Older protocols, such as Exchange ActiveSync and legacy mail apps (the Other clients category), that sign in with basic authentication. MFA isn't possible with them, so Conditional Access policies use the client apps condition to block them.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Legacy authentication in context, with comparison tables and the common traps.
Terms in this definition
- Exchange ActiveSync
A protocol some phone and tablet email apps rely on for syncing mail. Conditional Access classes it as legacy authentication, so policies aimed at it should be scoped to Exchange Online alone.
- Deployment credentials
Username and password pairs for local Git and FTP/S on App Service. They use basic authentication and are not Entra identities.
- MFA
Multifactor authentication: asking for another factor on top of a password at sign-in, usually required by a Conditional Access grant control.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
Related terms
- EWS
A legacy Exchange client protocol that falls into the legacy authentication category. Such clients can't perform MFA, so Conditional Access usually blocks them.
- IMAP
An older email protocol relying on legacy sign-in that cannot prompt for multifactor authentication; this weakness is the reason organisations use Conditional Access to shut legacy authentication off.
- Microsoft Entra workbooks
Interactive Azure Monitor reports over Microsoft Entra logs, for instance showing who still uses legacy authentication or where Conditional Access coverage is missing. They rely on P1 and on the logs being sent to Log Analytics.
- POP3
Post Office Protocol version 3 is a long-established way for email clients to download mail. Because it relies on legacy authentication and cannot handle multifactor authentication, organisations often block it with Conditional Access.
- Security defaults
A no-cost set of baseline protections applied across the whole tenant: everyone must register for MFA and legacy authentication is blocked. It cannot be targeted at particular groups.