M365 Charity Security Settings: What’s Switched Off by Default?

13 minutes
engineer using triple screens

If someone at your charity mentioned advanced security features you haven’t switched on, and you’re not certain whether they’re necessary or just optional extras, you’re not alone. It’s one of those things that sounds important but seldom gets explained for charities specifically.

Microsoft 365 can give charities access to an extensive set of security tools, particularly through licences such as Microsoft 365 Business Premium. But having a feature included in your licence doesn’t automatically mean that every protection is configured for your organisation, applied to the right people and devices, or enforcing the policies your charity needs.

That distinction is key.

A small charity with five employees working exclusively on organisation-owned laptops has different risks from a charity with 100 volunteers accessing beneficiary information from personal devices. Simply accepting the same Microsoft 365 configuration in both organisations doesn’t amount to a respected security strategy.

This guide breaks down what’s protecting you now, why some advanced features need further configuration, and whether your charity’s specific risks, including beneficiary data, volunteer devices and Cyber Essentials scope, mean you should configure them. You can find a checklist at the end to audit which security settings are suited to your charity. 

Which Security Settings Are Switched Off by Default in Your Charity’s M365?

The first thing to understand is that Microsoft 365 isn’t one security product with a single on/off switch.

Depending on your licence, it can include layers of protection for identities, email, devices, applications and data. Microsoft 365 Business Premium, for example, includes:

  • Microsoft Defender for Business
  • Microsoft Defender for Office 365 Plan 1
  • Microsoft Intune Plan 1
  • Microsoft Entra ID Plan 1
  • Microsoft Purview data protection capabilities. 

However, licences, default protections and policies configured explicitly for your organisation are three different things.

As Adam Graham explains in Qlic’s Cyber Security Tips for Charities webinar:

“Microsoft 365 is a huge beast of a tool. There are ways it can be set up well, and ways it comes out of the box. You need to tailor that to your organization.”

That tailoring is particularly important across four areas.

Microsoft Defender

Microsoft Defender for Business provides endpoint security for devices such as laptops and desktops. It can help charities identify vulnerabilities, detect threats and respond when suspicious activity occurs.

This is different from simply having email filtering. A phishing email, for example, can be one stage of a wider attack that eventually compromises an account or device. Our guide to charity phishing scams and impersonated-user protection explains some of the risks charities need to consider, while our article on Microsoft Defender for charities looks at the technology in more detail.

Defender for Business is included with Microsoft 365 Business Premium, but devices still need to be correctly onboarded, and the service configured to gain the intended endpoint protection.

Microsoft Intune

Microsoft Intune is Microsoft’s cloud-based device and application management platform. It allows an organisation to establish rules for the devices accessing its resources and centrally manage organisation-owned equipment.

That becomes especially beneficial when staff are working away from an office. As we explain in our guide to the benefits of Microsoft Intune for remote working, central management gives charities much greater visibility over devices that aren’t sitting inside the charity’s premises.

Having an eligible licence doesn’t automatically mean every device is enrolled and governed by the policies your charity needs. Those decisions need to be made and configured.

Conditional Access

Microsoft Entra Conditional Access allows you to determine the conditions under which somebody can access your charity’s systems.

Rather than treating every login in the same way, policies can consider factors such as the user, device, application and location or risk signals before access is granted. This can be especially relevant when trustees, volunteers and employees have different access requirements.

For charities relying on volunteers, our guide to volunteer access and permissions in Microsoft 365 explains why controlling who can access information, and what they can access, deserves careful attention.

Microsoft does provide baseline identity protections, and eligible tenants may also receive Microsoft-managed Conditional Access policies. However, Microsoft’s documentation states that these managed policies are initially created in report-only mode. A charity therefore shouldn’t assume that having Conditional Access available means its own appropriate access rules are already being enforced.

Data Loss Prevention

Microsoft Purview Data Loss Prevention (DLP) is designed to recognise sensitive information and apply rules governing how that information can be used or shared.

For a charity, that may mean reducing the likelihood of somebody accidentally sending sensitive information outside the organisation or moving protected information somewhere it shouldn’t go.

Microsoft now creates certain baseline DLP policies automatically in tenants. However, those defaults are limited in scope. For example, Microsoft’s default Office 365 DLP policy focuses on externally shared credit-card-number information, while its default device policy audits specified activities rather than automatically blocking all of them. Charities therefore still need to assess whether tailored DLP policies are required for the information they hold.

Our guide to Microsoft Data Loss Prevention for nonprofits explains how charities can use DLP to protect sensitive information in practice.

