First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Blog/Nonprofits After Microsoft Grant Changes: Best-C…

Nonprofits After Microsoft Grant Changes: Best-Cost Architecture

2026-06-16·IT PartnerNewMicrosoft 365NonprofitSecurityCost Optimization

Microsoft grant changes did more than raise renewal costs. They exposed licensing decisions that were never designed. Many nonprofits now run a mix of donated Microsoft 365 Business Basic, a small number of Microsoft 365 Business Premium seats, legacy E1/E3 assumptions, shared mailboxes, volunteers, seasonal staff, and unmanaged laptops that touch donor data. The goal is not to buy the cheapest SKU. It is to place paid licenses where they reduce real risk, replace other tools, or support work that donated licenses cannot cover.

The real problem: free licenses hid weak architecture

When grants covered more of the tenant, many nonprofits let licensing grow by habit. New staff received whatever SKU was available. Volunteers stayed active because the license appeared to cost nothing. Shared accounts were tolerated for speed. Finance, HR, executives, and temporary event volunteers often had the same protection level.

That model breaks when donated capacity changes, discounted SKUs become the default, or the board asks why Microsoft spend increased.

The expensive mistake is downgrading everyone. That usually creates three risks:

  • Staff lose desktop Microsoft 365 apps and move work to local storage or personal cloud services.
  • Unmanaged devices keep accessing Exchange, SharePoint, OneDrive, and Teams without compliance controls.
  • The organization saves a small monthly amount while leaving donor, HR, finance, and executive mailboxes exposed.

Start with workload and risk. Who handles payment, payroll, HR, grant, or donor data? Who approves payments? Who uses unmanaged home devices? Who only needs browser access to a schedule or team site? Which former volunteers or board members still have accounts?

In many nonprofit tenants, the first savings do not come from changing plans. They come from removing stale accounts, unlicensing shared mailboxes that do not need licenses, retiring duplicate tools, and assigning stronger security only where the risk justifies it.

Use the grant where it fits, not as your security model

For eligible nonprofits, Microsoft 365 Business Basic is often the cost anchor. It commonly provides donated seats up to the nonprofit program limit and is useful for Exchange email, Teams, SharePoint, OneDrive, and web and mobile Microsoft 365 apps. Microsoft 365 Business Premium commonly includes a small donated allocation and discounted pricing beyond that. Program limits and availability can change, so confirm current quantities in the Microsoft nonprofit portal before finalizing a design.

The trap is treating Business Basic as good enough for everyone because it is donated. Business Basic is a strong fit for low-risk, browser-based users. It is not a complete security architecture for staff who handle restricted data from devices you need to manage.

Microsoft 365 Business Premium is often the best-value nonprofit SKU because it combines productivity, identity, endpoint, and device controls that many organizations otherwise buy separately:

  • Microsoft Entra ID P1 for Conditional Access and related identity controls.
  • Microsoft Intune Plan 1 for device management and compliance policies.
  • Microsoft Defender for Business for endpoint protection.
  • Microsoft Purview capabilities such as sensitivity labels and data loss prevention for supported workloads.
  • Desktop Microsoft 365 apps for Windows and Mac.

Conditional Access is not a free tenant-wide feature. Users protected by Conditional Access need the appropriate Microsoft Entra ID P1 licensing, which is included in Business Premium or available as an add-on. If users remain on Business Basic without Entra ID P1, use security defaults and strong MFA at minimum, but do not assume that matches a managed Conditional Access design.

If the nonprofit is already paying for endpoint protection, mobile device management, basic identity tooling, or VPN workarounds for unmanaged access, Business Premium may cost less than it appears. The decision should compare the whole stack, not only the Microsoft line item.

Use donated Business Basic for users whose access pattern and data risk fit it. Use Business Premium where identity, endpoint, desktop app, and data protection requirements justify the spend.

The best-cost nonprofit architecture: license by persona

A cost-effective Microsoft 365 design should mirror access patterns, not the org chart.

Group users into practical personas:

  1. Core staff: employees with email, Teams, SharePoint, OneDrive, and regular document work.
  2. High-risk staff: finance, HR, executives, development leaders, grant writers, legal, and anyone with payroll, donor, or restricted program data.
  3. Field or program workers: staff using shared devices, mobile devices, or browser-first workflows.
  4. Volunteers, board members, and seasonal users: intermittent access, low data ownership, high offboarding risk.
  5. Shared mailboxes and service accounts: often over-licensed and under-governed.
  6. Administrators: privileged users that should be separate from daily work accounts.

