Event banner
Basic Authentication and Exchange Online AMA
Event Ended
Wednesday, Oct 13, 2021, 09:00 AM PDTEvent details
We are very excited to announce a Basic Authentication and Exchange Online AMA!
An AMA is a live text-based online event similar to a “YamJam” on Yammer or an “Ask Me Anything” on Reddit. This ...
Dylan_Snodgrass
Updated Oct 13, 2021
mmattana
Oct 09, 2021Brass Contributor
Hello there! I have some questions 🙂
- What happens if your Office 365 uses ADFS with federated domains? Do we need to change anything?
- What happens if you use Exchange Active-Sync devices that do not support modern auth? Will they stop working?
- Is there a checklist that we can run against a tenant to understand it's ready to switch off B.A. without impact?
Thanks guys!
Greg Taylor - EXCHANGE
Microsoft
Oct 13, 2021Hi Massimo, Federation with ADFS doesn't really change anything - if you use Basic to authenticate to Exchange Online (which you do when Modern Auth is disabled or unavailable), that will be blocked after we make these changes, federation or not. You need to update the clients/apps to use Oauth (Modern Auth). That includes ActiveSync devices too.
A good way to check to see the impact would be to enable Conditional Access in report only mode, and create a policy to block legacy auth. Or, use the Azure AD Sign In logs to filter by legacy auth and see who's using it.
- mmattanaOct 13, 2021Brass ContributorHi Greg, thank you so much for the answers! Ok for ADFS and EAS. I'll follow up about the CA on the other post! Thank you!