Security in Microsoft for Nonprofits

Microsoft's approach to securing data relies on an understanding of shared responsibility in the cloud model.

Microsoft
Microsoft cloud services are built on a foundation of trust and security. Microsoft enables the best-in-breed security controls, monitoring, and protections to ensure that when you come to the cloud it's trustworthy.


The security of your Microsoft cloud service is an operational partnership between Microsoft and you.

You
You own your data and all user identities. You're responsible for protecting them, the security of your on-premises resources, and the security of cloud components you control (varies by service).
Responsibility On-premises IaaS PaaS SaaS
Customer data
Configurations and settings
Identities and users
Client devices
Applications
Network controls
Operating system
Physical hosts
Physical network
Physical data center

■ Customer       ◩ Shared       ☐ Microsoft

Microsoft commitment to secure solutions

Microsoft uses the best development and operation practices outlined in Microsoft Security Development Lifecycle (SDL) and Microsoft Operational Security Assurance (OSA). Microsoft developers validate that source code, documentation, configurations, and dependencies don’t cause unintended side effects. For more information, see Security development and operations overview.

The data security section in Microsoft Products and Services Data Protection Addendum (DPA) describes the security practices and policies adopted by Microsoft online services.

Shared responsibility and customer responsibilities

Follow best practices when deploying into Azure. These best practices help ensure that your data is secure and your privacy controls are addressed.

Protecting your data also requires that all aspects of your security and compliance program include your cloud infrastructure and data. The following guidance can help you secure your deployment.

Security across Microsoft for Nonprofits solutions

Microsoft for Nonprofits isn't a single product. It's a set of solutions built on different Microsoft platforms, and each solution inherits the security model of the platform it's built on. Configure security separately for each solution you deploy. Settings that you apply to one solution don't carry over to another, and a control that exists on one platform might have no equivalent on another.

Solution Built on Where you configure security
Azure Landing Zone for Nonprofits Azure Azure role-based access control, network controls, and policy. For more information, see Security design in Azure
Common Data Model for Nonprofits Microsoft Dataverse Dataverse security roles
Fundraising Model-driven app on Dataverse Dataverse security roles
Grant Management Model-driven app on Dataverse Dataverse security roles
Outcome Management Model-driven app on Dataverse Dataverse security roles
Volunteer Management Model-driven app on Dataverse Security in Volunteer Management and Volunteer Engagement
Volunteer Engagement Power Pages Security in Volunteer Management and Volunteer Engagement
Nonprofit data solutions Microsoft Fabric Security in Microsoft Fabric, workspace roles, and report access
Manage volunteers Teams template Microsoft Teams Team and channel membership. For more information, see Security guide for Microsoft Teams
Volunteer center SharePoint template SharePoint Sharing and permissions in the SharePoint modern experience

Solutions that are reachable by people outside your organization need more attention than internal ones. Volunteer Engagement is a public-facing website, and SharePoint and Teams content can be shared externally. So, review the sharing and anonymous access settings for those solutions specifically.

Controls that apply across solutions

The following controls are configured once for your tenant or environment and affect every solution you deploy. None of them are enabled automatically, and the defaults might not match your organization's obligations.

  • Identity and access: All the solutions rely on Microsoft Entra ID for staff sign-in. Require multifactor authentication and apply Conditional Access policies to the people who administer or use the solutions.

  • Least privilege: Grant the minimum access each role needs. Review administrator roles, security role assignments, application users, and guest accounts on a regular schedule.

  • Environment and tenant governance: Separate production from development and test. Use data policies to control which connectors can be used together. For more information, see Power Platform environments overview.

  • Data classification and protection: Constituent, donor, and volunteer records are often sensitive or subject to regulation. Use sensitivity labels and Microsoft Purview to classify and protect the data your solutions hold.

  • Auditing and monitoring: Turn on auditing for the data you need to track. Decide who reviews the logs and how long you keep them. For more information, see Auditing solutions in Microsoft Purview.

  • External sharing: Decide deliberately which content is reachable anonymously or by guests. Revisit that decision when you extend or customize solutions.

Deploying a Microsoft for Nonprofits solution doesn't by itself make your environment secure. Treat the controls in this article as a starting point, validate them against your own risk profile and regulatory obligations, and review them as your deployment changes.

Microsoft Purview for data governance and inventory discovery

One of the most essential aspects of a security model is ensuring that your data stored in the cloud, hybrid, and on-premises is classified and cataloged. Microsoft Purview can help you assess and inventory your network.

Microsoft Purview can connect to and classify the following services used in Microsoft for Nonprofits:

Microsoft Defender for Cloud protects your deployment

Use Defender for Cloud to protect Microsoft for Nonprofits. Defender for Cloud provides Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) for all of your Azure, on-premises, and multicloud (Amazon AWS and Google GCP) resources. Defender for Cloud fills three vital needs as you manage the security of your resources and workloads in the cloud and on-premises:

  • Defender for Cloud secure score: Continually assesses your security posture so you can track new security opportunities and precisely report on the progress of your security efforts.
  • Defender for Cloud recommendations: Secures your workloads with step-by-step actions that protect your workloads from known security risks.
  • Defender for Cloud alerts: Defends your workloads in real-time so you can react immediately and prevent security events from developing.

Defender for Cloud can protect the following elements of Microsoft for Nonprofits:

Microsoft Sentinel cloud-based security operations

Microsoft Sentinel delivers intelligent security analytics and threat intelligence across your enterprise. You can integrate the following services used in Microsoft for Nonprofits into Microsoft Sentinel. Sentinel provides a full view of your security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution.

For guidance on deploying, managing, and using Microsoft Sentinel, go to Best practices for Microsoft Sentinel.

Configuring your auditable logs in Office 365 gives you a richer view of your data. Microsoft provides an extensive set of logging and audit capabilities in the following portals:

You can enable logging and monitoring for each service capability: