How to Verify Legacy Authentication Is Fully Blocked in Your Tenant
Retrospective: this article looks back at events from October 2022, written in 2026 with the benefit of hindsight.
Microsoft retired Basic Authentication for most Exchange Online protocols in 2022, but legacy authentication can still appear through SMTP AUTH, other services or policy gaps. Here is how to verify it's fully blocked.
Step 1: Check sign-in logs
In the Entra admin center, filter Sign-in logs (interactive and non-interactive) by Client app and select legacy authentication clients (Exchange ActiveSync, IMAP, POP3, SMTP, Authenticated SMTP, Exchange Web Services, Other clients). Review the last 30 days.
- Successful legacy sign-ins indicate a gap.
- Failed legacy sign-ins show attempts being blocked.
Step 2: Confirm the Conditional Access block
Make sure a Conditional Access policy blocks legacy authentication for all users (excluding break-glass accounts) and all resources. Check that it's On, not report-only.
Step 3: Check SMTP AUTH
In the Exchange admin center or PowerShell:
Get-TransportConfig | Format-List SmtpClientAuthenticationDisabled
Get-CASMailbox -ResultSize Unlimited | Where-Object {$_.SmtpClientAuthenticationDisabled -eq $false}
Disable SMTP AUTH at the organization level and enable it only on mailboxes that require it, using OAuth where possible.
Step 4: Check authentication policies
Exchange Online authentication policies can block basic authentication for remaining protocols. Confirm a default policy exists if relevant to your tenant.
Step 5: Check other services
Review legacy authentication to other Entra-integrated apps — some third-party apps use resource owner password credentials (ROPC) flows. Block where possible.
Verify
Set an alert for any successful legacy authentication sign-in. It should never fire.