First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Blog/The True Cost of “Free” Microsoft Licenses: Nonp…

The True Cost of “Free” Microsoft Licenses: Nonprofit Grant Changes

2026-06-16·IT PartnerNewMicrosoft 365LicensingCost OptimizationNonprofit

The grant is not the painful part of Microsoft nonprofit licensing. The pain starts when a tenant grows around free Microsoft 365 Business Basic, legacy Office 365 E1, shared mailboxes, volunteers, and a few Business Premium seats — then grant availability changes or security requirements catch up.

The grant did not become expensive. The operating model did.

Many nonprofit licensing problems start with a reasonable choice: use the donated licenses first. That works for a small organization with basic email, web apps, and little device management. It breaks when the same tenant later supports executives, finance, case workers, grant managers, field staff, board members, volunteers, contractors, and a fundraising platform.

Microsoft 365 Business Basic grants and legacy Office 365 E1 grants can be useful for the right users. The problem is using one free SKU as the default for every identity, device, data set, and access pattern.

The hidden costs show up when:

  • Staff need desktop Office apps, not only web and mobile apps.
  • Finance, HR, leadership, and IT need stronger identity and endpoint controls.
  • Sensitive files sync to unmanaged personal devices.
  • Volunteer and board accounts remain active after the relationship ends.
  • Shared mailboxes are used as sign-in accounts.
  • A few paid licenses are used to enable features for users who are not properly licensed.

When Microsoft changes grant availability, renewal terms, or eligibility, the spreadsheet exposes the real issue: the free-license design was carrying operational debt.

The common pattern: free seats for everyone, paid seats for exceptions

A typical nonprofit tenant might have up to 300 donated Microsoft 365 Business Basic seats, up to 10 donated Microsoft 365 Business Premium seats, and several discounted paid licenses added over time. Business Basic is assigned broadly because it is free. Business Premium goes to the CEO, CFO, IT lead, and the users who asked for Outlook desktop most recently.

That feels cost-conscious, but it creates three risks.

First, licensing follows complaints instead of risk. A development user exporting donor data may have a web-only license while a low-risk operations user has Business Premium because they wanted desktop apps.

Second, premium controls may be under-licensed. Conditional Access requires Microsoft Entra ID P1 for each user covered by the policy. Intune device management, Microsoft Defender for Business, and other premium services also require the appropriate license for the users or devices benefiting from them. The admin center may let a configuration work technically; that does not make it compliant.

Third, edge cases become attack paths. Board members, volunteers, shared mailboxes, generic accounts, terminated staff, and seasonal users are often reviewed less rigorously than employees. That is where license waste and security exposure accumulate.

The security cost of a free license can exceed the license cost

The wrong free license may not appear on a Microsoft invoice. It appears as incident response, downtime, cyber-insurance friction, audit findings, or staff time.

A common failure path:

  1. A volunteer receives an internal account with a free grant license.
  2. MFA is registered once, but there is no recurring access review.
  3. The volunteer leaves, but the account stays active because someone might need the mailbox history.
  4. The account still has access to Teams and SharePoint content with donor, event, client, or finance data.
  5. A reused password is compromised elsewhere.
  6. The attacker signs in, creates inbox forwarding, and searches SharePoint for finance, HR, or payment terms.

Microsoft 365 can reduce this risk, but only when the right controls are assigned to the right identities: Conditional Access, compliant-device requirements, phishing-resistant MFA for high-risk roles, Defender policies, external forwarding restrictions, audit logging, and disciplined joiner-mover-leaver processes.

Treat every license assignment as a risk decision. A receptionist, program director, grant writer, finance approver, and board treasurer should not receive the same SKU just because one option is free.

Where nonprofit grant changes create real budget shock

Budget shock usually comes from four scenarios.

Scenario one: legacy E1-heavy tenants. Organizations that relied on large quantities of donated Office 365 E1 seats often cannot replace them one-for-one. Some users can move to Microsoft 365 Business Basic. Some need Business Standard for desktop apps. Some need Business Premium for identity, endpoint, and security controls. Organizations above Business plan limits or with advanced compliance needs may need Enterprise plans.

Scenario two: security requirements change. A funder, cyber insurer, regulator, or board audit asks for Conditional Access, endpoint management, data loss prevention, retention, or stronger auditability. The question changes from “What is the cheapest email license?” to “Which users need which security and compliance services?”

Scenario three: desktop Office dependency was underestimated. Business Basic is appropriate for web-first users. It is a poor fit for staff who rely on advanced Excel workbooks, large Word documents, Outlook desktop workflows, mail merge, add-ins, or offline work.

Scenario four: the tenant was never cleaned up. The organization pays for departed users, keeps licensed shared accounts alive, assigns paid SKUs to inactive mailboxes, or buys add-ons to compensate for a poor base-license choice.

The useful question is not “How do we keep everything free?” It is “Which users can safely stay on donated licenses, which users need paid capabilities, and which accounts should not exist as licensed users at all?”

A practical cost model: classify people before licenses

Start with personas, data exposure, device requirements, and lifecycle. Then map licenses.

