We’re constantly improving the security of Office 365 products and services. Modern Authentication and Conditional Access are two of the best ways of ensuring that your clients can take advantage of authentication features like multi-factor authentication (MFA), third-party SAML identity providers, and are implementing automated access control decisions for accessing your cloud apps based on conditions. Firstly, here’s some news about Modern Authentication. As you might already know, all new Office 365 tenants created on or after August 1, 2017 have Modern Authentication enabled by default in Exchange Online for all clients. Today, we’re announcing that Modern Authentication will soon be enabled for the Windows Outlook client and Skype for Business client in all managed (non-federated) tenants that were created before to August 1, 2017. Those tenants already have Modern Authentication enabled for Outlook mobile, Outlook for Mac and Outlook on the Web, so there are no changes to any of those clients.
Blog Post
Exchange Online - Modern Authentication and Conditional Access Updates
42 Comments
- Chris VarnerCopper Contributor
I'm not sure what changed, but recently I've had a couple of users that once sync'd to the cloud via hybrid config, the modern authentication doesn't work. Most of the users in my environment have no issues at all, but in the last week, I've had two new users created that once migrated to exchange online via hybrid, they no longer use the modern authentication. When trying to configure their mailboxes, they are being prompted with the basic authentication and that obviously will not work. I have done everything I can to try to figure this out and nothing works except to leave them on my local exchange server until this issue is resolved.
- Greg Taylor - EXCHANGE
Microsoft
jsdao - that's a lot of q's. Let me try and answer them;
OAuth won't work with RPC/HTTP - only MAPI/HTTP.
You HAVE to be Hybrid with O365 for Hybrid Modern Auth to work. It will not work direct against on-prem ADFS in the same OWA does.
Your 3 questions;
1. It's not done the same way. It's done by enabling an Auth Server at the Org level, and setting it to the default Auth provider.
2. By doing step #1.
3. No. It cannot.
- jsdaoCopper Contributor
There is a demand by our leadership that we enable MFA for the outlook 2016 Fat Client. We already do this for OWA and ECP by redirecting to on prem ADFS to our internal IDP.
1. We are 100% on prem. 0 hybrid. Yes there are plans, but during the scope of this demand.
2. I ensured that all my VD are setup of Modern Auth. OAUTH is available.
3. Setting RPC does not allow for OAUTH???
4. I have validated the OAUTH cert Get-ExchangeCertificate (Get-AuthConfig).CurrentCertificateThumbprint
5. I have configured exchange online [PS] C:\Windows\system32>Get-PartnerApplication "Exchange Online"
and enabled is set to $TRUE
6. The organizationconfig for oauth2 is set to $TRUE
7. We are only going to allow 2016 and block older versions. ADAL support is on by default.
Questions:
1. When I set MFA for OWA and ECP there was an ADFS issuer that I pointed exchange two. Where is this for MAPI.
2. How do I redirect authentication for MAPI
3. I know AAD and HYBRID scenarios this can be done. Can a 100% ON PREM accomplish this.
- andrasdeakCopper Contributor
Hi,
We create and manage our users at our on-prem AD but it is synced up to O365 and we use Azure MFA.
Are we going to get the Modern Authentication for "Outlook for Office 365 MSO"?
How is this going to affect users with MFA already enabled with an App Password for Outlook?
Thank you!
Andras
- noleschopCopper Contributor
I encourage all to utilize the M365 https://docs.microsoft.com/en-us/office365/admin/manage/message-center?view=o365-worldwide to monitor for change. If its not been communicated via the message center then its likely still under dev.
Some additional unsolicited guidance: MS has a great tool for the https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=.
Have fun!! - assofohdz1575Copper Contributor
Any update on this change (Modern Authentication) ? Our tenant has not recieved the change yet - and I'm wondering whether I need to enable it myself or just wait a bit and let it happen.
- Deleted
We have a managed O365 tenant created before Aug2017, with MFA already enabled on many users, with app passwords on Windows Outlook 2016.
Please i need an answer, if this change will affect these users or not. Will Outlook client pop up this prompt that will ask for users' real passwords the time that Microsoft will roll out this change?
BR
- DeletedWhat is the timeframe for rolling out the modern auth. change to older tenants?
We would like to be able to enable this feature our self, and not just out of the blue by Microsoft.
So I need to know how much time we got before this feature is rolled out?
- DeletedMy tech support rep says that EAS conditional policies that check against device compliance are not supported.
For example, a policy that blocks was except on compliant devices. Is this true and will this change with this rollout?
- DeletedSo this means all users will suffer the awful "Use this account everywhere on your device" additional prompt when they log in. Can we supress this and set it to Never?