For many nonprofits using Microsoft 365 Business plans, a best-cost pattern looks like this:

  • Business Premium for permanent staff who use organization-managed devices, need desktop apps, or access sensitive data.
  • Business Basic for volunteers, board members, seasonal users, and browser-only program users with limited data access.
  • Business Standard only where desktop apps are required and identity, endpoint, and device management are intentionally covered another way.
  • Unlicensed shared mailboxes unless they require features such as storage over 50 GB, archive, litigation hold, or another licensed compliance requirement.
  • Separate admin accounts with strong controls and no daily email use. License them appropriately for the controls applied to them.

A 75-user nonprofit might use 30 Business Premium licenses for leadership, finance, HR, development, operations, and managed-laptop users; 35 Business Basic licenses for volunteers, board members, and browser-only program access; 5 Business Standard licenses for justified desktop-app-only needs; and 5 unlicensed shared mailboxes. That is usually safer and cheaper than giving every user the same paid SKU.

For nonprofits approaching Microsoft 365 Business plan seat limits, the discussion changes. Enterprise plans such as Microsoft 365 E3 or E5 may be required for scale, compliance, security, or operational reasons. Do not move everyone to enterprise licensing just because it is simpler. First identify which users need enterprise-only capabilities.

Do not cut these controls to save a few dollars

Nonprofits are targeted because they hold useful data, have trusted reputations, and often run lean IT. A common attack path is simple: steal a password, bypass weak MFA, access email, search for invoices or donor files, create forwarding rules, and impersonate a trusted person.

Treat these controls as baseline architecture:

  • MFA for every account. Use phishing-resistant MFA for admins, finance, and other high-risk users where possible.
  • Conditional Access for users licensed with Microsoft Entra ID P1, including policies for device compliance, location, app access, and session controls.
  • Security defaults at minimum for accounts that are not covered by Conditional Access licensing.
  • Block legacy authentication.
  • Require compliant or managed devices for sensitive SharePoint sites, OneDrive content, and finance or HR workflows.
  • Separate privileged admin accounts from daily work accounts.
  • Disable or tightly control automatic external forwarding.
  • Review guest users, anonymous links, and external sharing in Teams, SharePoint, and OneDrive.
  • Use retention and eDiscovery settings for finance, HR, grant, and governance records where licensing supports the requirement.
  • Deploy endpoint protection on organization-owned devices, such as Microsoft Defender for Business when using Business Premium.

Be precise about licensing. Risk-based Conditional Access policies, such as policies driven by sign-in risk or user risk, require Microsoft Entra ID P2. Business Premium includes Entra ID P1, not P2. If risk-based identity protection is required, model the P2 add-on or an enterprise plan for the affected users.

The right question is not, “Can this user survive on Business Basic?” The right question is, “If this account or device is compromised, what data, payments, people, and workflows are exposed?”

Where nonprofits overpay after grant changes

Cost optimization is not only downgrading. In nonprofit tenants, avoidable waste usually appears in five places.

First, stale users. Former staff, inactive volunteers, old board members, and test accounts keep licenses assigned for months or years. Review sign-in activity, group membership, and ownership before renewal.

Second, licensed shared mailboxes. Shared mailboxes usually do not need licenses when accessed by licensed users with delegated permissions. They do need licenses for certain scenarios, such as storage over 50 GB, archive, litigation hold, or specific compliance requirements. Avoid direct login to shared mailboxes; use delegated access and auditability instead.

Third, duplicate security tools. If Business Premium is deployed correctly, Microsoft Defender for Business and Microsoft Intune may replace standalone endpoint and device-management subscriptions for many nonprofits. The savings may appear outside the Microsoft invoice.

Fourth, desktop app assumptions. Some users need desktop Excel, Word, Outlook, or PowerPoint. Others need only Teams, browser-based Microsoft 365 apps, and SharePoint access. Assign desktop-app licenses based on workflow, not habit.

Fifth, overbroad premium licensing. Giving Business Premium, E3, or E5 to every volunteer because it is administratively easy is rarely the best-cost model. Use groups, access reviews, access packages, and offboarding rules to keep a mixed-license model manageable.

