Forum Discussion
Do we need to update Windows 7 once TLS 1.2 is mandatory for Office 365?
- Jan 26, 2018
So, at first support engineer just provided me the same link about preparing to TLS 1 disabling. When i have provided him my arguments and doubts, he has discussed this with other technical staff and then replied that we don't need to update.
Well, i think there is still a chance something was misunderstood, but at least i now have an official answer. My chief will have a final decision about this though.
Thanks for the reply. I have opened a request today (as well as asking by providing feedback on the message center message, no reply though). But i doubt i will get a useful response. Based on my experience with Office 365 support it seems that they only work with a limited list of FAQ and anything outside of it gets "it's out of our scope" response..
I came to the same conclusion that this update only covers specific scenarios (like hybrid one) and older apps, which are not negotiating TLS on their own and use system's available mechanism. I guess Office 365 ProPlus should be good (same as IE11). When i check traffic on my PC i see TLS 1.0 and TLS 1.2 connections going to MS servers (using Office, Skype, OneDrive). As TLS 1.2 is disabled on Windows 7, it looks like apps are negotiating it on their own without problems. But TLS 1.0 is still in use for some reason (maybe handshakes). Btw, we do use AD Connect to sync AD users to Azure AD. But AD Connect is up to date and on Windows Server 2012, so there shouldn't be problems with it connecting with Azure. We also use SMTP to relay messages from internal systems to Exchange Online. I only see TLS 1.2 in traffic to EO servers from our SMTP (IIS on WS2012). So it seems it is also ok.
All in all, i feel that we most probably don't have to do anything. But i'm still a bit worried if i'm not overlooking something.
So, at first support engineer just provided me the same link about preparing to TLS 1 disabling. When i have provided him my arguments and doubts, he has discussed this with other technical staff and then replied that we don't need to update.
Well, i think there is still a chance something was misunderstood, but at least i now have an official answer. My chief will have a final decision about this though.