4 ms·
> You can still enable these protocols per user From what I understand, Microsoft will disable basic authentication starting January 2023, and the next few mon
by b215826 4y ago
> You can still enable these protocols per user
From what I understand, Microsoft will disable basic authentication starting January 2023, and the next few months are sort of a "grace period" to migrate to Microsoft's new authentication protocol [1]:
> On September 1, 2022, we announced there will be one final opportunity to postpone this change. Tenants will be allowed to re-enable a protocol once between October 1, 2022 and December 31, 2022. Any protocol exceptions or re-enabled protocols will be turned off early in January 2023, with no possibility of further use. See the full announcement at Basic Authentication Deprecation in Exchange Online – September 2022 Update.
> Microsoft are disabling these and Basic Authentication as most users don’t use them and it’s the primary vector for sending emails from compromised accounts
Even if most users don't use basic auth, I don't see why Microsoft has to disable it altogether. For people who want to keep using legacy clients, it's not too hard to force the usage of application-specific passwords.
[1] https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/deprecation-of-basic-authentication-exchange-online https://learn.microsoft.com/en-us/exchange/clients-and-mobil...
- jonathantf2 4y agoI'm referring to IMAP/POP, you'll be able to use these with OAuth instead of basic auth. I imagine their stats show that 99 percent of users use Outlook of some sort so to up security they turned basic auth off.
- denton-scratch 4y agoSo Microsoft want you to switch from (awful) Basic Auth to a Microsoft-modified version of OAuth, is that it? I don't use Microsoft mail services, except as SMTP destinations. Does Outlook not support Digest Auth? Digest Auth certainly isn't perfect (I seem to remember that it requires an extra roundtrip), but it's not a security disaster like Basic Auth. My main problem with OAuth is that it's hard for users to understand. If we expect users to use the internet securely, then they need to be able to know when that's not what they're doing, and I don't know any ordinary Joe that I could explain OAuth to. Hell, I implemented OAuth once, and now I can't remember how it works. It doesn't help that OAuth is a moving target.