To block legacy authentication in Microsoft 365 without an outage, first find every account that still signs in with a legacy protocol, using the Entra sign-in logs and the Exchange SMTP AUTH clients report. Then move each printer, scanner and application to a method that doesn't need Basic auth, and only then turn on a Conditional Access policy that blocks Exchange ActiveSync and Other clients, starting in report-only mode. Most breakage comes from multifunction devices that send scan-to-email through smtp.office365.com with a stored username and password, and these can be moved to OAuth, High Volume Email or an SMTP relay connector before the block goes live.
Who this is for and what you will have
This guide is for Microsoft 365 and Entra ID administrators who want to retire legacy authentication on purpose instead of waiting for a device to fail. It assumes you can sign in to the Microsoft Entra admin center and the Exchange admin center. At the end you will have:
- An inventory of every user, service account and device that signed in with a legacy protocol, covering as far back as your logs allow: 30 days in the Entra sign-in logs with P1 or P2, up to 90 days in the SMTP AUTH clients report, and longer if you send sign-in logs to Log Analytics.
- A decision for each one: update the client, move it to a different sending method, or exclude it for a fixed period.
- A Conditional Access policy that blocks legacy authentication, validated in report-only mode before enforcement.
- Exchange Online settings that keep SMTP AUTH off for everyone except the mailboxes that still need it.
If you are planning a wider identity hardening project, the same report-only approach applies to the Microsoft 365 MFA rollout, and blocking legacy authentication is a prerequisite for it, because legacy clients can't satisfy an MFA requirement.
What counts as legacy authentication
Microsoft Entra ID treats as legacy any client that uses Basic (username and password) authentication against a protocol that doesn't support modern authentication. In Conditional Access these clients fall into two checkboxes under Conditions > Client apps:
| Client app option | What it covers |
|---|---|
| Exchange ActiveSync clients | All use of the Exchange ActiveSync (EAS) protocol |
| Other clients | Authenticated SMTP, Autodiscover, Exchange Online PowerShell, Exchange Web Services, IMAP4, MAPI over HTTP, Offline Address Book, Outlook Anywhere (RPC over HTTP), Outlook Service, POP3 and Reporting Web Services |
Microsoft's guidance is blunt about why this matters: legacy clients can't do MFA, and its analysis attributes more than 97 percent of credential stuffing attacks and more than 99 percent of password spray attacks to legacy authentication. Conditional Access grant controls such as Require multifactor authentication also block legacy clients, because they can't satisfy the control. If you already enforce MFA for all users and some legacy sign-ins still succeed, those accounts are excluded somewhere.
Where Exchange Online already stands
Exchange Online has already removed Basic authentication for EAS, POP, IMAP, Remote PowerShell, EWS, Offline Address Book, Autodiscover, Outlook for Windows and Outlook for Mac. The exception is SMTP AUTH client submission. Microsoft's updated timeline keeps Basic auth for SMTP AUTH working until the end of December 2026, when it becomes disabled by default for existing tenants (administrators can still turn it back on), with a final removal date to be announced in the second half of 2027. Microsoft has moved this date before, so check the linked announcement for the current milestones.
That makes authenticated SMTP the protocol most likely to break when you block legacy authentication, and the one to inventory most carefully.
Prerequisites
- Roles: Reports Reader (or higher) to read sign-in logs, Conditional Access Administrator to create the policy, and an Exchange administrator role for the SMTP AUTH report and Exchange Online PowerShell.
- Licensing: Conditional Access requires Microsoft Entra ID P1. Without it, use security defaults, which block all legacy authentication but allow no exclusions.
- Workbook (optional): the Sign-ins using legacy authentication workbook needs Entra ID P1 and a Log Analytics workspace that receives sign-in logs.
- Emergency access accounts: at least one break-glass account to exclude from the policy, so a misconfiguration can't lock every administrator out.
- Exchange Online PowerShell module, connected with
Connect-ExchangeOnline.
Step 1: Inventory legacy sign-ins
Use at least two sources. The Entra sign-in logs show every legacy protocol; the Exchange report shows SMTP senders that the logs make awkward to group.
Entra sign-in logs
- Sign in to the Microsoft Entra admin center as at least a Reports Reader.
- Browse to Entra ID > Monitoring & health > Sign-in logs.
- Select Columns and add Client App if it isn't shown.
- Select Add filters > Client App, choose all the legacy authentication protocols and select Apply.
- Repeat on the User sign-ins (non-interactive) tab so you don't miss non-interactive sign-ins.
Open individual events to see the protocol on the Basic Info tab. Export the list and group it by user principal name and client app.
Sign-ins using legacy authentication workbook
If sign-in logs already flow to Log Analytics, browse to Entra ID > Monitoring & health > Workbooks and open Sign-ins using legacy authentication from the Usage section. It filters by time range (up to 90 days), user, application and sign-in status, and walks you from protocol to application to user.
SMTP AUTH clients report
In the Exchange admin center, open Reports > Mail flow > SMTP AUTH clients. The Authentication Protocol column shows TlsAuthLogin for Basic auth and XOAUTH2 for OAuth. The default view covers 7 days, so set the date range to the maximum of 90 days and use Export to get a CSV.
Every sender with TlsAuthLogin is a device or app that will stop sending when you block legacy authentication or when Basic auth for SMTP AUTH is disabled.
Step 2: Classify each sender and choose a fix
Most findings fall into a few patterns:
| What you found | Typical cause | Fix |
|---|---|---|
| Exchange ActiveSync with a user's phone | Native mail app configured with Basic auth | Remove and re-add the account, or move to Outlook for iOS and Android |
| IMAP4 or POP3 plus Authenticated SMTP | Third-party mail client | Update to a version that supports OAuth, or switch clients |
| Authenticated SMTP from a printer or scanner | Device sends through smtp.office365.com with a stored password | Move to OAuth if the firmware supports it, otherwise HVE or an SMTP relay connector |
| Authenticated SMTP from a line-of-business app | App built on SMTP with a service account | Update the app to OAuth or Microsoft Graph |
| Exchange Online PowerShell or EWS from a script | Old module or custom code | Use the current Exchange Online PowerShell module or OAuth |
| Outlook 2010 or older | Client can't do modern authentication | Upgrade Outlook |
Moving printers and scanners
Microsoft documents several ways for a device to send mail. The one that matters is who the device needs to reach:
| Method | Recipients | Port | How the device authenticates |
|---|---|---|---|
| Client SMTP submission with OAuth | Internal and external | 587 (recommended) or 25 | OAuth token for a licensed mailbox |
| High Volume Email | Internal only | 587 | HVE account with Basic auth or OAuth |
| SMTP relay connector | Internal and external | 25 | Certificate (recommended) or static public IP on an inbound connector |
| Direct Send | Internal only | 25 | None |
For a scanner that must send to external recipients and can't do OAuth, the SMTP relay connector is usually the answer. In the Exchange admin center go to Mail flow > Connectors > Add a connector, set Connection from to Your organization's email server, and on Authenticating sent email choose certificate validation or the device's static public IP address. Point the device at your MX endpoint, for example contoso-com.mail.protection.outlook.com, on port 25 with TLS, and add the IP address to your SPF record.
Relay and Direct Send don't sign in to Microsoft Entra ID with a user account, so the Conditional Access policy in the next step doesn't affect them.
Step 3: Turn SMTP AUTH off where it isn't needed
Before you block legacy authentication tenant-wide, reduce the attack surface in Exchange Online. Microsoft recommends disabling SMTP AUTH for the organization and enabling it only on mailboxes that still need it. The mailbox setting overrides the organization setting.
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
# Turn SMTP AUTH off for the whole organization
Set-TransportConfig -SmtpClientAuthenticationDisabled $true
# Allow it only for a mailbox that still needs it (for example, OAuth sending)
Set-CASMailbox -Identity scanner@contoso.com -SmtpClientAuthenticationDisabled $false
# Check the organization setting and list mailboxes that override it
Get-TransportConfig | Format-List SmtpClientAuthenticationDisabled
Get-CASMailbox -ResultSize unlimited | Where-Object {$_.SmtpClientAuthenticationDisabled -eq $false}The value $null on a mailbox returns control to the organization setting. In the Microsoft 365 admin center the same per-mailbox switch is Authenticated SMTP under Users > Active users > the user > Mail > Manage email apps.
Optional: block Basic auth for SMTP before it reaches Entra ID
Exchange Online authentication policies block Basic auth at the first step, before the credentials are forwarded to Entra ID, which means password spray attempts against those protocols never reach the identity provider. A new policy blocks Basic auth for every protocol unless you allow one:
New-AuthenticationPolicy -Name "Block Basic Auth"
Set-OrganizationConfig -DefaultAuthenticationPolicy "Block Basic Auth"
# A device mailbox that must keep Basic SMTP for a short time
New-AuthenticationPolicy -Name "Allow Basic SMTP" -AllowBasicAuthSmtp
Set-User -Identity scanner@contoso.com -AuthenticationPolicy "Allow Basic SMTP"Policy changes take effect within 24 hours. To apply one within 30 minutes, run Set-User -Identity scanner@contoso.com -STSRefreshTokensValidFrom $([System.DateTime]::UtcNow). If an authentication policy disables Basic auth for SMTP, the client can't use SMTP AUTH with Basic auth even when SmtpClientAuthenticationDisabled is $false.
