Trusted IT, Cyber Security & Strategic Guidance Since 2010
This guide explains the ten essential Microsoft 365 security controls we recommend for charities to reduce cyber risk, improve governance and strengthen long-term resilience.
Estimated reading time 🕒 45 seconds
Everything you need to know about this security control in under 60 seconds.
🟢 Security improvement🟢 Risk reduction🟡 Operational impact
Very HighVery HighLow
Multi-Factor AuthenticationMicrosoft DefenderIdentity Protection
→→→
Review how users currently access Microsoft 365 and introduce a baseline Conditional Access policy for all users.
What it does
Applies access rules based on factors such as the user, device, location and level of risk before allowing access to Microsoft 365.
Why it matters
Helps prevent unauthorised access by blocking or challenging suspicious sign-ins and enforcing additional security controls where needed.
Time to implement
⏱ 2–4 hours
Who it affects
All users accessing Microsoft 365, with particular importance for administrators, trustees, remote workers and users handling sensitive information.
Implementation difficulty
Licensing
Included with Microsoft 365 Business Premium and eligible Microsoft 365 enterprise licences.