Microsoft 365CIO BriefingsRetrospectives

CIO Brief: Legacy Protocols Are a Legacy Risk

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2019, written in 2026 with the benefit of hindsight.

The short version: In 2019, Microsoft announced it would switch off older sign-in methods for its cloud email because they couldn't use multi-factor authentication. It took three years. The lesson: old technology quietly accumulates, and removing it takes longer than anyone expects.

Why legacy protocols are a legacy risk

Older sign-in methods were built before modern security existed. They often accept just a username and password, which means attackers can bypass newer protections entirely. Microsoft found these methods were behind most password-guessing attacks on its email service.

The business impact

  • Security bypass: one old protocol can undo your MFA investment.
  • Operational surprises: printers, scripts and apps stop working when the old method is turned off.
  • Change fatigue when deadlines are rushed.

Questions to ask your team

  • Which systems in our environment still use older sign-in methods?
  • Who owns the devices and applications that depend on them?
  • When a vendor announces a deprecation, how quickly do we start planning?

What good looks like

A maintained inventory of legacy dependencies, owners for each, migration plans with dates, and a habit of starting work as soon as a deprecation is announced.

The decision

Treat every vendor deprecation notice as a project kickoff, not a future problem. The cost of early discovery is small; the cost of an outage on deadline day is not.

exchange online basic authentication impactBasic auth retirement announced2019

More on this story