Step 4: Create the Conditional Access policy in report-only mode
- Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator.
- Browse to Entra ID > Conditional Access > Policies and select New policy.
- Name it according to your standard, for example
CA010-Block legacy authentication-All users. - Under Users or workload identities, include All users. Under Exclude, select your emergency access accounts and a group for temporary exceptions.
- Under Target resources > Resources (formerly cloud apps) > Include, select All resources (formerly 'All cloud apps').
- Under Conditions > Client apps, set Configure to Yes, check only Exchange ActiveSync clients and Other clients, and select Done.
- Under Grant, select Block access.
- Set Enable policy to Report-only and select Create.
Microsoft also publishes this policy as a Conditional Access template if you prefer to deploy it from there.
Handling exceptions
If a device can't be moved before your enforcement date, put its account in the exception group, record an owner and an end date, and make sure the account can only do what it must: SMTP AUTH enabled on that mailbox only, an authentication policy that allows only AllowBasicAuthSmtp, and no admin roles. An excluded account is still protected only by its password, so keep the list short and review it.
Step 5: Review results and enforce
Leave the policy in report-only mode long enough to cover monthly jobs and devices that send rarely. Then review it three ways:
- Sign-in logs: open a legacy sign-in and check the Report-only tab.
Report-only: Failuremeans the policy would have blocked that sign-in. - Policy impact: shows the potential effect on interactive sign-ins over 24 hours, 7 days or 1 month.
- Conditional Access Insights and Reporting workbook: compares report-only and enforced results if you have Log Analytics.
Every Report-only: Failure that isn't an attacker is a client you still need to fix or exclude. When the list is empty or contains only known exceptions, change Enable policy from Report-only to On.
Verification
After enforcement:
- Filter the sign-in logs by Client App for legacy protocols. Remaining entries should show a failure from Conditional Access, or belong to excluded accounts.
- Re-run the SMTP AUTH clients report. Senders should show
XOAUTH2or disappear because they moved to a relay connector or HVE. - Send a test scan from each migrated device to an internal and an external address.
Troubleshooting
A user's phone mail app stops syncing and the user gets a quarantine email. That is expected when the policy blocks Exchange ActiveSync. Remove and re-add the account so the app uses modern authentication, or move the user to Outlook for iOS and Android.
A script fails with AADSTS53003: Access has been blocked by Conditional Access policies. The access policy does not allow token issuance. Open the failed sign-in, check the Conditional Access tab to see which policy applied, and update the script to use the current Exchange Online PowerShell module or app-only authentication.
A scanner stops sending after enforcement. Find its sign-in in the logs: a Client App of Authenticated SMTP with a Conditional Access failure means the device still uses Basic auth against smtp.office365.com. Move it to OAuth, HVE or a relay connector as described in step 2, or add its account to the exception group while you do.
Legacy sign-ins still succeed after enforcement. Check whether the account is in the exclusion group or another policy excludes it. Calls made by service principals aren't covered by policies scoped to users.
A client gets 401 Unauthorized after you assign an authentication policy. That is how Exchange Online responds when an authentication policy blocks Basic auth for the protocol. Check which policy the user has with Get-User and whether the right AllowBasicAuth* switch is set.
Checklist
- Sign-in logs exported for both interactive and non-interactive sign-ins, filtered to legacy client apps, for the full retention period available.
- SMTP AUTH clients report exported for 90 days and every
TlsAuthLoginsender assigned a fix. - Printers and scanners moved to OAuth, HVE, a relay connector or Direct Send.
- SMTP AUTH disabled for the organization and enabled only on mailboxes that need it.
- Conditional Access policy created in report-only mode, results reviewed, then switched to On.
- Emergency access accounts excluded; temporary exceptions documented with owners and end dates.
- Sign-in logs reviewed again a week after enforcement.
References
- Block legacy authentication with Conditional Access
- How to use conditions in Conditional Access policies
- Sign-ins using legacy authentication workbook
- Conditional Access report-only mode and policy impact
- Security defaults in Microsoft Entra ID
- Deprecation of Basic authentication in Exchange Online
- Updated Exchange Online SMTP AUTH Basic Authentication Deprecation Timeline
- Enable or disable SMTP AUTH in Exchange Online
- Disable Basic authentication in Exchange Online
- SMTP AUTH clients report in the new EAC
- How to set up a multifunction device or application to send email using Microsoft 365