The important question, then, isn’t simply: “Does our Microsoft licence include these tools?”

It’s: “Have we configured the protections that make sense for our charity?”

Why Do These Security Settings Matter for Non-Profits?

Microsoft 365 security configuration isn’t just an IT question. For charities, it is also a governance question.

Can you explain what’s protecting beneficiary information? Do you know what happens when a volunteer accesses Microsoft 365 from their own laptop? Could you identify inappropriate access to sensitive data? If a trustee asked why a particular security control wasn’t enabled, could you explain the decision?

As Oliver Bradshaw discusses in Qlic’s cybersecurity best practices webinar, cyber security matters especially to charities because of the information, services and people they are responsible for protecting.

There are four areas worth considering.

Beneficiary data under GDPR

Many charities hold personal information about beneficiaries, donors, employees and volunteers. Depending on the organisation’s work, some of that information may be particularly sensitive.

The UK’s official data protection guidance explains the responsibilities organisations have when collecting and using personal information. Our essential guide to GDPR and data protection for charities puts those responsibilities into a charity-specific context.

Microsoft 365 security controls can support those responsibilities in several ways. Conditional Access can help determine who is permitted to access systems and under which circumstances. DLP can help identify and control the movement of sensitive information. Audit capabilities can provide visibility into activity.

Consider a charity supporting vulnerable families. Its Microsoft 365 environment might contain names, contact details and case information. The question isn’t simply whether SharePoint or OneDrive is “secure”. The charity also needs to consider who should have access to that information and what should happen if somebody tries to share it outside the organisation.

Volunteer and trustee personal devices

Bring-your-own-device arrangements are common in the nonprofit sector because purchasing and maintaining a corporate device for every volunteer or trustee may not be practical.

But personal devices change the risk result.

Suppose a trustee accesses board documents through a personal laptop that is subsequently lost. Or a volunteer uses an old device that hasn’t received security updates. Your charity must know how much control it wants over those scenarios.

Intune can help manage organisation-owned devices and, depending on the chosen approach, protect organisational applications and data on personal devices. Conditional Access can help determine whether a particular device or access scenario should be permitted in the first place.

The goal isn’t necessarily to gain intrusive control over a volunteer’s personal laptop. In many cases, the better question is: what control does the charity need over its own information while respecting the fact that the device belongs to somebody else?

That is an intentional policy decision rather than something Microsoft can decide for you.

Cyber Essentials scope

The National Cyber Security Centre’s Cyber Essentials scheme focuses on five technical controls designed to safeguard organisations against common cyber-attacks.

Those controls include areas such as secure configuration, user access control, malware protection and security updates. Therefore, the devices, accounts and systems within your certification scope need to be considered thoroughly`.

Defender, Intune and Conditional Access can all contribute to a well-managed Microsoft environment, but simply owning the licences isn’t the same as satisfying a certification requirement. Your controls need to be accurately configured and appropriate for the organisation and scope being assessed.

If certification is on your roadmap, Qlic can also help charities with Cyber Essentials and work through the practical requirements with your team.

Trustee accountability

Trustees don’t need to become Microsoft 365 administrators.

They do, however, need sufficient assurance that crucial risks are understood and managed.

There’s a meaningful difference between saying, “Conditional Access isn’t configured because nobody ever switched it on,” and saying, “We reviewed Conditional Access, documented our access risks and implemented the policies appropriate to our staff, trustees and volunteers.”

The second is a deliberate governance decision.

The same applies to Defender, Intune and DLP. Not every available control needs to be applied in its strictest possible form. Security measures should reflect risk, usability, budget, licensing and the way the charity operates.

The important thing is knowing what you’ve decided and why.

Checklist: Should Your Charity Enable These Features?

You don’t need to enable every possible Microsoft 365 control purely because it exists. You do need to make an informed decision.

A simple way to start is to coordinate each feature to a risk your charity has.

You don’t need to enable every Microsoft 365 control just because it exists, but you do need to make an informed decision. Work through each question below and tick the ones that apply to your charity.

  • Do volunteers or trustees use personal laptops?

If yes, review Intune and Conditional Access

  • Decide what information personal devices should be able to access
  • Decide whether you need application-level protection
  • Consider restricting certain access to devices that meet your security requirements

If not, Intune may still be worth it. Charity-owned laptops also benefit from centralised device management and consistent security policies.

  • Do you handle beneficiary or donor data covered by GDPR?