Optimize the whole stack: Microsoft licensing, identity controls, endpoint management, retention requirements, backup needs, and support overhead.

A practical 30-day redesign plan

A nonprofit does not need a six-month licensing study. It needs a focused audit and a decision model finance, operations, and IT can defend.

Week 1: inventory the tenant. Export users, assigned licenses, sign-in activity, MFA methods, admin roles, shared mailboxes, guest users, devices, groups, and mailbox forwarding rules. Identify inactive accounts and accounts with no recent sign-in activity. Review Global Administrator, Exchange Administrator, SharePoint Administrator, Teams Administrator, and billing roles.

Week 2: map users to personas. Do not ask department heads which licenses they want. Ask which data users access, whether they need desktop apps, whether they use managed devices, whether they are permanent or temporary, and whether they are staff, volunteers, board members, or guests.

Week 3: define the licensing architecture. Assign Business Premium where device control, Conditional Access, endpoint protection, desktop apps, and sensitive data access justify it. Use donated Business Basic for low-risk web users. Use Business Standard only for justified desktop-app needs when security and device controls are handled separately. Remove licenses from shared mailboxes where possible. Identify any users who truly require enterprise SKUs or add-ons such as Entra ID P2, Microsoft Defender for Office 365, or advanced compliance licensing.

Week 4: implement controls and governance. Build license groups, offboarding rules, MFA and Conditional Access baselines, shared mailbox standards, admin account standards, and a monthly license review. Document exceptions with an owner and review date.

The best result is not just a lower bill. It is a tenant where the CFO understands why one user costs more than another, leadership can explain the risk posture to the board, and IT can manage change without rebuilding licensing every renewal.

User / workload pattern Best-cost default When to upgrade Common mistake to avoid
Permanent staff on organization-managed laptops Microsoft 365 Business Premium Upgrade to enterprise plans or add-ons when enterprise-only compliance, identity, or security features are required Putting staff on Business Basic to save money while leaving devices unmanaged
Finance, HR, executives, development leaders Business Premium minimum Add Entra ID P2, Defender for Office 365, or advanced compliance features if the risk model requires them Treating high-risk users like standard email users
Volunteers, board members, seasonal users Business Basic when browser access is enough Upgrade only if they need desktop apps, managed-device access, or sensitive data access Keeping former volunteers licensed indefinitely
Program users with light collaboration needs Business Basic Business Premium if they access restricted data, use organization devices, or need Conditional Access and device compliance Buying desktop apps for users who only use Teams and web Microsoft 365 apps
Shared mailboxes Usually unlicensed with delegated access License for storage over 50 GB, archive, litigation hold, or specific compliance needs Paying for every info@, donations@, or events@ mailbox by default
Admin accounts Separate privileged accounts with strong MFA and no daily email use License for the identity and security controls applied to the account Using daily email accounts as Global Administrators
Users needing desktop apps but not device management Microsoft 365 Business Standard, selectively Business Premium if Intune, Conditional Access, Defender for Business, or data protection controls are needed Using Business Standard as a cheaper substitute when the real need is security and device control
Users covered by Conditional Access Business Premium or Entra ID P1 licensing Entra ID P2 for risk-based policies such as user risk or sign-in risk Applying Conditional Access broadly without licensing the affected users
Organization near Business plan seat limits or with complex compliance needs Model a Business plus enterprise mix carefully Microsoft 365 E3/E5 or add-ons where specific requirements exist Moving everyone to enterprise licensing for simplicity before proving need

Key takeaways

  • The best-cost nonprofit Microsoft 365 design is persona-based, not one-license-for-everyone.
  • Business Basic is a strong fit for low-risk browser users, but it is not a substitute for managed identity, endpoint, and device controls.
  • Business Premium is often the best-value security and productivity SKU for permanent staff, finance, HR, executives, and users on managed devices.
  • The fastest savings usually come from stale users, over-licensed shared mailboxes, duplicate tools, and desktop-app assumptions.
  • Nonprofits should optimize Microsoft spend and security posture together; separating them creates false savings.

If you are unsure which users should stay on donated licenses, which need Business Premium, and where your tenant carries hidden risk, start with IT Partner’s free Microsoft 365 Tenant Health Check: /microsoft-365-tenant-health-check-free. It provides a practical view of licensing waste, security gaps, and a best-cost architecture for your nonprofit.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.