On this page
It almost always starts the same way. A Thunder Bay firm hires a fourth admin assistant, balks at another ~$17 a month for a Microsoft 365 Business Standard licence (annual billing, as of April 2026), and decides she’ll “just use Sarah’s login when she needs it.” A regional non-profit has one QuickBooks Online subscription shared across the bookkeeper and two program managers. A contractor in Timmins has three site supervisors rotating through a single Adobe Acrobat Pro login.
It feels resourceful. It feels like the vendor is gouging and the business is pushing back. It feels, at $30 or $40 a month, like nothing.
It’s one of the most expensive “savings” a small business can make — and in 2026, the downside has gotten sharper, not softer. Here’s why.
1. It’s a Contract Breach (and Sometimes Software Piracy)
Most major SaaS agreements you’ve ever clicked through — Microsoft 365, Google Workspace, QuickBooks Online, Adobe Creative Cloud, Xero, Sage, most line-of-business applications — license the product per user. Microsoft’s own guidance is that you assign a licence to each person in your organization. Not one device, not one desk, not one role. One person.
Sharing a login falls outside those terms. For Microsoft specifically, sign-in logs make the pattern visible: a single account signing in from three different devices, three different IP addresses, during overlapping hours is not subtle.
When a vendor audits and finds shared use, the consequences typically include:
- Retroactive true-up billing for every unlicensed user, often going back 12 months
- Penalty fees on top of the back-billing
- Loss of volume or partner pricing going forward
- Termination of support — for regulated vendors (accounting, legal practice management, clinical systems), this can void warranty and professional-services coverage
For perspective: saving $17 a month by sharing one licence between two people can generate a back-bill running into hundreds of dollars plus penalties on audit — before you count the ongoing loss of discounted pricing.
2. It Destroys Your Audit Trail
Every modern compliance framework — PIPEDA (federal privacy law), PHIPA (Ontario health information), SOC 2, every cyber insurance questionnaire you’ll ever fill out — assumes one identity equals one person. That’s what makes logs meaningful.
When three people share admin@yourcompany.com, you can no longer answer any of these questions:
- Who accessed the client contract file on Tuesday afternoon?
- Who approved the $8,400 vendor payment?
- Who changed the employee salary field in the HR system?
- Who downloaded the customer list the week before the breach?
In an incident investigation, “we don’t know which of four people did it” is the single worst answer you can give. It turns what might have been a contained incident affecting one account into a full-scope investigation across every user of that shared credential — multiplying legal, forensic, and notification costs.
Under PIPEDA’s accountability principle, your business is responsible for the personal information under its control. An audit trail you cannot trust is effectively no audit trail at all.
3. Multi-Factor Authentication Collapses
MFA — the second factor required for login, usually a phone prompt or authenticator app — is one of the most effective controls against credential theft.
It does not survive credential sharing. If three people share one account, one of three things is happening:
- The MFA prompt lives on one person’s phone, and the other two bypass it (calling, texting the code over Teams, or worse)
- MFA is disabled entirely so everyone can log in
- A shared phone or hardware token is passed around the office
Every one of those destroys the security benefit MFA was supposed to provide.
And it matters beyond security. Cyber insurance applications in Canada now routinely ask whether MFA is enforced for every user as a condition of coverage. Beazley’s cyber application form asks outright whether you require MFA for all users’ access to email and for all remote access to the network; Coalition, Aviva Canada and the other cyber-specialist carriers ask similar questions on their forms (as reported at April 2026). Shared accounts cannot credibly answer “yes” to that question. A denied claim after an incident is a very expensive lesson, and by the time you discover it, the breach has already happened.
4. Offboarding Has No Good Option
When an employee leaves a business that practises credential sharing, IT faces a choice with no good option:
- Disable the account → the other people sharing it lose access, and the business grinds
- Change the password and redistribute → the password gets written down, pasted into a group chat, or emailed, and is likely to leak faster than before
- Do nothing → the departed employee retains access to company data indefinitely
The third option is the one most SMBs default to. The result is that when we audit an environment for the first time, we routinely find former employees with active credentials months — sometimes years — after their last day. Under PIPEDA, that’s a material risk if personal information is in scope, and it’s a finding any auditor, insurer, or incoming buyer will flag immediately during due diligence.
5. Password Hygiene Craters
In our experience, shared passwords are almost always:
- Simple enough for a group to remember (
Company2024!,Welcome1) - Written down on a sticky note, whiteboard, or shared Note
- Pasted into group chats or unencrypted emails
- Never rotated, because rotation creates a distribution problem
- Reused across multiple systems, because the cognitive load of shared credentials is already high
One phishing hit on any of the shared users then compromises multiple humans’ worth of data. The blast radius is usually larger than leadership expects.
