Security & identity

Block legacy authentication in Microsoft 365 without breaking printers

Find every device and app that still signs in with legacy authentication, move printers and scanners to a supported sending method, then block legacy auth with Conditional Access.

13 min read
On this page

To block legacy authentication in Microsoft 365 without an outage, first find every account that still signs in with a legacy protocol, using the Entra sign-in logs and the Exchange SMTP AUTH clients report. Then move each printer, scanner and application to a method that doesn't need Basic auth, and only then turn on a Conditional Access policy that blocks Exchange ActiveSync and Other clients, starting in report-only mode. Most breakage comes from multifunction devices that send scan-to-email through smtp.office365.com with a stored username and password, and these can be moved to OAuth, High Volume Email or an SMTP relay connector before the block goes live.

Who this is for and what you will have

This guide is for Microsoft 365 and Entra ID administrators who want to retire legacy authentication on purpose instead of waiting for a device to fail. It assumes you can sign in to the Microsoft Entra admin center and the Exchange admin center. At the end you will have:

  • An inventory of every user, service account and device that signed in with a legacy protocol, covering as far back as your logs allow: 30 days in the Entra sign-in logs with P1 or P2, up to 90 days in the SMTP AUTH clients report, and longer if you send sign-in logs to Log Analytics.
  • A decision for each one: update the client, move it to a different sending method, or exclude it for a fixed period.
  • A Conditional Access policy that blocks legacy authentication, validated in report-only mode before enforcement.
  • Exchange Online settings that keep SMTP AUTH off for everyone except the mailboxes that still need it.

If you are planning a wider identity hardening project, the same report-only approach applies to the Microsoft 365 MFA rollout, and blocking legacy authentication is a prerequisite for it, because legacy clients can't satisfy an MFA requirement.

What counts as legacy authentication

Microsoft Entra ID treats as legacy any client that uses Basic (username and password) authentication against a protocol that doesn't support modern authentication. In Conditional Access these clients fall into two checkboxes under Conditions > Client apps:

Client app optionWhat it covers
Exchange ActiveSync clientsAll use of the Exchange ActiveSync (EAS) protocol
Other clientsAuthenticated SMTP, Autodiscover, Exchange Online PowerShell, Exchange Web Services, IMAP4, MAPI over HTTP, Offline Address Book, Outlook Anywhere (RPC over HTTP), Outlook Service, POP3 and Reporting Web Services

Microsoft's guidance is blunt about why this matters: legacy clients can't do MFA, and its analysis attributes more than 97 percent of credential stuffing attacks and more than 99 percent of password spray attacks to legacy authentication. Conditional Access grant controls such as Require multifactor authentication also block legacy clients, because they can't satisfy the control. If you already enforce MFA for all users and some legacy sign-ins still succeed, those accounts are excluded somewhere.

Where Exchange Online already stands

Exchange Online has already removed Basic authentication for EAS, POP, IMAP, Remote PowerShell, EWS, Offline Address Book, Autodiscover, Outlook for Windows and Outlook for Mac. The exception is SMTP AUTH client submission. Microsoft's updated timeline keeps Basic auth for SMTP AUTH working until the end of December 2026, when it becomes disabled by default for existing tenants (administrators can still turn it back on), with a final removal date to be announced in the second half of 2027. Microsoft has moved this date before, so check the linked announcement for the current milestones.

That makes authenticated SMTP the protocol most likely to break when you block legacy authentication, and the one to inventory most carefully.

Prerequisites

  • Roles: Reports Reader (or higher) to read sign-in logs, Conditional Access Administrator to create the policy, and an Exchange administrator role for the SMTP AUTH report and Exchange Online PowerShell.
  • Licensing: Conditional Access requires Microsoft Entra ID P1. Without it, use security defaults, which block all legacy authentication but allow no exclusions.
  • Workbook (optional): the Sign-ins using legacy authentication workbook needs Entra ID P1 and a Log Analytics workspace that receives sign-in logs.
  • Emergency access accounts: at least one break-glass account to exclude from the policy, so a misconfiguration can't lock every administrator out.
  • Exchange Online PowerShell module, connected with Connect-ExchangeOnline.

