Global Greengrants Fund UK is a charitable organisation dedicated to supporting grassroots environmental and social justice initiatives across the globe. Operating within a complex digital landscape, the organisation manages sensitive donor, partner, and project data, requiring robust security controls to safeguard information. As a mission-driven entity, maintaining trust, compliance, and operational continuity is critical to its ongoing impact.
As part of a routine security and compliance review, Global Greengrants Fund UK identified the need to strengthen its Microsoft 365 security posture. The organisation required improved protection against evolving cyber threats such as phishing, malware, and unauthorised access. There was also a need to address gaps in user access controls, external sharing, and data governance.
The review highlighted inconsistencies in policy enforcement and limited visibility over user activities, increasing the risk of data exposure. Additionally, Microsoft Secure Score metrics indicated opportunities for improvement across identity protection, email security, and data classification. The organisation sought a structured approach to enhance its security framework while ensuring minimal disruption to users and day-to-day operations.
We implemented a comprehensive Secure Score Improvement programme tailored to Global Greengrants Fund UK’s operational needs. Our approach began with the design and deployment of Conditional Access policies, ensuring that access to systems was tightly controlled based on user identity, location, and device compliance. These policies were carefully configured and enforced to balance security with user productivity.
We strengthened endpoint and identity protection by enabling Microsoft Defender Standard policies, providing enhanced threat detection and automated response capabilities. Email security was significantly improved through updates to Anti-Phish, Anti-Malware, and Anti-Spam policies, reducing the likelihood of successful attacks and improving filtering accuracy.
To further protect sensitive data, we implemented Data Sensitivity Labels, enabling the organisation to classify and protect information based on its level of confidentiality. We also reviewed and updated user consent settings to prevent unauthorised third-party application access.
A Quarantine Policy was created and global security settings were aligned to ensure consistent handling of suspicious content. Additionally, Company Branding was configured to deliver clear and trusted communication experiences for users. External sharing risks were mitigated by disabling calendar external sharing, thereby reducing exposure to unknown parties.
Throughout the engagement, we ensured all configurations were aligned with Microsoft best practices and optimised to improve the organisation’s Secure Score while maintaining usability.
Global Greengrants Fund UK achieved a significantly enhanced security posture across its Microsoft 365 environment. The implementation of Conditional Access policies reduced the risk of unauthorised access, whilst improved email filtering and Defender protections provided a strong defence against common cyber threats.
The organisation benefited from greater visibility and control over its data through the introduction of sensitivity labels and enhanced policy management. This not only improved compliance but also increased staff awareness of data handling responsibilities.
Secure Score improvements reflected measurable progress, demonstrating a more resilient and robust security framework. The organisation can now respond more effectively to threats, with improved detection and response mechanisms in place.
Importantly, these changes were implemented with minimal disruption, ensuring staff could continue their work seamlessly. The result is a secure, scalable environment that supports the organisation’s mission while safeguarding critical information and maintaining stakeholder confidence.
- Enhanced Microsoft Secure Score through targeted improvements
- Stronger access controls with Conditional Access enforcement
- Improved protection against phishing, malware, and spam threats
- Deployment of Microsoft Defender Standard policies for advanced threat detection
- Implementation of Data Sensitivity Labels for better data governance
- Reduced risk from third-party applications via updated user consent settings
- A more secure, compliant, and resilient Microsoft 365 environment