Skip to content
← Back to the guide

How to block legacy authentication with Conditional Access

8slides. Screenshot a slide, download it as a PNG, or use your browser's Print → Save as PDF for a LinkedIn-ready multi-page carousel — each slide becomes one page.

M
solvingmicrosoft365.com
1 / 8

How to block legacy authentication with Conditional Access

How to block legacy authentication in Entra ID with Conditional Access: find who still uses it, build the block policy, run report-only, then enforce.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-block-legacy-authentication-with-conditional-access

Slide 1Download PNG
M
solvingmicrosoft365.com
2 / 8
01

Isn't legacy authentication already disabled in Microsoft 365?

Mostly. Microsoft turned off Basic authentication for Exchange Online protocols (EWS, POP, IMAP, ActiveSync, Remote PowerShell) for all tenants during 2022–2023, and SMTP AUTH is disabled by default in new tenants. But…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-block-legacy-authentication-with-conditional-access

Slide 2Download PNG
M
solvingmicrosoft365.com
3 / 8
02

Will blocking legacy authentication break printers and scanners that send email?

Only if they use SMTP AUTH with a username and password against Exchange Online — and the sign-in logs will show them before you enforce. The fixes are, in order of preference: Microsoft Graph or OAuth-capable firmware,…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-block-legacy-authentication-with-conditional-access

Slide 3Download PNG
M
solvingmicrosoft365.com
4 / 8
03

Do security defaults block legacy authentication?

Yes. Security defaults block legacy authentication protocols for all users. If your tenant is on security defaults you already have this control, but you cannot combine security defaults with Conditional Access policies…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-block-legacy-authentication-with-conditional-access

Slide 4Download PNG
M
solvingmicrosoft365.com
5 / 8
04

Step 1: Find who still uses legacy authentication

Entra admin center → Monitoring → Sign-in logs, add the Client app filter and select every option except Browser and Mobile Apps and Desktop clients. Include the user sign-ins (non-interactive) and service principal tab…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-block-legacy-authentication-with-conditional-access

Slide 5Download PNG
M
solvingmicrosoft365.com
6 / 8
05

Step 2: Fix or isolate each remaining consumer

Move devices to OAuth-capable firmware or to an Exchange Online connector-based relay that authenticates by certificate or source IP, so no user credential is involved. Old mail profiles just need re-adding with modern…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-block-legacy-authentication-with-conditional-access

Slide 6Download PNG
M
solvingmicrosoft365.com
7 / 8
06

Step 3: Create the policy

Entra admin center → Protection → Conditional Access → Policies → New policy:

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-block-legacy-authentication-with-conditional-access

Slide 7Download PNG
M
solvingmicrosoft365.com
8 / 8
07

Step 4: Run report-only

Leave it in report-only for at least a week (a month if you have monthly batch jobs). Sign-in logs → the sign-in → Report-only tab shows what the policy would have done per sign-in; the Conditional Access Insights and r…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/how-to-block-legacy-authentication-with-conditional-access

Slide 8Download PNG

Auto-generated from How to block legacy authentication with Conditional Access. This page is not indexed and isn't part of the guide itself.