Microsoft 365How-To & HardeningRetrospectives

How to Inventory and Migrate Apps Off Basic Authentication in Exchange Online

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2019, written in 2026 with the benefit of hindsight.

Legacy (basic) authentication bypasses MFA. Even after Microsoft's retirement of basic authentication in Exchange Online, many organizations still find apps, devices and scripts that depend on old authentication patterns. Here is how to inventory and migrate them.

Step 1: Inventory with sign-in logs

In the Entra admin center, filter Sign-in logs by Client app for legacy clients (Exchange ActiveSync, IMAP, POP, SMTP, Other clients). Export 30 days of data and group by user, application and IP address.

Step 2: Check SMTP AUTH separately

SMTP client submission is commonly used by printers, scanners and applications. Review which mailboxes have SMTP AUTH enabled, and check message trace and sign-in logs for SMTP submissions.

Step 3: Migrate by category

  • Users with old mail clients: update to current Outlook or mobile apps with modern authentication.
  • Printers and scanners: use an SMTP relay connector with a static IP, direct send, or a modern-auth-capable device; consider High Volume Email or Azure Communication Services for application mail where appropriate.
  • Applications reading mailboxes: move to Microsoft Graph with an app registration and certificate, scoped with application access policies or RBAC for Applications to specific mailboxes.
  • Admin scripts: use the Exchange Online PowerShell module with modern authentication or certificate-based app-only authentication.

Step 4: Disable per mailbox and tenant

Disable SMTP AUTH at the tenant level and enable it only for mailboxes with a documented need.

Step 5: Block with Conditional Access

Create a Conditional Access policy blocking legacy authentication client apps for all users (excluding break-glass accounts), first in report-only mode.

Verify

The sign-in logs filter for legacy clients should return only blocked attempts.

migrate off basic authenticationBasic auth retirement announced2019

More on this story