Great info in this thread!
For one of my clients, I just enabled Modern Auth about 2 weeks ago. Looks like most Outlook clients have switched over to modern auth but I still see 3-4 users ever day that are connecting with "MAPI over HTTP" so they aren't on Modern Auth yet. They are Office 365-based installations of Outlook so they should be compatible without any reg settings. I ran a script to enable ADAL =1, in case that was not set already and that hasn't made a difference. Any suggestions on how to trouble those machines that are still doing legacy auth?
Also, this client has a ton of "Exchange ActiveSync" in the sign-ins report. Seems to be evenly split between iPhone and Android. But compared to my own org, we have zero entries for Exchange ActiveSync. Shouldn't iPhones and Android largely be doing modern auth automatically if they are using Outlook app, native IOS Mail or Gmail app? Should I be doing something to get rid of the Exchange ActiveSync connections or just leave that as an allowed protocol?
Thanks!
Jason