We’re constantly improving the security of Office 365 products and services. Modern Authentication and Conditional Access are two of the best ways of ensuring that your clients can take advantage of authentication features like multi-factor authentication (MFA), third-party SAML identity providers, and are implementing automated access control decisions for accessing your cloud apps based on conditions. Firstly, here’s some news about Modern Authentication. As you might already know, all new Office 365 tenants created on or after August 1, 2017 have Modern Authentication enabled by default in Exchange Online for all clients. Today, we’re announcing that Modern Authentication will soon be enabled for the Windows Outlook client and Skype for Business client in all managed (non-federated) tenants that were created before to August 1, 2017. Those tenants already have Modern Authentication enabled for Outlook mobile, Outlook for Mac and Outlook on the Web, so there are no changes to any of those clients.
Blog Post
Exchange Team Blog
4 MIN READ
Exchange Online - Modern Authentication and Conditional Access Updates
The_Exchange_Team
Apr 01, 2019Platinum Contributor
42 Comments
- DeletedHow do I opt out, prevent or delay this change from happening? I do not want modern authentication enabled on my tenant.
- DeletedWe have multi factor authentication enabled and app passwords deployed to about 500 devices (Outlook 2016 and iOS mail). Enabling modern authentication for the tenant is going break all of our devices. I need a way to roll this out gradually without disrupting our users.
- DeletedIn order for the update for EAS in Conditional Access does the tenant have to be managed or does this change take affect into a federated environment as well?
- DeletedThe EAS change will happen for all tenants, managed auth or federated.
- DeletedWhat does this mean for Outlook 2010 clients which while still possibly not supported still work with O365?
- DeletedThere's no impact to Outlook 2010, as it can't trigger the Modern Auth flow.
- DeletedOut tenant has approx 30 different domains associated with it. Some of the domains are Managed (Password Hash sync or Cloud Only identities which authenticate directly in the cloud) and others are Federated and authenticate against an on-premise AD using ADFS. So - we have a foot in each camp......how will this change affect us?
- DeletedIf you have multiple domains, some managed, some federated, we'll treat your tenant as federated. No changes will take place at this time.
- DeletedIs it only for Office 365 installs of Outlook or will Outlook 2016 MSI versions also be able to utilise this?
- DeletedOutlook 2016 MSI/Perpetual supports MA, so it will work for that client too.
- DeletedWill on premises mailboxes in hybrid environments be able to take advantage of this?
- DeletedThis doesn't apply to on-premises mailboxes, only this in Exchange Online.
- DeletedWe’ve had a ton of issues with needing to reinstall Office or reconnect users to Azure Ad based on a recent change to modern authentication. What changed in the last six weeks to make this change as seamless as you’re saying it will be?
- DeletedHi StuBeck,
We saw an issue when we turned on Modern Auth for an older tenant where a very small set of users received a login prompt which was caused by the account logged into Office ProPlus (via the File > Office Account tab). It was only a few users but we just had to remove their creds from Credential Manager and have them log back in. Then the prompts were resolved.
- DeletedDid you raise a support incident for the issues? You should if not, we're not aware of anything in particular that might explain the issues you describe.
- DeletedDoes the EAS change go into effect immediately? Or is it rolling out? What's the time frame?
- DeletedIt's slowly rolling out now.
- DeletedWhat indicators will we have to know this change has rolled out to our tenant?
- DeletedThe EAS change has started rolling out and we've sent Message Center posts to all tenants we believe might see an impact based on their existing policies. So check Message Center.
- DeletedIs this an aprils fool or is this announcement just be done at an unfortunate date?
- DeletedOh it's for real, just unfortunate timing, but we wanted to get the message out asap.
- DeletedGreg, how do we not know that your comment isn't also part of the April Fool's gag?