HomeinetExchange Online: Starting in January, it will no longer support basic auth

Exchange Online: Starting in January, it will no longer support basic auth

Microsoft has warned that it will permanently disable Exchange Online basic authentication, starting in early January 2023, in order to strengthen protection.

See also: Microsoft Outlook: Fix for Exchange Online mailbox issues

Exchange Online

“Starting in early January, we will send notifications to users affected by this change so they have 7 days to consider disabling Basic auth for all applicable protocols.” This crucial update was announced on Tuesday by the Exchange team.

The company has issued several advisories on the subject over the past three years, with the initial one being issued in September 2019. Two more followed, in September 2021 and May 2022 respectively, as customers had not yet migrated to the more modern authentication. Now, the company is finally making this announcement to ensure everyone’s safety.

CISA a warning in June to government and private sector organizations using Microsoft's Exchange cloud email platform, recommending they move away from legacy authentication methods that lack proper multi-factor authentication (MFA) protection.

In September 2022, a warning was issued that basic authentication would be disabled for random users worldwide in October, giving individuals the opportunity to re-enable this protocol once until December.

See also: Microsoft: Retires Exchange Online access rules in one year
basic authentication

The old Exchange Online basic auth login protocol is soon to be phased out, affecting Exchange ActiveSync (EAS), POP, IMAP, Remote PowerShell (RPS), Exchange Web Services (EWS), Offline Address Book (OAB), Autodiscover, and Outlook for Windows and Mac.

To protect customer security, the SMTP AUTH protocol will be disabled on all accounts where it is not currently in use.

Starting in early January 2023, these protocols will be permanently disabled for basic authentication use. There is no way to re-enable them after this time.

Microsoft has taken proactive measures to protect user accounts from attacks that exploit the vulnerable basic auth login system, disabling millions of users who were not already using it and disabling all unused protocols for those who still use it.

See also: Microsoft: Investigating ongoing Exchange Online outage

In January 2023, customers may experience multiple issues when basic authorization is disabled. These may include the inability to access Exchange Online, which will be a significant inconvenience.

The Exchange team provides clear instructions on how to stop basic auth, thus preventing your email applications from constantly asking for credentials or failing to connect

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS