Skip to the main content.
Microsoft 365 Tenant Assessment
Built for Pregnancy Help Centers

Get your Microsoft 365 Security Posture Assessment.

Real Tenant ScanNot a self-quiz
HIPAA-AlignedHealthcare-grade controls
48-Hour ReportPersonalized PDF

An ABT consultant pulls your actual Microsoft Secure Score, maps your tenant against HIPAA-aligned client-data-protection controls and donor-data stewardship best practices, and ships a one-page report telling you what to fix first. Microsoft 365 Copilot readiness check included as bonus. Free for 501(c)(3) pregnancy help centers, Care Net affiliates, and faith-based ministries with medical services.

Trusted by Tier 1 Microsoft CSP Microsoft BAA Included SOC 1 Type II · Security Controls SOC 2 Type I 750+ Regulated Institutions 25+ Years Microsoft Cloud

How the assessment works.

Four steps. Total of your time: about 35 minutes. We do everything else.

1

Tell us about your center

Five short questions: center size, current Microsoft 365 status, top concern. We tailor the report to your context.

5 min · on this page
2

Grant read-only tenant access

Your Microsoft 365 admin grants ABT read-only access via a standard Microsoft consent URL. Nothing is changed in your tenant.

30 min · with your M365 admin
3

ABT runs the scan

We pull your Microsoft Secure Score, map your tenant against HIPAA-aligned controls (the standard Microsoft 365 control set healthcare-grade nonprofits adopt voluntarily), review donor-data stewardship posture, and check Microsoft 365 Copilot readiness as bonus.

48 hours · on us
4

You get your grade + report

Personalized one-page PDF: your current grade, top five gaps, fix priorities, and a 90-day roadmap. Plus a 20-minute walkthrough call.

20 min · walkthrough call

Three things most pregnancy help centers do not realize about their security.

When we run the assessment, this is what we typically find.

  • Your donor list is more visible than you think.Default Microsoft 365 sharing settings often expose donor records to any user in your tenant — including volunteers, including former staff whose accounts were never properly deprovisioned. We tighten access by role + add audit logging so you know who saw what. For pregnancy help centers, the donor list is the asset most vulnerable to targeted attack and the one that, if leaked, you cannot recover from. We harden this first.
  • Your client intake data may not be encrypted at rest.Microsoft 365 includes encryption by default, but the features that matter for sensitive client data — sensitivity labels, Customer Lockbox, eDiscovery hold for breach response — often require a license tier most centers do not have. We confirm what you have, what you are missing, and what nonprofit pricing makes affordable.
  • Your audit logs default to 90 days — too short.Microsoft 365 audit logs need to be retained for at least 12 months to catch the kind of slow data leak that activist groups have used against pregnancy help centers. We extend retention + add alerting that fires within hours, not weeks, so a breach attempt is caught early.

What is inside your report.

Built from your actual Microsoft 365 tenant data. Not from how you answer the questions.

Your one-page assessment report

Six things every pregnancy help center executive director needs to know.

  • Your Microsoft Secure Score (current)The actual number Microsoft assigns your tenant, ranked against pregnancy help centers of similar size. National average for small nonprofits sits in the low 30s. Healthy is 70+.
  • Your top five missing security controlsSpecific Microsoft 365 controls that are turned off, mis-configured, or unlicensed in your tenant. Each one mapped to a fix priority and an estimated time to remediate.
  • HIPAA-aligned client-data protection mapHow your current tenant maps to the HIPAA-aligned controls pregnancy help centers offering medical services (ultrasound, STI testing) voluntarily adopt: access controls, audit logs, encryption at rest, breach notification readiness. Acknowledges Nov 2024 HHS guidance that PRCs may not be HIPAA-covered entities while still positioning the control set as a reasonable trust framework.
  • Donor-data stewardship + board fiduciary reviewHow your tenant protects donor information per ECFA (Evangelical Council for Financial Accountability) expectations, plus a board-fiduciary readiness check. Donor breaches at pregnancy help centers carry both regulatory and reputational risk; board members can be personally exposed.
  • Microsoft 365 Copilot readiness check (bonus)Whether your tenant is configured safely to enable Microsoft 365 Copilot when you are ready. Most centers have at least two configuration gaps that would surface sensitive client information in Copilot results. We tell you what to fix before turning Copilot on.
  • Your 90-day priority roadmapWhat to fix first, second, and third. With pricing where it applies, including Microsoft nonprofit licensing eligibility, Guardian Plan tier options, and which items your existing IT can handle vs which need a Tier 1 Microsoft CSP.

The grade bands.

Where most pregnancy help centers land before working with ABT.

A
Audit-ready
Microsoft Secure Score 85+, full HIPAA-aligned control coverage, donor-data stewardship documented, Copilot ready when desired. Rare in our experience. Most centers in this band already work with a Tier 1 Microsoft CSP.
B
Most controls in place
Secure Score 65 to 84. A handful of HIPAA-aligned control gaps. Donor-data stewardship mostly in place. Copilot needs preparation. Most likely your center is on Microsoft 365 but missing two or three high-impact controls.
C
Foundational gaps
Secure Score 40 to 64. Several HIPAA-aligned controls missing or unlicensed. Donor-data exposure risk meaningful. Copilot not safe to enable today. Typical for centers on Microsoft 365 Business Basic without security add-ons.
D
Significant exposure
Secure Score under 40 or no Microsoft 365 at all. Audit-fail risk. Most centers in this band have an email security gateway in front of a thin tenant, or are still on Google Workspace.

Sister center spotlight

A pregnancy help center that has been doing this work with us.

