Find and Block Legacy Authentication in Microsoft 365
By Gordon Graff · Published
Legacy authentication refers to sign-in methods where the username and password are sent directly to the service – for example older mail protocols such as POP, IMAP or SMTP with Basic authentication. These methods cannot perform multi-factor authentication.
As a result, even a consistently deployed MFA rollout is ineffective as long as an attacker can sign in through a legacy protocol with a guessed or stolen password. Microsoft therefore lists blocking legacy authentication as one of the most important single measures for identity security.
What Microsoft has already switched off
In Exchange Online, Microsoft has permanently disabled Basic authentication for most protocols, including Exchange ActiveSync, POP, IMAP, EWS and Remote PowerShell. Microsoft has also announced the end of Basic authentication for SMTP AUTH (client submission); the current timeline is published on Microsoft Learn.
A dedicated Conditional Access block is still worthwhile: it applies tenant-wide to all applications, is independent of individual service settings and makes remaining usage visible in the logs.
Finding remaining usage
In the Microsoft Entra ID sign-in logs you can filter by the “Client app” column. Relevant entries are everything other than “Browser” or “Mobile apps and desktop clients”, for example “Exchange ActiveSync”, “IMAP4”, “POP3”, “Authenticated SMTP” or “Other clients”.
Typical sources are multifunction printers and scanners with scan-to-email, older line-of-business applications, monitoring scripts or mailboxes that third-party systems read via IMAP.
Alternatives for devices and applications
- Move applications and scripts to modern authentication (OAuth 2.0) or Microsoft Graph.
- Run scan-to-email through an SMTP relay with an Exchange Online connector or via Direct Send instead of storing a user password on the device.
- Check for current firmware – many devices now support OAuth.
- Decommission integrations that are no longer needed.
Blocking with Conditional Access
The policy targets all users and all cloud apps; under “Conditions → Client apps” select “Exchange ActiveSync clients” and “Other clients”, and set the grant control to “Block access”. As with every policy, exclude the emergency access accounts.
Again: enable the policy in report-only mode first and review the results in the sign-in logs. Enforce it only once every legitimate source has been migrated.
Key takeaway
Switching off legacy authentication is one of the most effective single measures in Microsoft 365. The work is not in the policy itself but in a clean inventory: who still uses the old protocols, and what is the modern alternative?