How to Block Legacy Authentication to Stop Password Spraying in Microsoft 365
Retrospective: this article looks back at events from March 2018, written in 2026 with the benefit of hindsight.
Password spraying succeeds most often through legacy authentication protocols that cannot perform MFA. Blocking legacy authentication closes that door. Here is how to do it safely in Microsoft 365.
What counts as legacy authentication
Older protocols that send a username and password with each request and do not support modern authentication: POP, IMAP, SMTP AUTH, Exchange ActiveSync with basic auth, older Office clients and some third-party apps. Microsoft disabled basic authentication for most Exchange Online protocols in 2022, but legacy flows can still appear elsewhere — and older tenants may have exceptions.
Step 1: Find who still uses it
In the Entra admin center, open Sign-in logs, add a filter for Client app, and select the legacy authentication clients. Review 30 days of data. Typical findings: old multifunction printers, line-of-business apps, scripts and a few users with old mail clients.
Step 2: Fix the stragglers
- Move scanners and apps to modern authentication or a dedicated SMTP relay.
- Update mail clients to modern versions.
- Replace scripts using basic auth with app registrations and certificate authentication.
Step 3: Create the block policy
Create a Conditional Access policy:
- Users: all users, excluding break-glass accounts.
- Target resources: all resources.
- Conditions → Client apps: Exchange ActiveSync clients and Other clients.
- Grant: Block access.
Run it in Report-only for a week, then enable.
Step 4: Ban weak passwords
Add a custom banned password list with your company name, products and locations in Entra Password Protection.
Verify
Sign-in logs should show no successful legacy authentication sign-ins. Keep an alert for any that appear.