report-only | Pilot of 12 signs in with MFA, no lockouts | Nothing guest-facing has moved |
| Days 31–60 | Mail, files, devices at property one | PMS confirmation delivered externally; scan-to-email works | Old MX and old relay retained for 14 days |
| Days 61–90 | Properties two and three, Teams, retention | A real starter onboarded end to end in under an hour | Per-property, one fortnight apart |
| Day 91+ | Operate and review | Weekly Defender review has a named owner | Not applicable |
Mistakes that make a Microsoft 365 setup for hotels fail
Every one of these has been seen in a real Microsoft 365 setup for hotels, and every one is cheaper to avoid than to fix.
Buying one licence tier for everybody in a Microsoft 365 setup for hotels
A flat Microsoft 365 setup for hotels looks simple and costs, in the worked example above, an extra £32,498.40 a year. It also usually means the frontline never gets an account at all, so the rota stays on a personal messaging app that the business cannot audit, retain or wipe.
Building the tenant, then thinking about security
Conditional access retrofitted onto a live estate locks out a night porter at 02:00 and gets switched off permanently. Report-only mode during the pilot, enforced before the second property, is the sequence that works.
Leaving the PMS on a saved password
The clock is public and published. SMTP AUTH basic authentication is unchanged through December 2026, then disabled by default for existing tenants. A hotel that has not moved its PMS and its scanner to a connector before then will discover it on a Saturday, and the symptom will be guests not receiving confirmations.
Migrating the folder structure
Lifting \\SERVER\Hotel\Shared\2019\Old\Final_v3 into SharePoint verbatim guarantees the same mess with a slower search. Migrate content, not hierarchy, and use the migration as the moment to delete what should have gone years ago.
Treating cybersecurity training as the control
Awareness helps. It is not a control. Technical controls — phishing-resistant MFA, blocked legacy authentication, compliant devices, DLP policy tips — stop the attack that trained staff still fall for at the end of a double shift. The Booking.com campaign worked precisely because it targeted people doing their job under pressure.
Never appointing an owner for the Microsoft 365 setup for hotels
The most common failure of all. The tenant works on day 90 and drifts from day 91. Name the person, book the monthly slot, and give them the delegated roles they need. The alternative is a Microsoft 365 setup for hotels that is perfect once and degrades quietly for three years.
Frequently asked questions about Microsoft 365 setup for hotels
How long does a Microsoft 365 setup for hotels take?
A Microsoft 365 setup for hotels at a single property with under 60 staff takes four to six weeks from discovery to handover. For a three-to-five property group, the 90-day plan above is realistic. The variable is almost never Microsoft — it is how long it takes to inventory the systems that send email and to get a maintenance slot at each property.
Do housekeeping staff really need a licence?
They need an identity. Whether that identity carries an F1 licence depends on whether you want the rota, safety notices and shift swaps inside a system the business controls. Most operators conclude that £2.00 a month per person is cheaper than the risk of running operations on an unmanaged consumer messaging app.
Can we keep our existing email addresses?
Yes. Domains move into the Microsoft 365 setup for hotels with you; only the MX records change. Plan the cutover for a low-occupancy midweek morning and keep the old platform receiving for a fortnight so nothing sent to the previous MX is lost during propagation.
What happens to our PMS emails during the migration?
Nothing, if you sequence the Microsoft 365 setup for hotels correctly: build and test the connector before you move the MX record, prove an external delivery, and only then change DNS. If you move DNS first, confirmations bounce and the front desk finds out from a guest.
Is Business Premium enough, or do we need E3 or E5?
For almost every independent hotel and small group, Business Premium is enough and better value, because it is the only Business tier with the full security stack. The trigger for moving up is the 300-user cap or a specific compliance requirement. Our Business Premium versus E3 versus E5 comparison sets out where the line falls.
How does this fit with our WiFi and network project?
They are separate builds that share a security model. The Microsoft 365 setup for hotels described here assumes the network is already segmented; if it is not, start with our hotel guest WiFi segmentation guide and the wider hotel WiFi security guide first.
Who should run it afterwards?
A Microsoft 365 setup for hotels needs a named internal owner plus a support partner. The internal owner handles starters, leavers and day-to-day questions through delegated administrative units; the partner handles policy, incidents and change. Our IT support for hotels and hospitality guide describes what that split looks like in practice.
References and further reading
How to set up a multifunction device or application to send email using Microsoft 365 or Office 365
Updated Exchange Online SMTP AUTH Basic Authentication Deprecation Timeline
Manage High Volume Email for Microsoft 365
Understand frontline worker user types and licensing
Shifts for your frontline organization
Deploy frontline teams with flexible membership
Set up your frontline operational hierarchy
Choose your frontline worker devices
Planning for mandatory multifactor authentication for Azure and admin portals
Microsoft Entra Conditional Access overview
Block legacy authentication with Conditional Access
Configure a Temporary Access Pass in Microsoft Entra ID
Enable passkeys (FIDO2) for your organization
Administrative units in Microsoft Entra ID
Dynamic membership rules for groups in Microsoft Entra ID
Compare groups in Microsoft 365
Planning your SharePoint hub sites
Information architecture in the SharePoint modern experience
Overview of Microsoft 365 Backup
What is Microsoft Defender for Business?
Safe Links in Microsoft Defender for Office 365
Anti-phishing policies in Microsoft 365
Create and configure retention policies
Data loss prevention policy reference
Phishing campaign impersonates Booking.com, delivers a suite of credential-stealing malware
Three ways to reimagine hospitality and empower your frontline with Microsoft Teams
Compare Microsoft 365 Business plans (UK)
The Immigration (Hotel Records) Order 1972