Microsoft Announces Basic Auth Retirement for Exchange Online (Sept 2019)
Retrospective: this article looks back at events from September 2019, written in 2026 with the benefit of hindsight.
In September 2019, Microsoft announced that it would turn off Basic Authentication in Exchange Online for Exchange ActiveSync, POP, IMAP, Exchange Web Services and Remote PowerShell. The original target date was October 2020.
Why Basic Authentication was a problem
Basic Authentication sends a username and password with every request. It cannot support modern multi-factor authentication, Conditional Access or token-based protections. That made it the preferred target for password spraying and credential stuffing: even tenants with MFA enabled could be breached through a legacy protocol that skipped it. Microsoft reported that the vast majority of password spray attacks against its cloud used legacy authentication.
What the change meant for customers
Organizations had to:
- Move users off old mail clients that didn't support modern authentication.
- Update scripts and applications using EWS or Remote PowerShell with Basic Auth.
- Find devices and services — scanners, printers, line-of-business applications — that sent mail or read mailboxes with stored passwords.
The timeline slipped
The COVID-19 pandemic and the scale of the change led Microsoft to postpone. Basic Authentication was finally disabled for most protocols in tenants beginning October 1, 2022, with SMTP AUTH handled separately.
In hindsight
The three-year transition showed how hard it is to remove legacy authentication from large environments — and how much hidden dependency builds up over time. Organizations that started inventorying legacy authentication in 2019 had a calm transition. Those that waited faced outages. The general lesson applies to every deprecation: start discovery the day it is announced.
- How to Inventory and Migrate Apps Off Basic Authentication in Exchange Online How-To & Hardening
- Legacy Authentication Discovery Checklist for Exchange Online How-To & Hardening
- CIO Brief: Legacy Protocols Are a Legacy Risk CIO Briefings