Are You Making the Most of Your Microsoft 365 Licence?

16 minutes

You probably know generally what your charity is paying Microsoft each month. But do you know what’s switched on?

Getting a Microsoft 365 licence and getting full value from it are two different things. Following Microsoft’s changes to its nonprofit grants, now is a great time for charities to check.

You may still be using Microsoft 365 Business Premium, but without taking advantage of all of the security and device-management tools included in your licence. Alternatively, you may have moved down to Business Basic since Microsoft changed its nonprofit grant terms in 2025, without feeling certain which capabilities you lost in the process.

Neither situation automatically means you have the wrong Microsoft 365 licence. But it is worth understanding what you have, what’s configured and whether you’re paying for the correct level of service.

This guide will walk you through what to check and what it means. If you’d rather have someone confirm it for you, we’re here to help.

What Changed in 2025 and Why It’s Worth Checking Again

First, a key point: Microsoft 365 Business Premium is not going away. What did change was Microsoft’s free Business Premium grant for eligible nonprofits.

Microsoft announced that its Microsoft 365 Business Premium and Office 365 E1 grants would be discontinued at each nonprofit’s next renewal on or after 1 July 2025. Microsoft continued to offer eligible organisations up to 300 granted Microsoft 365 Business Basic licences, while paid nonprofit plans remained available at discounted rates.

This didn’t mean charities could no longer use Business Premium. It changed how they paid for it.

As Adam Graham explored in Qlic’s Moving to Cloud & Maximising Microsoft 365 webinar, this made it significant for charities to review what their Microsoft licences were providing, rather than simply renewing the setup they had always used.

Microsoft has also made further pricing and packaging changes. Microsoft’s current UK nonprofit pricing lists Business Basic as a grant for up to 300 users, Business Standard at £2.60 per user per month and Business Premium at £4.20 per user per month (based on an annual commitment and excluding VAT). Microsoft currently describes Business Premium as being available to eligible nonprofits at a 75% discount. (These prices can change, so charities should confirm the current rate and their own renewal arrangements before making a budgeting decision.)

You can read Qlic’s explanation of the Microsoft 2026 pricing changes for recent developments, or read our blog about what happened when the Microsoft 365 nonprofit grants were discontinued.

The practical takeaway is simple: if you haven’t reviewed your Microsoft 365 licence since the grant changes, it’s worth doing so. Your charity could be paying for Business Premium without using its most significant capabilities, or it may have moved to Basic and lost security or management features that are focal to the way your organisation operates.

What’s Actually Included at Each Tier

What’s the difference between Microsoft 365 Business Basic and Premium? In simple terms, Business Basic gives charities web and mobile versions of the core Microsoft apps alongside email, Teams and cloud storage. 

Business Standard adds installed desktop Office apps. Business Premium combines those productivity capabilities with a much stronger security, identity and device-management layer.

That final distinction matters because Business Premium is not simply “Standard with a few extras”. For many charities, security and device management are the core reasons to pay for it.

Here’s a simplified comparison:

Feature

Business Basic

Business Standard

Business Premium

Exchange Online (50GB mailbox), Teams, SharePoint and OneDrive

Yes

Yes

Yes

1TB OneDrive cloud storage per user

Yes

Yes

Yes

Web and mobile versions of Word, Excel, PowerPoint and Outlook

Yes

Yes

Yes

Installed desktop Microsoft 365 apps

No

Yes

Yes

Install Office apps on up to 5 PCs/Macs, 5 tablets and 5 phones per user

No

Yes

Yes

Exchange Online Protection (spam and malware filtering)

Yes

Yes

Yes

Microsoft Defender for Business (endpoint protection)

No

No

Yes

Microsoft Intune Plan 1 (MDM/MAM)

No

No

Yes

Microsoft Entra ID P1 (includes Conditional Access)

No

No

Yes

Advanced Device Management and Compliance Policies

No

No

Yes

Microsoft Defender for Office 365 Plan 1 (Safe Links and Safe Attachments)

No

No

Yes

Data Loss Prevention (DLP) and Information Protection

Limited

Limited

Enhanced capabilities included with Premium

Suitable for Cyber Essentials device management requirements without additional licences

No

No

Yes

For the detailed breakdown, Qlic’s Microsoft 365 charities plan comparison is the best reference point.

