Several companies, one site: how to share a network cleanly
A shared internet connection and firewall, separate networks and a Microsoft 365 tenant for each company. What is shared, what stays separate, how costs are split and where such projects are most likely to snag.
Several companies in a group under one roof often share more than they realise: the internet connection, the firewall, the printers, the phone system. For that to work without the companies being able to look into each other’s data, the network needs a clear division. This article covers what is shared, what stays separate and where such projects are most likely to snag in practice. The article is based on a project from 2024.
The starting point
A group with several companies, all at the same site. Over the years the companies grew into one shared network: one connection, one network, every computer able to see every other. Email ran with a web host, line-of-business software sat on local machines, and who was allowed to see which data was more a matter of habit than of design.
As long as everything works, hardly anyone notices. At the latest when a company is sold, restructured or audited, or when a computer in one company is infected with malware, the habit becomes a problem.
What is shared and what stays separate
Internet connection, firewall, switches and Wi-Fi infrastructure. Plus devices that several companies genuinely use together, such as printers or the phone system.
Each company has its own network segment and its own Microsoft 365 tenant with its own accounts, mailboxes and file storage. What a company can see is its own decision.
The firewall decides which traffic is allowed between the segments. The default is nothing, except what is explicitly needed.
Shared infrastructure and shared effort are split between the companies, according to a key the group sets in advance.
A network segment for each company
Technically, the separation is done with VLANs. Each company gets its own virtual network, as do telephony, guests and the management of the network devices. A company’s computers can see each other, but not those of the other companies. Whether and how traffic may flow between the networks is decided by the firewall, not by the accident of how the cabling was done.
In its IT baseline protection guidance, Germany’s Federal Office for Information Security (BSI) recommends that VLANs belonging to different organisations on one switch should be separated physically, or that the data should be encrypted. For a group whose companies work closely together and share an owner, separation through VLANs and firewall rules is often appropriate. How far the separation has to go depends on how sensitive the data is, and that should be settled before the planning, not afterwards.
A separate Microsoft 365 tenant for each company
One shared tenant for all companies looks simpler at first glance. Separate tenants fit better with what the companies are in legal terms, though: independent entities with their own data, their own licences and their own responsibility. If a company is later sold or wound up, its tenant can be handed over as a whole, rather than untangling accounts and files from a shared environment.
Where staff work across companies, Microsoft’s multitenant organisation capabilities offer ways to connect tenants without merging them.
Shared devices
Printers and the phone system are where clean separation needs exceptions. Here the firewall ensures that computers from every company can reach the shared printer without that opening a path into the other companies’ networks. The phone system sits in its own segment anyway, so that voice calls do not compete with the rest of the data traffic.
Splitting costs fairly
Shared infrastructure means shared effort, both during set-up and in day-to-day operation. I bill this effort split between the companies. Which key applies, by workstation for example or in equal shares, is for the group to decide. What matters is that it is settled before work begins. Negotiating afterwards over who pays what share of a firewall is unpleasant for everyone involved.
The real difficulty
The technology in projects like this is quite manageable. Harder are change requests that only come up after the work is done: one company does need access to another’s files after all, a device is suddenly to be used by everyone, a workstation moves to a different company. Each of these requests is understandable on its own. Not discussed in advance, though, it can only be met with extra effort, because the rules, segments and permissions are already in place.
That is why I recommend clarifying with each company individually, before the planning, who works with whom, which devices are shared and which data really has to stay separate. The result should be written down and confirmed by every company.
Questions before planning
- Which companies actually work together? And on which data?
- Which devices are shared? Printers, phone system, meeting rooms, scanners.
- How sensitive is each company’s data? That determines how far the separation has to go.
- Who decides for each company? One contact per company saves many rounds of coordination later.
- What key is used to split costs?
- What happens when a company joins or leaves the group?
Sources
- Separating network segments, VLANs of different organisations: BSI IT-Grundschutz Compendium, module NET.1.1 Network architecture and design (German), requirement NET.1.1.A23
- Collaboration between several Microsoft 365 tenants: Microsoft Learn – Multitenant organization capabilities in Microsoft Entra ID
- Moving mailboxes between tenants: Microsoft Learn – Cross-tenant mailbox migration
Server move in one day: why the preparation takes longer than the move
A new server, a new domain, every workstation moved across and normal work the next morning. What has to happen beforehand, what the schedule and fallback plan look like, and where the time really goes.
Read→
Company phones that set themselves up: iPhone and Android with Intune
How iPhones enrol in Intune through Apple Business Manager and Android devices through zero-touch the first time they are switched on, how personal phones are protected with app protection policies, and what to watch for with privately bought devices.
Read→
Taking over Macs in Intune: what I check first
Which points decide the effort before existing Macs are taken over into Intune, when a Mac has to be erased, how Platform SSO, FileVault and software deployment are set up, and where Intune reaches its limits on Macs.
Read→