Alternatives Pregnancy Center, Sacramento, California

A Care Net-affiliated pregnancy help center serving the greater Sacramento area, on ABT’s Guardian Plan + managed Microsoft 365.

Alternatives Pregnancy Center moved their Microsoft 365 tenant and security stack to ABT’s Guardian Plan because their leadership wanted to focus on the women they serve, the donors who fund the mission, and the volunteers who staff their programs — not on IT logistics, HIPAA paperwork, or wondering whether their donor records were safe.

Today their executive team spends meeting time on programs and donor relationships, not on IT troubleshooting. Their board moved past quarterly IT crises into proactive governance. The center’s tech-savvy volunteers stayed at the table — ABT did not replace their existing IT people. We gave them the playbook, kept them in the loop, and let them do their work well.

If you are a Care Net affiliate, a Heartbeat International member center, or any 501(c)(3) faith-based pregnancy help center, your leadership probably knows Alternatives PC’s name already. Ask any sister center in your network. The work is the same; the IT should not get in the way of it.

Start your assessment.

Five questions. Then your ABT consultant reaches out within one business day to set up the tenant scan.

Step 1 of 8

What is the name of your pregnancy help center?

We will use this on your personalized report.

Please tell us your center name.
Step 2 of 8

How many clients does your center see per month?

Best estimate. Used to size the tenant against centers of similar scale.

Fewer than 50
50 to 200
200 to 500
500 to 1,000
More than 1,000
Step 3 of 8

How is your team structured?

Volunteer vs paid staff matters for Microsoft 365 nonprofit licensing eligibility.

Step 4 of 8

Are you currently using Microsoft 365?

Be as honest as you can. If you are not sure, that is a valid answer and helpful.

Yes, Microsoft 365 Business Basic or higher
Yes, but I am not sure which tier
No, we use Google Workspace
No, we use something else for email
I do not know
Step 5 of 8

What is your single biggest concern right now?

Pick the one keeping you up at night. We weight the report accordingly.

Client data leaks or breach exposure
HIPAA-aligned gaps or board fiduciary exposure
Staff productivity and IT slowness
Microsoft 365 Copilot readiness
Honestly, all of the above
Step 6 of 8

Are you a registered 501(c)(3) nonprofit?

This unlocks free and discounted Microsoft 365 licensing.

Yes, we are a 501(c)(3)
Yes, via a parent ministry or umbrella organization
No
I am not sure
Step 7 of 8

Microsoft 365 admin authority.

We need read-only access to your Microsoft 365 tenant to run the real scan. Your admin grants it via a standard Microsoft consent URL.

I am the Microsoft 365 Global Admin
I am not the admin, but I can reach them
Honestly, I do not know who the admin is
We have no Microsoft 365 admin yet
Step 8 of 8 (final)

Where should we send your report?

Your ABT consultant will reach out within one business day to set up the tenant scan.

First name required.
Last name required.
A valid business email is required.

You are in.

Your ABT consultant will review your responses and reach out within one business day to set up the Microsoft 365 tenant scan.

Total time for you from here: about 30 minutes. Your personalized report ships within 48 hours of the scan.

Step 1 of 8

This is a real assessment. Not a self-quiz.

Most "security assessments" or "AI-readiness scorecards" online ask you eight questions and give you a number. We pull data directly from your Microsoft 365 tenant. That is the only way the assessment has any meaning. We need about 30 minutes of your Global Admin's time to grant read-only access. Everything else is on us.

Common questions.

If yours is not here, ask it on the wizard or on the form below.

Read-only means ABT can see how your Microsoft 365 tenant is configured but cannot change anything. The access is granted by your Microsoft 365 Global Admin via a standard Microsoft consent URL. The scopes we request are publicly documented Microsoft Graph read scopes (SecurityEvents.Read.All, SecureScore.Read.All, Reports.Read.All, Policy.Read.All). Your admin can review and revoke the access at any time from the Microsoft 365 admin center.
Your time: about 35 minutes total. Five minutes for the wizard on this page, 30 minutes with your Microsoft 365 Global Admin to grant the access. Our time: 48 hours. We pull the data, run the analysis, and prepare your personalized one-page PDF report. After that, a 20-minute walkthrough call to go over the findings.
The assessment and the walkthrough call are free for 501(c)(3) pregnancy help centers, including Care Net affiliates, Heartbeat International member centers, NIFLA network centers, and other faith-based ministries with a current IRS determination letter or coverage under a parent ministry. There is no obligation to engage ABT for ongoing services after the report.
That is a common starting point. If you are on Google Workspace or another email platform, the wizard tells us, and the report shifts from "what is missing in your tenant" to "what your tenant would look like on Microsoft 365 nonprofit pricing, and what migration would require." You still get a personalized roadmap and walkthrough call.
You and your team decide. The report is yours. If your roadmap is something your existing IT person can implement, great. If it includes work that needs a Microsoft Tier 1 Cloud Solution Provider (managing the Microsoft 365 tenant, running the security stack, layering Guardian Plan on top), ABT is one option but not the only option. We will tell you up front what you can do yourself versus what genuinely needs a partner.
Most online assessments produce a result based on how you answer the questions. Garbage in, garbage out. We pull your actual Microsoft Secure Score, your actual policy configuration, and your actual license footprint directly from Microsoft. The wizard on this page is for context. The grade is from your tenant.

Prefer to talk first?

Skip the wizard, schedule a confidential 20-minute conversation with the ABT pregnancy help center team. We will explain the assessment in more detail and decide together whether it is the right next step for your center.