6. It’s a False Economy
Do the math on a realistic example. A 12-person professional services firm sharing one Microsoft 365 Business Standard licence among three staff instead of buying two more at roughly $17.50 each — about $35 a month:
- Annual “savings”: about $420
- Back-billing on audit (2 extra users × 12 months retroactive): about $420, plus penalties
- Loss of partner discount going forward: variable, but often hundreds per month across the tenant
- Denied cyber insurance claim after a breach: a typical SMB incident runs to six figures once forensics, legal, notification, and business interruption are counted; the exact number depends on the incident, and estimates vary widely
- PIPEDA investigation exposure: legal and remediation costs on top
The trade is roughly $420 a year of “savings” against a six-figure worst-case downside, and a likely compliance finding at the next audit, renewal, or sale. Nobody would take that trade if it were framed honestly.
What to Actually Do Instead
The goal isn’t to buy more licences than you need — it’s to structure access so every action is tied to a real person without over-licensing.
1. Right-size the licence tiers. Most SMBs over-buy at the top end. Microsoft 365 has several business tiers with different price points — not every employee needs Business Standard or Premium. Front-line staff who use email and Teams on the web may fit a much cheaper tier. An honest licence audit usually finds both over-licensed and under-licensed users in the same tenant.
2. Use shared mailboxes the right way. In Microsoft 365, a shared mailbox (e.g. info@ or reception@) does not require its own licence as long as it’s under 50 GB and is accessed by already-licensed users. Each employee signs in with their own identity, and the shared mailbox is a delegated resource. You preserve the audit trail and pay nothing extra.
3. Leverage Microsoft 365 Groups and SharePoint permissions. For shared documents, calendars, and project spaces, identity-based permissions are included with existing licences. There is rarely a legitimate reason to share a login in order to share a file.
4. Deploy a business password manager. For the handful of genuinely shared credentials that still need to exist — a social media account, a vendor portal with no SSO, a shared POS login — use a business-tier password manager such as Bitwarden Business, 1Password Business, or Keeper Business. These tools log who retrieved the credential and when, which preserves an audit trail even on shared secrets.
5. Enforce MFA on everything. Every account, every user, with any break-glass exceptions documented and monitored. This is table stakes for cyber insurance and for a PIPEDA-defensible security posture.
6. Build offboarding into a documented process. Every departure should trigger licence reclamation, access revocation across every system, and a review of any shared resources the employee touched.
How DVG Systems Helps
We run a licensing and identity review as part of onboarding every managed IT client. In a typical engagement we:
- Audit current Microsoft 365 / Google Workspace licensing against actual usage, identifying over-licensed and under-licensed users
- Identify shared-credential patterns — including the ones staff haven’t told leadership about
- Deploy shared mailboxes, Microsoft 365 Groups, and SharePoint permissions to replace shared logins without adding licence cost
- Roll out a business password manager for the legitimately-shared credentials that remain, with audit logging enabled
- Enforce MFA across the tenant with exception reporting
- Build structured offboarding into the managed service, so licence reclamation and access revocation happen on the same day as the employee’s last day
In almost every case, the net licensing cost after an audit is within a few dollars per month of what the business was paying before — but the compliance posture, audit trail, and insurability all improve dramatically.
The Bottom Line
Credential sharing feels like a small act of resistance against a vendor pricing model the business didn’t choose. In reality, it’s a contract breach, an audit-trail hole, an MFA bypass, an offboarding nightmare, a password-hygiene disaster, and a cyber-insurance voider — all for a saving that typically evaporates on the first audit or incident.
Every action in your business should be traceable to a single human being. That’s what compliance frameworks, insurance carriers, and your own incident responders assume. Credential sharing is the fastest way to lose that — and the slowest, most expensive thing to recover from.
If a client is sharing logins to stretch licences, they’re not saving money. They’re financing a much larger future bill at the worst possible interest rate.
Related Reading
- The Business Case for a Password Manager — the practical half of the solution for credentials that genuinely need to be shared
- When Employees Leave: The IT Offboarding Checklist — why shared accounts turn every departure into a compliance problem
- Cybersecurity, Cyber Insurance, and MSP Liability for Canadian SMBs — why shared credentials can void your cyber insurance claim
Sources and last verified
Last verified 11 September 2026. Microsoft 365 licence prices and insurer application wording change regularly; the licence figures here are approximate Canadian annual-billing prices at the time of writing.
- Subscriptions and licenses in Microsoft 365 for business, Microsoft Learn: licences are assigned to each person.
- About shared mailboxes, Microsoft Learn: shared mailboxes under 50 GB do not need their own licence.
- PIPEDA Fair Information Principle 1 — Accountability, Office of the Privacy Commissioner of Canada: responsibility for personal information under your control.
- Beazley cyber insurance application (short form), Beazley: the MFA questions on the underwriting form.
DVG Systems provides managed IT services, Microsoft 365 licensing reviews, and identity and access management for small and mid-sized businesses across Northern Ontario, including Thunder Bay, Timmins, and the surrounding region. If you’d like a confidential licensing and credential audit for your organization, book a free assessment or reach us at (807) 700-0061 or solutions@dvgsystems.com.