This guide explains the ten essential Microsoft 365 security controls we recommend for charities to reduce cyber risk, improve governance and strengthen long-term resilience.
Review your Microsoft 365 email security settings, enable anti-phishing and Safe Links policies, and ensure users are protected against malicious email threats.
Protects your organisation against phishing, malware, spam and business email compromise by securing inbound and outbound email across Microsoft 365.
Why it matters
Email is the most common route for cyber attacks. Effective email security helps prevent malicious messages from reaching users and reduces the risk of account compromise and data loss.
Time to implement
⏱ 2–4 hours
(Depending on existing Exchange Online and Microsoft Defender for Office 365 configuration.)
Who it affects
All Microsoft 365 users who send and receive email, particularly finance teams, trustees, leadership and staff handling sensitive information.
Implementation difficulty
Medium
Licensing
Basic email protection is included with Microsoft 365. Advanced phishing protection and threat investigation require Microsoft Defender for Office 365 Plan 1 or Plan 2, available with selected Microsoft 365 licences.