Microsoft 365How-To & HardeningRetrospectives

Legacy Authentication Discovery Checklist for Exchange Online

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2019, written in 2026 with the benefit of hindsight.

Use this checklist to find every remaining dependency on legacy authentication in Exchange Online and Microsoft 365.

Data sources

  • Entra ID sign-in logs filtered by legacy client apps for at least 30 days.
  • Exchange Online reports on SMTP AUTH client submissions.
  • Inventory of applications registered in Entra ID with mail permissions.
  • List of service accounts and shared mailboxes with passwords.

Common sources of legacy authentication

  • Old Outlook versions and third-party mail clients on desktops.
  • Native mail apps on older mobile devices using Exchange ActiveSync.
  • Multifunction printers and scanners sending email.
  • Line-of-business applications sending notifications.
  • Monitoring and ticketing tools reading mailboxes via IMAP or POP.
  • PowerShell scripts using stored credentials.
  • Third-party archiving or backup tools.

For each dependency, record

  • Owner.
  • Protocol and account used.
  • Migration path (modern auth client, Graph API, relay connector, retire).
  • Target date.

Controls after migration

  • Tenant-level SMTP AUTH disabled; enabled only per mailbox where justified.
  • Conditional Access policy blocking legacy authentication in place.
  • Authentication policies blocking basic authentication for remaining protocols (where still applicable).
  • Alert on any successful legacy authentication sign-in.

Review

  • Recheck sign-in logs monthly for new legacy sign-ins introduced by new devices or vendors.
legacy authentication discovery checklistBasic auth retirement announced2019

More on this story