Most nonprofits now run email, files, and calendars in Microsoft 365. That makes it the front door to donor lists, grant files, and board documents. Strong Microsoft 365 security depends less on buying new tools and more on configuring the settings you already have.
Why default settings fall short
Microsoft 365 works out of the box, but convenience drives many of its defaults. For example, users can often share files with anyone who has a link. Also, older sign-in methods may still work, even though they bypass modern protections.
Nonprofits add their own complications. Volunteers share generic accounts, former staff keep mailboxes for years, and board members forward messages to personal email. Each habit widens the attack surface.
In addition, many tenants grow without a plan. A volunteer sets up email, a consultant adds Teams, and nobody reviews the whole picture. As a result, settings drift away from what the organization actually needs.
Lock down identity first
Attackers rarely break in through clever hacking. Instead, they sign in with stolen passwords. That is why identity controls come first.
Start by requiring multifactor authentication for every account, including executives and board members. Next, block legacy authentication, since it cannot enforce MFA. If your license includes Conditional Access, use it to block sign-ins from countries where you do not operate.
Then review admin roles. Limit global administrators to a few separate accounts that people use only for admin tasks. Daily email should never run under an admin login.
Control sharing in SharePoint, OneDrive, and Teams
Files move easily in Microsoft 365, which helps collaboration and also creates risk. A single “anyone” link to a client spreadsheet can expose sensitive data to strangers.
So set the default sharing link to “specific people” or “people in your organization.” Also, set expiration dates on external links. For Teams, decide whether guests can join and who can invite them.
Finally, organize sites by sensitivity. For instance, keep program files with client data in a separate site with tighter membership than the general staff site.
A Microsoft 365 security checklist
Use this list to review your tenant with your IT partner. Most items take minutes to change, yet each one closes a common gap.
- MFA enforced for every user, including shared accounts where possible
- Legacy authentication blocked across the tenant
- A small number of dedicated admin accounts, each with MFA
- Automatic forwarding to outside addresses turned off
- Default sharing links set to internal or specific people
- Unified audit logging turned on and retained
- Former staff accounts blocked, with mailboxes converted or delegated
- Alerts reviewed for risky sign-ins and new inbox rules
- Secure Score checked monthly for new recommendations
Watch for account compromise
Even with MFA, attackers still try tricks such as fake login pages that capture session tokens. So you need a way to notice when something looks wrong.
Warning signs include sign-ins from unusual locations, new rules that move or delete messages, and sudden bursts of outgoing mail. For example, an attacker inside a development director’s mailbox may create a rule that hides replies from donors.
Because these clues appear in logs, someone must actually review them. Many small nonprofits lack the time, which is why outside monitoring often makes sense.
When you spot a compromised account, act quickly. First, reset the password and revoke active sessions. Then remove any rules or forwarding the attacker created, and check whether they sent messages to donors or vendors.
Back up your Microsoft 365 data
Microsoft runs the service, but restoring data that you or an attacker deleted largely falls to you. Recycle bins and retention settings help, yet they have time limits and gaps.
Therefore, a separate backup protects against accidental deletion, malicious insiders, and ransomware that syncs through OneDrive. Also, test a restore of a mailbox and a SharePoint folder at least once a year.
In addition, decide how long to keep backups of former staff mailboxes. Grant files and donor correspondence may need to stay available long after someone leaves.
How WEBIT helps
WEBIT approaches Microsoft 365 security by reviewing your tenant against the CIS Controls baseline we apply to every client, then fixing the gaps we find. Our Security Advanced add-on brings Microsoft 365 threat detection and response, email security, and Microsoft 365 backup.
We also offer Duo MFA and managed SIEM when you need stronger monitoring. Learn more on our cloud infrastructure page, or contact us to schedule a tenant review.
Key takeaways
- Default Microsoft 365 settings favor convenience, so review them deliberately.
- MFA, blocked legacy sign-ins, and separate admin accounts protect identity first.
- Tighter sharing defaults keep client and donor files away from strangers.
- Someone needs to watch sign-in logs and inbox rules for signs of compromise.
- A separate backup covers deletions that built-in retention may miss.