Skip to content
Call +49 40 88192642 Send an email [email protected] Chat in Teams [email protected]
← All articles ·Unkategorisiert · ·6 min read

Several companies, one site: how to share a network cleanly

A shared internet connection and firewall, separate networks and a Microsoft 365 tenant for each company. What is shared, what stays separate, how costs are split and where such projects are most likely to snag.

Ein Standort, drei getrennte Netzbereiche mit gemeinsamer Firewall und gemeinsamem Drucker

Several companies in a group under one roof often share more than they realise: the internet connection, the firewall, the printers, the phone system. For that to work without the companies being able to look into each other’s data, the network needs a clear division. This article covers what is shared, what stays separate and where such projects are most likely to snag in practice. The article is based on a project from 2024.

The starting point

A group with several companies, all at the same site. Over the years the companies grew into one shared network: one connection, one network, every computer able to see every other. Email ran with a web host, line-of-business software sat on local machines, and who was allowed to see which data was more a matter of habit than of design.

As long as everything works, hardly anyone notices. At the latest when a company is sold, restructured or audited, or when a computer in one company is infected with malware, the habit becomes a problem.

What is shared and what stays separate

Shared

Internet connection, firewall, switches and Wi-Fi infrastructure. Plus devices that several companies genuinely use together, such as printers or the phone system.

Separate

Each company has its own network segment and its own Microsoft 365 tenant with its own accounts, mailboxes and file storage. What a company can see is its own decision.

Controlled

The firewall decides which traffic is allowed between the segments. The default is nothing, except what is explicitly needed.

Billed

Shared infrastructure and shared effort are split between the companies, according to a key the group sets in advance.

A network segment for each company

Technically, the separation is done with VLANs. Each company gets its own virtual network, as do telephony, guests and the management of the network devices. A company’s computers can see each other, but not those of the other companies. Whether and how traffic may flow between the networks is decided by the firewall, not by the accident of how the cabling was done.

In its IT baseline protection guidance, Germany’s Federal Office for Information Security (BSI) recommends that VLANs belonging to different organisations on one switch should be separated physically, or that the data should be encrypted. For a group whose companies work closely together and share an owner, separation through VLANs and firewall rules is often appropriate. How far the separation has to go depends on how sensitive the data is, and that should be settled before the planning, not afterwards.

A separate Microsoft 365 tenant for each company

One shared tenant for all companies looks simpler at first glance. Separate tenants fit better with what the companies are in legal terms, though: independent entities with their own data, their own licences and their own responsibility. If a company is later sold or wound up, its tenant can be handed over as a whole, rather than untangling accounts and files from a shared environment.

Where staff work across companies, Microsoft’s multitenant organisation capabilities offer ways to connect tenants without merging them.

Shared devices

Printers and the phone system are where clean separation needs exceptions. Here the firewall ensures that computers from every company can reach the shared printer without that opening a path into the other companies’ networks. The phone system sits in its own segment anyway, so that voice calls do not compete with the rest of the data traffic.

Splitting costs fairly

Shared infrastructure means shared effort, both during set-up and in day-to-day operation. I bill this effort split between the companies. Which key applies, by workstation for example or in equal shares, is for the group to decide. What matters is that it is settled before work begins. Negotiating afterwards over who pays what share of a firewall is unpleasant for everyone involved.

The real difficulty

The technology in projects like this is quite manageable. Harder are change requests that only come up after the work is done: one company does need access to another’s files after all, a device is suddenly to be used by everyone, a workstation moves to a different company. Each of these requests is understandable on its own. Not discussed in advance, though, it can only be met with extra effort, because the rules, segments and permissions are already in place.

That is why I recommend clarifying with each company individually, before the planning, who works with whom, which devices are shared and which data really has to stay separate. The result should be written down and confirmed by every company.

Questions before planning

  1. Which companies actually work together? And on which data?
  2. Which devices are shared? Printers, phone system, meeting rooms, scanners.
  3. How sensitive is each company’s data? That determines how far the separation has to go.
  4. Who decides for each company? One contact per company saves many rounds of coordination later.
  5. What key is used to split costs?
  6. What happens when a company joins or leaves the group?

Sources