The login three people share is about to stop working
- Technology
- IT consultancy
- Cyber security
- Knutsford
Somewhere in most small firms there is a login that belongs to nobody. The bookkeeper uses it, the office manager uses it, and the director used it once in 2023. It has a password everyone knows and a mobile number attached to it that nobody has looked at in years.
That arrangement is about to meet a one-time code.
What HMRC is doing, and when
Multi-factor authentication is being switched on for every remaining agent account: the agent services account and the older online services account both. HMRC will activate it between 28 September and 15 October 2026, and it has said plainly that it cannot tell any individual agent which day inside that window is theirs. After it happens, signing in means the Gateway ID, the password, and then a one-time code from an authenticator app, a text message or a voice call.
For an accountancy practice this is a diary item. It arrived in the trade press in June, most firms have a plan, and the ones that wanted an earlier fixed date had until July to ask for one.
The reason it is worth your attention if you are not an accountant is that agent accounts are the last ones to get this. Personal and business Government Gateway accounts came first, which for a lot of firms means the change has already been and gone without comment, because one person signs in and it is their phone. The arrangement all of it breaks is not remotely unique to accountants.
The shape of the problem
One login. Three people. One phone number, registered years ago, belonging to whoever set the account up.
Once a code is required, that account has a single point of entry, and it is a handset. If the handset is in the building, you have turned a shared login into a queue: somebody shouts the six digits across the office every time anyone signs in. If the handset left with its owner, you have not got a queue, you have a locked door and a helpline.
Have a look for the same shape elsewhere in your business, because it is rarely just the one.
- The
accounts@mailbox that people sign into as though it were a person - The bank's read-only login the bookkeeper uses on a Tuesday
- The domain registrar account still in the name of the web company that built the site five years ago
- The insurance portal, the courier account, the trade supplier, the payroll software
Each of them is one provider's security update away from becoming somebody's afternoon.
Nobody set it up badly on purpose
This is worth saying, because the standard advice on shared logins is written as though someone were careless. Almost always they were not.
The account was created by one person because one person was doing the job. Then a second person needed to see something, once, and the quickest honest answer was the password. Nothing was decided. It accumulated.
And in fairness, for years it worked. A shared login is genuinely convenient right up to the moment the provider adds a second factor, or the person whose phone it is goes on holiday, or leaves, or falls out with you.
The other cost, which shows up earlier
Long before anything gets locked, a shared login has already taken something away: the answer to who did that.
Every log for that account says the same name. When a payment goes to the wrong place, when a filing is submitted early, when a setting changes and nobody admits to it, there is nothing to look at. Three people, all honest, all sure it was not them, and no way to close the question. That is a bad afternoon in a small firm and it lasts longer than the incident did.
It also means offboarding cannot really be done. When someone leaves, you change one password and hope the list of things they knew was the list you remembered.
What to do instead, roughly in order of effort
Give people their own accounts where the service supports it. More services do than firms realise. HMRC's business tax account has a team member function: an administrator adds people, gives each one access to specific taxes or schemes, and picks a role of administrator, standard or view only. GOV.UK documents it under "manage team members using your HMRC business tax account". Most banks, most payroll products and most portals have the same thing under a settings menu nobody has opened. Each person then registers their own second factor, and a leaver is removed rather than a password being changed.
Use a shared mailbox rather than a shared user. This is the one we implement most often on the Microsoft 365 estates we run, and it is widely misunderstood. A shared mailbox is not an account people log into. It is a mailbox that named people are granted access to, from their own accounts, with their own multi-factor authentication. Sending as accounts@ still works. What disappears is the password everyone knows, and mail sent from it can be traced back to the person who actually typed it.
Put the leftovers in a password manager, not a spreadsheet. Some accounts genuinely cannot be split. A supplier portal that permits one user is a supplier portal that permits one user, and no amount of tutting changes it. The right answer there is a business password manager holding the credential, so the password can be shared without being known, revoked without being changed, and the recovery details are not stored in a file called passwords on somebody's desktop.
Before the end of the month, one thing matters more than the rest
Check what is already on the account.
The specific warning being circulated to agents is that an out-of-date second factor is worse than none. Where an old mobile number or a retired authenticator is still registered, the account can lock at activation, and the moment to fix that is while you can still sign in normally. Administrators can correct these settings on behalf of the people they manage, which is much easier than doing it afterwards through a helpline in the same fortnight as everyone else.
The same is true of every other account on your list. Signing in is not the test. Signing in and then looking at the security settings is the test.
- 01List every login more than one person uses
- 02For each, note whose phone or email the recovery goes to
- 03Cross off anyone who has left, and anyone who would be on a beach in October
- 04What is left is the work, and most of it is a settings page
An hour with that list is not a project. It is the difference between reading about the HMRC window in advance and finding out about it on the morning somebody cannot file.
If your list turns out to be longer than you expected, or half of it points at a phone number you no longer recognise, that is a conversation worth having before the end of September rather than after it.
We work with businesses across Knutsford, Alderley Edge, Wilmslow, Altrincham, Stockport and Warrington, and remotely for clients anywhere in the UK.
If any of this sounds like your business, we will tell you plainly whether we can help.
