The challenge
Each venue had grown its own IT habits. Some sites used personal Gmail accounts for rosters and supplier orders, others ran an unsupported legacy Exchange tenant, and back-office PCs frequently shared a single Windows login between duty managers, chefs and accounts staff. When someone left, credentials rarely changed.
The group had also been hit by an invoice-redirection email scam targeting venue managers, and the executive team was concerned about PCI exposure, payroll fraud and the lack of any consistent backup, MFA or device baseline across sites — especially with high staff turnover typical of hospitality.
The approach
Mycelium 365 ran a venue-by-venue discovery covering mailboxes, identities, back-office devices, Wi-Fi separation, POS vendor requirements and the group's PCI obligations. We mapped a single tenant model with venue-based naming, shared mailboxes for roles (reservations@, functions@, accounts@) and personal mailboxes for managers and head office.
Mail and identities were consolidated into Microsoft 365 with Microsoft Defender for Office 365 protecting against the invoice-redirection and supplier-impersonation patterns the group had already seen. Entra ID conditional access enforced phishing-resistant MFA for finance, payroll and head-office roles, with simpler sign-in journeys for venue floor staff.
Microsoft Intune brought back-office PCs, manager laptops and group-owned iPads under a single compliance baseline, with autopilot reprovisioning so a venue could replace a failed device the same trading day. Staff and guest Wi-Fi were separated, and POS networks isolated, to support the group's PCI position.
Change was rolled out venue-by-venue across quieter trading windows, with on-site floor walks during shift changes so duty managers and chefs were comfortable before the next service.
The outcome
The group now runs a single, supported Microsoft 365 tenant across all nine venues, with role-based shared mailboxes and personal accounts that follow staff joining, moving or leaving. Credential sharing on back-office PCs has been eliminated.
Defender stopped a repeat invoice-redirection attempt within the first quarter of go-live, and finance reports far fewer suspicious supplier emails reaching inboxes. MFA coverage across finance, payroll and head-office roles is now at 100%.
Venue managers can replace a failed back-office PC the same day using Intune autopilot, removing a previous pain point that often left a site without rosters or supplier ordering for 24–48 hours. The group has a defensible, evidence-ready security position ahead of its next PCI and cyber insurance reviews.
Technologies used
- Microsoft 365 (Exchange Online, SharePoint, Teams)
- Microsoft Defender for Office 365
- Microsoft Entra ID (conditional access, MFA)
- Microsoft Intune with Windows Autopilot
- Shared mailboxes for venue roles
- Segmented staff, guest and POS Wi-Fi
Need a similar outcome?
Book a Discovery Call with Mycelium 365 to discuss your environment, security priorities, and the practical next step.
