Age UK Lancashire Head Office supports a wide range of internal teams delivering services that depend on secure access to information, email communication, and shared documentation. As a charity handling sensitive personal data, the organisation places strong importance on cyber security, compliance, and safeguarding. Microsoft 365 sits at the centre of daily operations, making platform security and account protection critical to supporting staff and protecting the people they serve.
Age UK Lancashire identified an opportunity to strengthen its Microsoft 365 security posture and improve its Secure Score. While the platform was already in use across the organisation, additional controls were required to better protect user accounts, devices, and data. There was a need to formalise identity protection, reduce exposure to email-based threats, and introduce clearer governance around data handling and device access.
The organisation wanted to adopt industry best practice security controls without disrupting staff productivity. The review focused on Conditional Access, email protection, user permissions, and mobile device security. The objective was to create a more resilient Microsoft 365 environment that reduced risk, improved visibility, and aligned with modern cyber security standards suitable for a charity environment.
We worked with Age UK Lancashire to deliver a structured security improvement programme across Microsoft 365, focused on increasing Secure Score and strengthening protection across all users and services.
Conditional Access policies were configured and fully enforced, ensuring sign-ins followed approved security conditions and reducing the risk of unauthorised access. Microsoft Defender standard policies were enabled to provide consistent baseline protection across the tenant.
Email security was enhanced through updates to Anti-Phish, Anti-Malware, and Anti-Spam policies, helping to reduce the likelihood of malicious content reaching staff inboxes. A Quarantine Policy was created, alongside updated global quarantine settings, to improve visibility and handling of potential threats.
User consent settings were reviewed and tightened to limit unnecessary application permissions. Data Sensitive Labels were introduced to support better information governance and protection of important data. Company branding was configured within Microsoft 365 to provide a consistent and trusted sign-in experience for users.
To further reduce risk, the ability for users to install Outlook add-ins was disabled, and external calendar sharing was turned off. BYOD App Protection policies were deployed to ensure that business data remained protected on personal mobile devices while respecting user privacy.
This approach delivered meaningful security improvements while maintaining a smooth and familiar experience for staff.
Age UK Lancashire has achieved a significantly stronger Microsoft 365 security posture, reflected in a higher Secure Score and improved protection across accounts, devices, and data. Conditional Access now provides robust identity protection while allowing staff to work efficiently and securely.
Email threats are better controlled, with improved filtering reducing phishing attempts, spam, and malicious attachments before they reach users. The introduction of Data Sensitive Labels has helped structure data handling and improve consistency across the organisation.
BYOD App Protection ensures that charity data remains secure on personal devices without impacting personal information, supporting flexible working practices. Administrative visibility and control have improved, enabling the organisation to manage security settings more confidently.
Overall, the project has embedded modern cyber security standards into the Microsoft 365 environment, reducing risk and providing reassurance that sensitive information is well protected.
- Secure Score increased through structured Microsoft 365 security improvements
- Conditional Access enforced across the organisation
- Enhanced email protection against phishing, malware, and spam
- Clearer control over data access through Sensitive Labels
- Improved protection for mobile users with BYOD App Protection
- Reduced exposure to unnecessary integrations and external sharing