We’re constantly improving the security of Office 365 products and services. Modern Authentication and Conditional Access are two of the best ways of ensuring that your clients can take advantage of authentication features like multi-factor authentication (MFA), third-party SAML identity providers, and are implementing automated access control decisions for accessing your cloud apps based on conditions. Firstly, here’s some news about Modern Authentication. As you might already know, all new Office 365 tenants created on or after August 1, 2017 have Modern Authentication enabled by default in Exchange Online for all clients. Today, we’re announcing that Modern Authentication will soon be enabled for the Windows Outlook client and Skype for Business client in all managed (non-federated) tenants that were created before to August 1, 2017. Those tenants already have Modern Authentication enabled for Outlook mobile, Outlook for Mac and Outlook on the Web, so there are no changes to any of those clients.
Blog Post
Exchange Online - Modern Authentication and Conditional Access Updates
42 Comments
- redamalekiBrass Contributor
Greg Taylor - EXCHANGE and The_Exchange_Team is there any guidance available for implementing Cloud Azure MFA today for OWA for Exchange Server 2016 on-premise? We're using AADC with pass-through authentication (no ADFS). The majority of existing documentation points to Azure MFA server, which is no longer supported for new deployments.
- Greg001Copper ContributorThere's an issue I'm having with this that I'd like to pass on to the developers, but I'm having a hard time finding a way to report it so I'm giving this a try in case someone sees it. We use group policy to have Outlook 2016 autoconfigure the first time it's launched, connecting people to accounts hosted on Office 365. Under the old system you'd see the Outlook loading splash, then the old login prompt would appear at the top of the screen, the user would fill it out and click OK, and then everything would continue and be fine. With the new system the modern auth login appears centered in the screen *behind* the loading splash. The password field is hidden and everything lines up so perfectly that many users don't realize it's a separate window they have to click on to bring to the foreground and log in. We just get people saying Outlook isn't loading. It looks like this: https://imgur.com/CBAG28y Outlook needs to be updated to either force the login window to appear above the loading splash, or to position it at the top of the screen so the password field is visible and it's more obvious to users what's happening. Already tried submitting this to the Outlook UserVoice (mod said post to TechNet) posted it to TechNet, contacted support.office.com (chat said open a O365 ticket) and opened an O365 ticket (guy said post to UserVoice. Alas.)
- Greg Taylor - EXCHANGE
Microsoft
Here's a great blog on that subject - https://blogs.technet.microsoft.com/praveenkumar/2013/07/17/how-to-create-service-requests-to-contact-office-365-support/
- Chris VarnerCopper Contributor
OK, I have used this same user on another computer and it doesn't work there either. But it does work for the other E1 licensed users on that machine.
How do I open a support case?
- Greg Taylor - EXCHANGE
Microsoft
Set ExcludeExplicit0365Endpoint back to 0. or remove it. Get AutoD working properly.
If those users can configure a profile on a different machine then clearly it's something in the registry local to the machines they have causing it. If they can't create a profile on a different machine, it's the user account in some way.
Opening a support case might be a better way of continuing to figure out what's going on.
- Chris VarnerCopper Contributor
OK with all of the above registry settings applied to the user, it still doesn't work and AutoDiscover has stopped working. After putting in all of the users information manually, it still wont connect. Any other user on the PC works fine.
- Chris VarnerCopper Contributor
OK, Here are the Current Registry settings I have in place. Let me add that these were only added because of these two users that are having this issue. Before them, everything worked fine.
This issue is happening with Outlook 2016.
All are DWORD values.
HKCU\Software\Microsoft\Office\16.0\Common\Identity\EnableADAL is set to "1"
HKCU\Software\Microsoft\Exchange\MapiHttpDisabled is set to "0"
HKCU\Software\Microsoft\Exchange\AlwaysUseMSOAuthForAutoDiscover is set to "1"
I will add ExcludeExplicit0365Endpoint and see if that makes a difference.
- Greg Taylor - EXCHANGE
Microsoft
Ok, then there are likely some reg keys under HKCU causing this. What version of Outlook is this?
Check for ExcludeExplicit0365Endpoint and make sure it's 0. Also check the client is using MAPI/HTTP and EnableADAL is set to 1 if this is Outlook 2013, or not set to 0 regardless of version.
- Chris VarnerCopper Contributor
Greg Taylor - EXCHANGE I don't think so because I just deleted the Outlook profile, tried to recreate it, and it started prompting for credentials using the Basic Authentication screen. I know it is going to fail at that point. Also, there is only one other user that has this issue. It isn't affecting everyone like it is affecting these two users. The current Exchange Online incident that just came out today sounds very similar to what I am experiencing with these two accounts, but these users don't have multiple accounts. This is issue is really mind blowing because it isn't affecting everyone the same. I can log into this same PC with a different E1 licensed user and Outlook works fine, so why it is happening for these 2 users is beyond me. If I migrate her back to the On-Prem server, it works fine.
- Greg Taylor - EXCHANGE
Microsoft
Chris Varner - that's odd Chris. We did have one new issue we're seeing - could this be it? https://support.microsoft.com/en-us/help/4516672/outlook-shows-disconnected-after-modern-authentication-enabled