top of page
Search

Microsoft Updates Nonprofits Should Know About in 2026

Ellen Karcsay
Aug 21
4 min read

Microsoft introduced several important pricing, licensing, and security changes in 2026. For nonprofit organizations operating with limited IT resources and tight technology budgets, these changes make now a good time to review Microsoft subscriptions, devices, security practices, and user access.


The goal is not necessarily to purchase more technology. In many cases, nonprofits can reduce costs and risk simply by understanding what they already have and ensuring it is properly configured.


Microsoft Nonprofit License Prices Changed July 1


Microsoft increased prices for several Microsoft 365 nonprofit licenses effective July 1, 2026. Because nonprofit pricing is tied to commercial pricing and discounts, increases in commercial rates also affected some nonprofit plans.


Existing customers generally retain their previous pricing until their first subscription renewal after July 1. As a result, the impact may not appear immediately but could affect an organization's next renewal or annual technology budget.


There are also some positive developments for nonprofits. Microsoft 365 Business Basic remains available as a donated license for eligible nonprofits, while Microsoft 365 Business Premium nonprofit pricing did not increase.


Microsoft has also introduced or announced enhancements to certain plans, including additional email storage, security protections, device management capabilities, and Copilot Chat features.


However, nonprofits should not assume that the licenses they have always used remain the most appropriate or cost-effective options.


Organizations often accumulate unused licenses, assign premium licenses to employees who do not need all of their features, or pay separately for services already included with Microsoft 365.


A regular licensing review can help identify opportunities to reduce unnecessary costs while ensuring employees have the tools they actually need.


Microsoft provides additional information in its official 2026 pricing and packaging updates.


Security Updates Require More Than Clicking "Install"


Microsoft continues to release monthly security updates for Windows and other supported products. Installing these updates promptly remains one of the most effective ways to reduce exposure to ransomware, credential theft, unauthorized access, and other cyber threats.


For nonprofits, patch management should extend beyond employee laptops.


Organizations should confirm that updates are being applied to:

  • Desktop and laptop computers

  • Windows servers

  • Microsoft 365 applications

  • Mobile devices that access organizational information

  • Remote and personally owned devices

  • Network-connected systems and specialized workstations

  • Firmware and device drivers where applicable


It is also important to verify that updates were successfully installed.


A device may be enrolled in an update policy but still miss patches because it is rarely connected, has insufficient storage, is running an unsupported operating system, or has not been restarted.


Effective patch management therefore requires both deployment and verification.


Windows 10 Devices May No Longer Be Protected


Standard support for most editions of Windows 10 ended on October 14, 2025.


Unless a device qualifies for a different lifecycle or is enrolled in Microsoft's Extended Security Updates program, it no longer receives regular security updates.


A Windows 10 computer may continue to operate after its end-of-support date, but continued operation does not mean the device remains secure.


Newly discovered vulnerabilities may remain unpatched, increasing risk to the computer and to the Microsoft 365 accounts and organizational information it can access.


Nonprofits should identify any remaining Windows 10 devices and determine whether to:

  • Upgrade compatible computers to Windows 11

  • Replace devices that cannot support Windows 11

  • Purchase temporary Extended Security Update coverage

  • Remove unsupported computers from access to sensitive systems


This review should be part of a broader technology asset inventory rather than treated as an isolated Windows upgrade project.


Secure Boot Certificates Also Require Attention


Microsoft is replacing older Secure Boot certificates that began expiring in 2026.


Secure Boot helps protect computers during startup by preventing untrusted software from loading before Windows.


Many supported Windows devices will receive updated certificates automatically through Windows Update. Some devices, however, may require firmware or UEFI updates from the manufacturer.


Organizations should confirm that their devices are supported, receiving updates, and successfully receiving the new certificates.


This is particularly important for organizations with older computers, inconsistent patching practices, custom device images, or limited centralized device management.


Authentication Changes May Affect Older Applications


The July 2026 Windows security updates also advanced Microsoft's enforcement of stronger Kerberos encryption.


Older applications and service accounts that still rely on RC4-based authentication may experience connection or sign-in failures.


This issue is most likely to affect organizations with older servers, legacy databases, custom applications, multifunction devices, or service accounts that have not been reviewed recently.


Nonprofits with on-premises Windows environments should ask their technology provider to review outdated Kerberos configurations and authentication-related events before they become operational problems.


What Nonprofits Should Do Now


The 2026 Microsoft changes provide a good opportunity to conduct a structured review of the organization's Microsoft environment.


At minimum, nonprofit leaders should ask:

  • Are we receiving all of the nonprofit grants and discounts for which we qualify?

  • Are employees assigned the right licenses for their actual roles?

  • Are we paying for unused or duplicative licenses?

  • Are all computers, servers, applications, and firmware supported and patched?

  • Are any Windows 10 devices still in use without appropriate Extended Security Update coverage?

  • Are multi-factor authentication and appropriate account protections enforced?

  • Do former employees, volunteers, vendors, or inactive accounts still have access?

  • Are Microsoft 365 security, sharing, retention, and device management settings properly configured?

  • Can we verify that backups and recovery procedures work?

  • Do we have a documented process for monitoring Microsoft changes?


These questions are not simply about Microsoft licensing or technology management.


They are about understanding the organization's overall technology risk, cost, and operational readiness.


Technology Decisions Should Start With What You Already Have


Technology planning does not always need to begin with purchasing new products.


In many cases, the first step is understanding what the organization already owns, how it is configured, who has access, and where avoidable costs or risks exist.


For nonprofits, this can be especially valuable. Limited budgets make it important to ensure that every technology investment supports the organization's mission.


Is Your Microsoft Environment Optimized and Secure?


Karcsay Consulting Group helps nonprofit organizations evaluate Microsoft licensing, security settings, user access, devices, collaboration tools, and technology management practices.


If you are uncertain how the 2026 pricing changes will affect your budget, or whether your Microsoft environment is properly licensed, patched, and protected, KCG can help.


A Microsoft environment assessment can identify risks, reduce unnecessary costs, and provide practical recommendations aligned with your organization's mission, capacity, and budget.


 
 
 

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page