The main question isn’t necessarily “Which licence has the most features?” It’s “Which features does our charity truly need?”

A small charity whose staff primarily need email, Teams and browser-based apps could find Business Basic sufficient. Another organisation might need locally installed Word and Excel but have relatively straightforward device and security requirements, making Business Standard the best choice.

But if your charity handles beneficiary or donor information, has staff working remotely, manages a mixture of charity-owned and personal devices, needs firmer controls around access, or is strengthening its cyber security, Business Premium can become much more valuable.

The catch is that paying for those capabilities does not mean you’re necessarily making full use of them.

The Features Most Charities Pay For and Never Switch On

This is where a Microsoft 365 licence review can produce the biggest surprises.

Business Premium includes a significant security and management stack. Microsoft itself describes Defender, Entra ID, Intune and Purview among the core security tools available with Business Premium. But licensing a capability and configuring it properly are different things.

Your charity may be paying for protection that is sitting essentially unused.

Microsoft Defender for Business: is every device actually protected?

Microsoft Defender for Business provides business-grade endpoint security for devices. It goes beyond assuming that, because a Windows computer has built-in antivirus, your organisation has an actively managed security strategy.

It can help protect endpoints against threats including malware and ransomware while giving administrators better visibility and control over device security.

This matters for charities because the devices accessing Microsoft 365 are rarely all sitting in one office under the watch of an IT team. Staff may work from home, visit service users, travel between locations or access charity information remotely. A compromised laptop can therefore become a path into organisational data wherever that laptop happens to be.

So, does Business Premium include antivirus and email security? Yes. Business Premium includes Microsoft Defender for Business for endpoint protection, while Microsoft 365 also provides email protection capabilities. Microsoft’s current Business Premium security guidance includes Defender for Business for devices and security capabilities for email and collaboration content. It also provides Safe Links URL scanning, Safe Attachments sandboxing, enhanced anti-phishing protection and impersonation protection. Despite phishing remaining the primary attack vector our team sees in our non-profit clients, these capabilities are often overlooked.

The question to ask is whether devices have been onboarded and whether the relevant protection policies have been configured.

A telltale sign that this area needs consideration is an inability to answer basic questions such as: How many devices currently access charity data? Are they protected? Are there devices showing security risks? Who reviews those alerts?

You should have visibility of the endpoints accessing organisational resources, appropriate protections applied, and someone accountable for acting when Defender identifies a problem.

Qlic can help your charity best use Microsoft Defender and ensure your organisation stays safe against phishing

Microsoft Intune: what happens when a laptop or phone disappears?

Intune is Microsoft’s cloud-based device and application management platform, and Microsoft 365 Business Premium includes Intune Plan 1.

In practical terms, it helps your charity apply security obligations to the devices accessing its systems. That might include requiring appropriate passcodes, checking device compliance and controlling how organisational information can be accessed.

The charity use case becomes particularly obvious when somebody leaves.

Imagine a fundraiser who works remotely and has charity information available on a laptop and phone. If they leave the organisation, you need confidence that their access can be removed correctly. The same principle applies when a device is lost or stolen.

Without proper device management, organisations can end up relying on someone manually checking whether accounts, apps and data have been removed.

If nobody has a dependable inventory of enrolled devices, or your IT team couldn’t quickly tell you which devices are compliant, Intune may already be included in your licence without being fully utilised.

A properly configured environment gives the organisation a much clearer way to manage devices throughout their lifecycle, rather than trying to regain control after something has gone wrong. 

For more information about Intune, you can read our blogs about its role in device management and its benefits for remote working.

For charities where staff and volunteers use personal devices, BYOD (Bring Your Own Device) App Protection Policies can also secure Outlook, Teams, OneDrive and SharePoint on those devices without requiring full device enrollment into Intune management. The Qlic team can assist in setting up a BYOD app protection policy suited to your charity.

Conditional Access: is MFA genuinely enforced?

This is one of the most important distinctions to understand.

Having multi-factor authentication available is not the same as having access policies designed and enforced around the way your charity works.

Conditional Access is Microsoft’s policy engine for restricting access based on conditions such as the user, device, location and application being accessed. Business Premium customers can use Conditional Access through the Microsoft Entra capabilities included with their licence. 