Most nonprofits can use five buckets:

  • High-risk core staff: finance, HR, leadership, grant management, program directors, IT, and anyone approving payments or handling regulated or sensitive data. These users often justify Business Premium or an Enterprise equivalent because Microsoft Entra ID P1, Intune, Defender for Business, and data protection matter.
  • Standard productivity staff: users who need desktop Office apps and normal collaboration but have lower data exposure. They may fit Business Standard, Business Premium, or discounted nonprofit Enterprise plans depending on required controls.
  • Web-only/light users: users who can work in browser-based Microsoft 365 apps, Teams, and email. Microsoft 365 Business Basic grant seats can fit when access is limited and device/security requirements are modest.
  • Frontline, seasonal, board, and volunteer users: these identities need defined owners, expiration dates, least privilege, and review. Some need internal licensed accounts; others should be guests, shared-mailbox delegates, or time-bound accounts with restricted access.
  • Non-human and shared functions: shared mailboxes, resource mailboxes, scanners, booking mailboxes, app accounts, and service accounts. Shared mailboxes generally do not need a license if they are under 50 GB and do not require archive or advanced features, but they should not be used for direct sign-in.

Example outcome: instead of upgrading 160 free-license users, a review may identify 35 high-risk users who need Premium-level controls, 50 web-only users who can remain on Business Basic, 20 stale accounts to disable, 15 shared mailboxes to unlicense or convert properly, and 40 users who need desktop apps but not the full high-risk control set.

That segmentation prevents a grant change from becoming a blanket budget increase.

The audit to run before renewal or license changes

Before buying replacements or upgrades, run a tenant-level licensing and security review. Do not make the decision from the billing screen alone.

Review at minimum:

  • Active users by SKU, department, role, manager, and last sign-in date.
  • Users with no sign-in activity in the last 30, 60, and 90 days.
  • Users with admin roles, privileged access, or payment authority.
  • Whether users covered by Conditional Access, Intune, Defender, or compliance features have the required licenses.
  • Shared mailboxes with licenses, direct sign-in enabled, forwarding, delegates, or archive requirements.
  • Mailboxes with external forwarding rules or suspicious inbox rules.
  • Teams and SharePoint sites with external sharing enabled.
  • Users handling finance, HR, donor, client, health, legal, or child/youth-related data.
  • Devices accessing Microsoft 365: managed, compliant, personal, unknown, or legacy-authentication dependent.
  • Guest accounts, stale invitations, board access, volunteer access, and external collaborators.
  • Generic accounts, scanner accounts, service accounts, and accounts excluded from MFA or Conditional Access.

The output should be an action plan: disable these users; convert these mailboxes; remove these licenses; move these users to Business Premium; keep these users on Business Basic; replace these generic accounts; scope this Conditional Access policy correctly; review these high-risk Teams and SharePoint sites.

Specific actions turn nonprofit licensing from a renewal scramble into a controlled remediation plan.

Reality check What it usually means Best-cost move
Donated licenses assigned to nearly everyone Licensing is based on price, not role, data, or device risk Reclassify users by data exposure, device needs, access level, and lifecycle
A few Business Premium licenses used while tenant-wide controls apply broadly Premium services may be technically enabled but not properly licensed for all benefiting users License covered users correctly or narrow policy scope to licensed groups
Conditional Access policies cover users without Microsoft Entra ID P1 The organization may be out of compliance even if the policy works Assign Entra ID P1-capable licenses, such as Business Premium or eligible Enterprise plans, to covered users
Shared mailboxes have paid licenses Former users or generic functions were never cleaned up, or archive/advanced features were not reviewed Convert, delegate, archive, or remove licenses where appropriate; block direct sign-in
Inactive users remain licensed Offboarding is not tied to license recovery Disable stale accounts, preserve data correctly, and reclaim licenses before buying more
Volunteers and board members have standard internal accounts indefinitely Temporary and external users are being treated like employees Use guest access where appropriate, expiration dates, least privilege, and recurring access reviews
Desktop apps drive random upgrades Complaints are dictating SKU selection Separate desktop Office need from security need and choose the lowest compliant SKU
Generic accounts are excluded from MFA or Conditional Access Convenience exceptions have become privileged attack paths Replace with named accounts, managed service identities, app permissions, or tightly controlled exceptions
Grant change triggers a blanket upgrade proposal The organization is reacting without segmentation Build a persona-based migration plan before purchasing

Key takeaways

  • Free nonprofit licenses are valuable, but they do not replace a risk-based licensing model.
  • The biggest hidden costs come from stale accounts, unmanaged devices, under-licensed premium controls, shared mailbox misuse, and weak lifecycle management.
  • Do not replace legacy grant seats one-for-one; segment users by role, data sensitivity, device requirements, and lifecycle.
  • A tenant audit before renewal can change the buying decision by identifying licenses to reclaim, users to upgrade, and accounts to remove.

If you are facing nonprofit grant changes or a renewal decision, start with evidence before buying more licenses. IT Partner’s free Microsoft 365 Tenant Health Check can help identify stale accounts, license waste, risky configurations, and practical next steps: https://www.itpartner365.com/microsoft-365-tenant-health-check-free/

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.