Step 1: Inventory legacy sign-ins

Use at least two sources. The Entra sign-in logs show every legacy protocol; the Exchange report shows SMTP senders that the logs make awkward to group.

Entra sign-in logs

  1. Sign in to the Microsoft Entra admin center as at least a Reports Reader.
  2. Browse to Entra ID > Monitoring & health > Sign-in logs.
  3. Select Columns and add Client App if it isn't shown.
  4. Select Add filters > Client App, choose all the legacy authentication protocols and select Apply.
  5. Repeat on the User sign-ins (non-interactive) tab so you don't miss non-interactive sign-ins.

Open individual events to see the protocol on the Basic Info tab. Export the list and group it by user principal name and client app.

Sign-ins using legacy authentication workbook

If sign-in logs already flow to Log Analytics, browse to Entra ID > Monitoring & health > Workbooks and open Sign-ins using legacy authentication from the Usage section. It filters by time range (up to 90 days), user, application and sign-in status, and walks you from protocol to application to user.

SMTP AUTH clients report

In the Exchange admin center, open Reports > Mail flow > SMTP AUTH clients. The Authentication Protocol column shows TlsAuthLogin for Basic auth and XOAUTH2 for OAuth. The default view covers 7 days, so set the date range to the maximum of 90 days and use Export to get a CSV.

Every sender with TlsAuthLogin is a device or app that will stop sending when you block legacy authentication or when Basic auth for SMTP AUTH is disabled.

Step 2: Classify each sender and choose a fix

Most findings fall into a few patterns:

What you foundTypical causeFix
Exchange ActiveSync with a user's phoneNative mail app configured with Basic authRemove and re-add the account, or move to Outlook for iOS and Android
IMAP4 or POP3 plus Authenticated SMTPThird-party mail clientUpdate to a version that supports OAuth, or switch clients
Authenticated SMTP from a printer or scannerDevice sends through smtp.office365.com with a stored passwordMove to OAuth if the firmware supports it, otherwise HVE or an SMTP relay connector
Authenticated SMTP from a line-of-business appApp built on SMTP with a service accountUpdate the app to OAuth or Microsoft Graph
Exchange Online PowerShell or EWS from a scriptOld module or custom codeUse the current Exchange Online PowerShell module or OAuth
Outlook 2010 or olderClient can't do modern authenticationUpgrade Outlook

Moving printers and scanners

Microsoft documents several ways for a device to send mail. The one that matters is who the device needs to reach:

MethodRecipientsPortHow the device authenticates
Client SMTP submission with OAuthInternal and external587 (recommended) or 25OAuth token for a licensed mailbox
High Volume EmailInternal only587HVE account with Basic auth or OAuth
SMTP relay connectorInternal and external25Certificate (recommended) or static public IP on an inbound connector
Direct SendInternal only25None

For a scanner that must send to external recipients and can't do OAuth, the SMTP relay connector is usually the answer. In the Exchange admin center go to Mail flow > Connectors > Add a connector, set Connection from to Your organization's email server, and on Authenticating sent email choose certificate validation or the device's static public IP address. Point the device at your MX endpoint, for example contoso-com.mail.protection.outlook.com, on port 25 with TLS, and add the IP address to your SPF record.

Relay and Direct Send don't sign in to Microsoft Entra ID with a user account, so the Conditional Access policy in the next step doesn't affect them.

Step 3: Turn SMTP AUTH off where it isn't needed

Before you block legacy authentication tenant-wide, reduce the attack surface in Exchange Online. Microsoft recommends disabling SMTP AUTH for the organization and enabling it only on mailboxes that still need it. The mailbox setting overrides the organization setting.

Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
 
# Turn SMTP AUTH off for the whole organization
Set-TransportConfig -SmtpClientAuthenticationDisabled $true
 
# Allow it only for a mailbox that still needs it (for example, OAuth sending)
Set-CASMailbox -Identity scanner@contoso.com -SmtpClientAuthenticationDisabled $false
 
# Check the organization setting and list mailboxes that override it
Get-TransportConfig | Format-List SmtpClientAuthenticationDisabled
Get-CASMailbox -ResultSize unlimited | Where-Object {$_.SmtpClientAuthenticationDisabled -eq $false}

The value $null on a mailbox returns control to the organization setting. In the Microsoft 365 admin center the same per-mailbox switch is Authenticated SMTP under Users > Active users > the user > Mail > Manage email apps.

Optional: block Basic auth for SMTP before it reaches Entra ID

Exchange Online authentication policies block Basic auth at the first step, before the credentials are forwarded to Entra ID, which means password spray attempts against those protocols never reach the identity provider. A new policy blocks Basic auth for every protocol unless you allow one:

New-AuthenticationPolicy -Name "Block Basic Auth"
Set-OrganizationConfig -DefaultAuthenticationPolicy "Block Basic Auth"
 
# A device mailbox that must keep Basic SMTP for a short time
New-AuthenticationPolicy -Name "Allow Basic SMTP" -AllowBasicAuthSmtp
Set-User -Identity scanner@contoso.com -AuthenticationPolicy "Allow Basic SMTP"

Policy changes take effect within 24 hours. To apply one within 30 minutes, run Set-User -Identity scanner@contoso.com -STSRefreshTokensValidFrom $([System.DateTime]::UtcNow). If an authentication policy disables Basic auth for SMTP, the client can't use SMTP AUTH with Basic auth even when SmtpClientAuthenticationDisabled is $false.

Step 4: Create the Conditional Access policy in report-only mode

  1. Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator.
  2. Browse to Entra ID > Conditional Access > Policies and select New policy.
  3. Name it according to your standard, for example CA010-Block legacy authentication-All users.
  4. Under Users or workload identities, include All users. Under Exclude, select your emergency access accounts and a group for temporary exceptions.
  5. Under Target resources > Resources (formerly cloud apps) > Include, select All resources (formerly 'All cloud apps').
  6. Under Conditions > Client apps, set Configure to Yes, check only Exchange ActiveSync clients and Other clients, and select Done.
  7. Under Grant, select Block access.
  8. Set Enable policy to Report-only and select Create.

Microsoft also publishes this policy as a Conditional Access template if you prefer to deploy it from there.

Handling exceptions

If a device can't be moved before your enforcement date, put its account in the exception group, record an owner and an end date, and make sure the account can only do what it must: SMTP AUTH enabled on that mailbox only, an authentication policy that allows only AllowBasicAuthSmtp, and no admin roles. An excluded account is still protected only by its password, so keep the list short and review it.

Step 5: Review results and enforce

Leave the policy in report-only mode long enough to cover monthly jobs and devices that send rarely. Then review it three ways:

  • Sign-in logs: open a legacy sign-in and check the Report-only tab. Report-only: Failure means the policy would have blocked that sign-in.
  • Policy impact: shows the potential effect on interactive sign-ins over 24 hours, 7 days or 1 month.
  • Conditional Access Insights and Reporting workbook: compares report-only and enforced results if you have Log Analytics.

Every Report-only: Failure that isn't an attacker is a client you still need to fix or exclude. When the list is empty or contains only known exceptions, change Enable policy from Report-only to On.

Verification

After enforcement:

  • Filter the sign-in logs by Client App for legacy protocols. Remaining entries should show a failure from Conditional Access, or belong to excluded accounts.
  • Re-run the SMTP AUTH clients report. Senders should show XOAUTH2 or disappear because they moved to a relay connector or HVE.
  • Send a test scan from each migrated device to an internal and an external address.

