Exchange Online Basic Auth Turned Off (Oct 2022): The End of an Era
Retrospective: this article looks back at events from October 2022, written in 2026 with the benefit of hindsight.
Beginning October 1, 2022, Microsoft started permanently disabling Basic Authentication in Exchange Online for Exchange ActiveSync, POP, IMAP, Remote PowerShell, Exchange Web Services, Offline Address Book and Outlook for Windows (MAPI/RPC). The change had been announced in 2019 and delayed by the pandemic.
What changed
Tenants were switched over in batches. Any client or application still using Basic Authentication for those protocols stopped working and had to move to modern authentication (OAuth 2.0). Microsoft offered a one-time temporary re-enablement option through the end of 2022 for organizations caught off guard.
SMTP AUTH was handled separately because many devices depended on it; Microsoft announced later timelines for retiring Basic Auth for SMTP client submission.
What broke
- Old mail clients on desktops and mobile devices.
- Scanners and multifunction printers that read or sent mail with stored passwords.
- Scripts and integrations using EWS or Remote PowerShell with passwords.
- Some third-party apps that hadn't updated.
What got safer
Basic Authentication had been the main avenue for password spraying against Exchange Online. Removing it meant MFA and Conditional Access applied consistently to email access. Microsoft reported substantial declines in password spray success.
In hindsight
The basic auth retirement was one of the largest security improvements Microsoft forced on its customers. It also showed how platform defaults can achieve what years of recommendations couldn't. Organizations should still check: Conditional Access policies blocking legacy authentication protect other services and catch anything that slipped through.
- How to Verify Legacy Authentication Is Fully Blocked in Your Tenant How-To & Hardening
- Post-Basic-Auth Cleanup Checklist: SMTP AUTH, Service Accounts and Scripts How-To & Hardening
- CIO Brief: What Broke When Basic Auth Died — and What Got Safer CIO Briefings