Trusted IT, Cyber Security & Strategic Guidance Since 2010
This guide explains the ten essential Microsoft 365 security controls we recommend for charities to reduce cyber risk, improve governance and strengthen long-term resilience.
Estimated reading time 🕒 45 seconds
Everything you need to know about this security control in under 60 seconds.
🔴 Security improvement🔴 Risk reduction🟢 Operational impact
Very HighVery HighLow
Multi-Factor AuthenticationConditional AccessMicrosoft Defender
→→→
Enable Microsoft Entra Identity Protection, review risky users and sign-ins, and configure automated policies to protect accounts based on ris
What it does
Continuously monitors user sign-ins and identities for suspicious activity, automatically detecting and responding to compromised accounts.
Why it matters
Reduces the risk of account takeover by identifying risky users and sign-ins before attackers can access your Microsoft 365 environment.
Time to implement
⏱ 2–4 hours
(Depending on licensing and existing Conditional Access policies.)
Who it affects
All Microsoft 365 users, particularly administrators, trustees and staff with access to sensitive information.
Implementation difficulty
Licensing
Requires Microsoft Entra ID P2 or Microsoft 365 E5. Some capabilities are not included with Microsoft 365 Business Premium.