Troubleshooting

A user's phone mail app stops syncing and the user gets a quarantine email. That is expected when the policy blocks Exchange ActiveSync. Remove and re-add the account so the app uses modern authentication, or move the user to Outlook for iOS and Android.

A script fails with AADSTS53003: Access has been blocked by Conditional Access policies. The access policy does not allow token issuance. Open the failed sign-in, check the Conditional Access tab to see which policy applied, and update the script to use the current Exchange Online PowerShell module or app-only authentication.

A scanner stops sending after enforcement. Find its sign-in in the logs: a Client App of Authenticated SMTP with a Conditional Access failure means the device still uses Basic auth against smtp.office365.com. Move it to OAuth, HVE or a relay connector as described in step 2, or add its account to the exception group while you do.

Legacy sign-ins still succeed after enforcement. Check whether the account is in the exclusion group or another policy excludes it. Calls made by service principals aren't covered by policies scoped to users.

A client gets 401 Unauthorized after you assign an authentication policy. That is how Exchange Online responds when an authentication policy blocks Basic auth for the protocol. Check which policy the user has with Get-User and whether the right AllowBasicAuth* switch is set.

Checklist

  • Sign-in logs exported for both interactive and non-interactive sign-ins, filtered to legacy client apps, for the full retention period available.
  • SMTP AUTH clients report exported for 90 days and every TlsAuthLogin sender assigned a fix.
  • Printers and scanners moved to OAuth, HVE, a relay connector or Direct Send.
  • SMTP AUTH disabled for the organization and enabled only on mailboxes that need it.
  • Conditional Access policy created in report-only mode, results reviewed, then switched to On.
  • Emergency access accounts excluded; temporary exceptions documented with owners and end dates.
  • Sign-in logs reviewed again a week after enforcement.

References

Questions people ask

Does blocking legacy authentication stop my printer from scanning to email?

It does if the printer signs in to smtp.office365.com with a username and password, because that is authenticated SMTP with Basic auth and the Other clients condition covers SMTP. Printers that use an SMTP relay connector or Direct Send don't sign in with a user account, so a Conditional Access policy that targets users doesn't apply to them.

Can I block legacy authentication without Microsoft Entra ID P1?

Yes. Security defaults block all legacy authentication requests and are available at no extra cost. You can't exclude individual accounts from security defaults, so every dependent device has to be fixed before you turn them on.

How do I find which users still use legacy authentication?

In the Microsoft Entra admin center, open the sign-in logs, add the Client App column and filter it to the legacy protocols, on both the interactive and the non-interactive tabs. The Sign-ins using legacy authentication workbook and the SMTP AUTH clients report in the Exchange admin center give you the same picture grouped by protocol and sender.

Isn't Basic authentication already turned off in Exchange Online?

For most protocols, yes. Microsoft removed Basic auth for EAS, POP, IMAP, Remote PowerShell, EWS, OAB, Autodiscover and Outlook, but SMTP AUTH client submission still accepts it until it is disabled by default at the end of December 2026. A Conditional Access block stops password-only sign-ins over that protocol now, on your schedule.

Microsoft 365Exchange OnlineConditional AccessSMTP AUTHMicrosoft Entra ID
  1. Plan a Microsoft 365 MFA rollout with Conditional Access and Authenticator

    A phased plan to require MFA for every Microsoft 365 user: pick security defaults or Conditional Access, set authentication methods, drive registration, pilot in report-only mode, then enforce.

  2. A Microsoft 365 tenant security baseline you can apply in a day

    Harden a new or existing Microsoft 365 tenant in one working day: emergency access, admin roles, MFA and legacy auth, app consent, email protection, external forwarding, audit logging and Secure Score.

  3. AADSTS50076, 50079 and 50158: fix Microsoft Entra MFA sign-in errors

    What AADSTS50076, AADSTS50079 and AADSTS50158 mean, how to find the policy that demanded MFA in the Entra sign-in logs, and how to fix each one for users, scripts and federated domains.