Legacy Authentication Discovery Checklist for Exchange Online
Retrospective: this article looks back at events from September 2019, written in 2026 with the benefit of hindsight.
Use this checklist to find every remaining dependency on legacy authentication in Exchange Online and Microsoft 365.
Data sources
- Entra ID sign-in logs filtered by legacy client apps for at least 30 days.
- Exchange Online reports on SMTP AUTH client submissions.
- Inventory of applications registered in Entra ID with mail permissions.
- List of service accounts and shared mailboxes with passwords.
Common sources of legacy authentication
- Old Outlook versions and third-party mail clients on desktops.
- Native mail apps on older mobile devices using Exchange ActiveSync.
- Multifunction printers and scanners sending email.
- Line-of-business applications sending notifications.
- Monitoring and ticketing tools reading mailboxes via IMAP or POP.
- PowerShell scripts using stored credentials.
- Third-party archiving or backup tools.
For each dependency, record
- Owner.
- Protocol and account used.
- Migration path (modern auth client, Graph API, relay connector, retire).
- Target date.
Controls after migration
- Tenant-level SMTP AUTH disabled; enabled only per mailbox where justified.
- Conditional Access policy blocking legacy authentication in place.
- Authentication policies blocking basic authentication for remaining protocols (where still applicable).
- Alert on any successful legacy authentication sign-in.
Review
- Recheck sign-in logs monthly for new legacy sign-ins introduced by new devices or vendors.
- Microsoft Announces Basic Auth Retirement for Exchange Online (Sept 2019) Platform Changes
- How to Inventory and Migrate Apps Off Basic Authentication in Exchange Online How-To & Hardening
- CIO Brief: Legacy Protocols Are a Legacy Risk CIO Briefings