For example, your charity may decide that access to organisational information requires MFA, or that certain resources should only be accessible under specified conditions.

For charities with remote staff, volunteers, trustees or external collaborators, this provides much greater control over who gets access and under what conditions.

The warning sign here is surprisingly straightforward: if someone says, “We have MFA,” but nobody can explain which users are covered, what policies enforce it or what happens when a sign-in doesn’t meet your organisation’s conditions, it warrants a closer look.

Business Premium also includes Self-Service Password Reset. This can reduce IT support requests and improve security when combined with MFA, which is especially valuable for volunteer and remote-working scenarios.

Additionally, it extends access control to external collaboration. You can govern guest access, anonymous link sharing and Teams external collaboration. This is useful where charities work with trustees, funders and external volunteers.

“Sorted” means access controls have been intentionally designed for the charity rather than left to assumptions or individual user choices. 

Data Loss Prevention: what stops sensitive information leaving accidentally?

Not every data incident starts with a hacker. Occasionally somebody simply sends information to the wrong person.

That is particularly important for charities, which can hold sensitive beneficiary information, donor records, bank details, employee information and safeguarding-related data.

Microsoft Purview Data Loss Prevention (DLP) capabilities can help organisations identify and control how sensitive information is shared. Policies can be designed to detect particular types of sensitive content and apply suitable restrictions or warnings.

Think about a staff member accidentally including sensitive information in an email to an external recipient or sharing a document more widely than intended. DLP gives you another layer of protection against human error.

Sensitivity labels can classify, encrypt and restrict sharing of trustee documents, beneficiary information and board papers. Additionally, for trustees using personal machines, Business Premium allows you to block downloads, enforce browser-only access or prevent file synchronisation from unmanaged devices. 

The telltale sign that it isn’t being used is plain: your organisation handles sensitive information, but there are no clearly defined DLP or information-protection policies running what happens when somebody tries to share it.

The objective is not to block staff from doing their jobs. Good configuration should protect sensitive information while keeping legitimate day-to-day work straightforward.

This is not just a theoretical issue. Qlic’s work with Age UK Lancashire provides a practical real-world example. The charity was already using Microsoft 365 Business Premium, but a security review identified opportunities to strengthen configuration around areas including Conditional Access, Microsoft Defender and information protection. Qlic implemented additional controls and improved the organisation’s Microsoft Secure Score without interrupting normal access for staff.

That illustrates the wider point: sometimes a charity does not need to buy another security product. It needs to make improved use of capabilities already sitting inside its existing Microsoft licence.

For organisations without the time or internal expertise to configure and monitor these tools, managed IT support for charities and nonprofits can turn those licensed capabilities into practical protection. And if you want a wider understanding of the platform before deciding what to change, our Ultimate Guide to Microsoft 365 for Charities covers the wider Microsoft 365 landscape.

How do I check what’s configured in our Microsoft 365?

You don’t need to launch a major IT project to get an initial answer.

Start in the Microsoft 365 admin centre. An administrator can look at Users > Active users to review users and their assigned licences. Exporting the user list can also be useful if you want a simple record to review away from the admin centre.

At this stage, you’re looking for the basics. Which plans are assigned? How many people have them? Are different users on different tiers? Do those licence choices still reflect their roles?

For example, if 80 people have Business Premium, ask why. If the answer is because you intentionally use its endpoint protection, Intune and Conditional Access capabilities, that may be excellent value. If the answer is simply “That’s what everyone has always had,” there may be an opportunity to augment either your configuration or your licensing.

Then, look beyond licensing and ask whether the capabilities you are paying for are truly in use. Can someone show you which devices are managed? Which Conditional Access policies apply? Whether Defender is monitoring endpoints? What DLP or sensitivity controls exist?

Microsoft Purview Audit can provide another useful source of evidence. It is Microsoft’s built-in auditing capability for recording and searching user and administrator activity across Microsoft services. Rather than relying exclusively on what people believe has been configured or used, audit data can help authorised administrators investigate what has really been happening in the environment.

Common Configuration Weaknesses Our Experts Spot in Microsoft 365

Our Head of Automation & Compliance at Qlic IT, Dan Green, has stated that some of the gaps we often see across organisations stem not from a lack of investment in security tools, but from underutilising the capabilities they already have. Businesses frequently have access to features such as Conditional Access, Microsoft Defender for Business and Intune, yet these remain partially configured or unused. 