If yes, review DLP and Conditional Access

  • Identify where sensitive information is stored
  • Confirm who genuinely needs access to it
  • Map the ways it could accidentally leave the organisation
  • Don’t assume Microsoft’s baseline DLP policies cover your data just because some default policies exist

 

  • Are laptops and desktops used to access charity systems and information?

If yes, review Microsoft Defender for Business

  • Email security is only one part of cyber security
  • If a device is compromised, you need visibility and the ability to detect and respond to threats

 

  • Are you pursuing Cyber Essentials?

If yes, review Defender, Intune and your access controls, including Conditional Access where appropriate

  • Map your configuration against the scheme’s requirements
  • Don’t treat a Microsoft licence as evidence of compliance

 

  • Do you report cyber security risks to your board or trustees? 

If yes, document your configuration decisions across all four areas

  • Record the risks considered, the controls selected, who owns them and when they’ll be reviewed
  • Keep it concise: your board doesn’t need a 50-page export of Microsoft settings
  • This exercise can also uncover licensing problems charities often overlook, such as paying for capabilities they aren’t using, or assuming a capability is included when their licence doesn’t provide the version they need.

A Microsoft 365 licence review can therefore be valuable alongside the security review. For organisations that don’t have internal capacity to continually manage configuration, managed IT support for charities and nonprofits can provide ongoing support rather than treating security configuration as a one-off exercise.

The experience of Media Archive for Central England (MACE) shows what this can look like in practice. MACE needed a structured, secure IT foundation with a Microsoft tenant configured correctly from the outset. Qlic selected Microsoft 365 Business Premium and established identity, access and security controls, while Microsoft Defender for Endpoint was deployed across user devices. The result was a more steady and secure Microsoft 365 environment with stronger device security and centralised identity and access management.

That’s an essential distinction. MACE didn’t simply buy Microsoft 365 and assume every security outcome would follow automatically. Its Microsoft environment was configured around the organisation’s actual requirements.

If you’d like to understand the wider Microsoft ecosystem before reviewing individual controls, our ultimate guide to Microsoft 365 for charities and nonprofits provides a effective starting point.

Microsoft 365 gives charities access to powerful security capabilities, but the safest approach is to understand what is already protecting you, what still requires configuration and which controls are justified by your organisation’s risks. If you’d like help reviewing your Microsoft 365 environment and making those choices intentionally, get in touch with Qlic to discuss your charity’s requirements.

Frequently Asked Questions About M365 Security Features

How do we prove to our charity’s funders that security is handled?

Start by auditing what is currently enabled and configured in Microsoft 365. Document the reasons behind important decisions, including how you protect beneficiary data, manage volunteer and trustee devices, control access and meet any Cyber Essentials requirements.

You can then turn that information into a concise summary for trustees, funders or other stakeholders. Rather than presenting a long list of Microsoft features, explain the risks your charity has identified, the controls being used to manage them, who is responsible and how frequently those arrangements are reviewed.

That demonstrates intentional governance rather than simply relying on whatever settings happened to exist when your Microsoft 365 tenant was created.

Is Microsoft 365 secure by default?

Microsoft 365 includes important baseline security protections, but “secure by default” shouldn’t be interpreted as “fully configured for every charity.”

The appropriate configuration depends on your licence and risk profile. Features and policies involving Defender, Intune, Conditional Access and DLP may require onboarding, configuration, enforcement or tailoring before they provide the protection your organisation expects.

If your charity handles beneficiary data under GDPR, allows volunteers or trustees to access systems from personal devices, or is pursuing Cyber Essentials, reviewing those advanced capabilities is particularly important.

Do I need antivirus if I have M365?

It depends on your Microsoft 365 licence and how your devices are configured.

Email protection and endpoint protection are not the same thing. Microsoft 365 Business Premium includes Microsoft Defender for Business, which provides endpoint protection, but eligible devices still need to be properly onboarded and managed for your organisation to benefit from that protection.

If your charity has correctly deployed Defender for Business across its devices, you may not need a separate third-party antivirus product. MACE, for example, deployed Microsoft’s endpoint protection across its user devices specifically to strengthen device security while reducing reliance on additional software.

Where volunteers or trustees use personal laptops, the decision can be more complicated because your charity may not own or fully manage those devices. In that situation, review your device-management, access and endpoint-security arrangements together rather than assuming that an M365 subscription alone protects every device used to access charity information.

Rae Byrne

Marketing

About the Author

Rae supports marketing activities, including creating content, managing social media, coordinating campaigns, and assisting with research and administrative tasks.

Get the Latest in Charity Tech!

Sign up for our NEWSLETTER!

Categories

Share this post