Common issues our team helps our clients identify in their set-up include: 

  • relying solely on Security Defaults instead of Conditional Access
  • failing to onboard devices into Defender
  • leaving Intune unused
  • not separating administrative accounts from day-to-day user accounts
  • enabling MFA only for Microsoft 365 while other critical systems remain unprotected
  • legacy authentication protocols that can bypass modern security controls
  • unrestricted access to SharePoint data from unmanaged devices
  • a lack of data classification and sensitivity labelling
  • Safe Links and Safe Attachments left at default settings
  • Microsoft Secure Score not being reviewed for extended periods. 

These gaps can significantly weaken an organisation’s security posture, despite already paying for the licences and tools needed to address them.

One detail worth checking particularly is whether auditing is enabled for your organisation. Microsoft’s current documentation notes that auditing is not enabled by default for SMB licences including Business Basic, Business Standard and Business Premium, so don’t assume that an audit trail is available without confirming the tenant’s status.

None of this is intended to replace a proper Microsoft 365 health check. A quick self-review is unlikely to tell you whether every policy is exactly correct.

What it will tell you is whether it’s worth looking deeper.

If you discover that nobody can confidently explain which licences you have, which devices are managed, which security policies are active or what happens to sensitive data when it is shared, you have your answer.

Switch It On, Move Up, or Move Down?

Once you know what’s missing, or what you’re paying for and don’t need, the decision becomes much simpler.

  • Already on Premium and missing features? Switch on and configure the capabilities you already pay for. You may not need another product or licence; the value could already be sitting inside your tenant.
  • On Basic and need the security layer? Consider moving the relevant users to Business Premium. The nonprofit rate can make the upgrade considerably less expensive than commercial pricing, and the included security and management tools may replace capabilities you would otherwise have to source separately.
  • Already on Premium but don’t need the security stack? Business Standard may save you money while retaining installed desktop Office applications. Review requirements carefully before downgrading so you understand which identity, device-management and security controls would be affected.

So, is Microsoft 365 Business Premium worth it for a charity?

A quick gut-check:

  • Managing volunteer or trustee devices, handling beneficiary data, supporting remote workers or working towards Cyber Essentials? Business Premium is likely to be worth serious consideration. Its combination of endpoint security, device management and identity controls can replace tools you might otherwise need to buy and manage individually.
  • Just need core apps, email and collaboration? Business Standard may be enough if you need installed desktop applications, while Business Basic may suit eligible users whose requirements can be met through web and mobile apps. Don’t pay for capabilities your charity has deliberately decided it doesn’t need.

The important word there is deliberately.

Downgrading simply because nobody has configured the Business Premium security stack can potentially create issues. Equally, paying for Premium year after year when you have assessed your needs and genuinely don’t require its additional capabilities is difficult to justify.

The right licence is the one that matches your charity’s actual working practices, security risks and budget.

Most of the value, and much of the risk, in Microsoft 365 ultimately comes down to configuration and knowing what you currently have available.

A licence alone doesn’t manage a lost laptop. It doesn’t decide who should be challenged for MFA. It doesn’t create the right DLP policies for beneficiary information. And it doesn’t certainly tell you whether you are paying for features your organisation doesn’t need.

That is why a short Microsoft 365 licence and configuration review can be so useful. You may discover security improvements you can make using tools you already have. You may find that upgrading a group of users gives you capabilities you currently lack. Or you may identify licences that can legitimately be moved down, releasing budget for something more valuable.

Qlic’s team of 45 supports more than 350 organisations across the UK, giving us a broad view of the Microsoft 365 challenges charities encounter in the real world. Often, the opportunity is not to add more technology but to configure existing technology accurately and make sure the organisation recognises what it is paying for.

You can carry out the initial checks yourself. And if you would rather have someone confirm what is configured, identify what is missing and help prioritise the changes, Qlic is here to support you.

Download our Microsoft 365 health-check checklist to see what your charity should review.

Rae Byrne

Marketing

About the Author

Rae supports marketing activities, including creating content, managing social media, coordinating campaigns, and assisting with research and administrative tasks.