← Back to blog

July 14, 2026

A Plain-English Guide to Legacy Authentication (and Why It's Still Enabled)

If you've inherited Microsoft 365 admin duties, or you're a newer IT admin, "legacy authentication" is one of those terms that shows up in every security checklist without much explanation. Here's what it actually means, in plain language.

What legacy authentication actually is

Legacy authentication refers to older ways of signing into Microsoft 365 that predate modern security features — specifically, protocols like IMAP, POP, SMTP AUTH, and older versions of Office that connect directly with just a username and password.

The important thing to understand: these protocols can't prompt for multi-factor authentication. They were built before MFA existed as a concept, and they have no mechanism to ask for a second factor. If legacy auth is allowed, a correct username and password is enough to get in — full stop, no matter how good your MFA policy looks everywhere else.

Why it's a real risk, not a theoretical one

This matters because legacy auth is a favorite target for automated credential-stuffing attacks — bots that try large lists of leaked username/password combinations against a login endpoint, hoping for a match. A modern sign-in flow would stop that cold with an MFA prompt. A legacy auth endpoint just checks the password and lets the request through.

In other words: even a tenant with a strong Conditional Access policy requiring MFA can have a wide-open back door if legacy authentication is still enabled somewhere.

Why it's still on in most tenants

If it's this risky, why isn't it just off everywhere by default? A few real reasons:

  • Nobody explicitly turned it off. Many tenants are set up quickly, and disabling legacy auth isn't always part of the initial checklist — it's the kind of thing that gets addressed "later," and later doesn't always come.
  • Something old still depends on it. An office scanner that scans-to-email over SMTP, an old line-of-business app, or someone still running a very old version of Outlook. Turning legacy auth off can break that thing, and nobody wants to be the one who broke the scanner.
  • It's invisible until you look for it. Unlike a missing MFA prompt, which a user notices immediately, legacy auth being open doesn't show up in anyone's day-to-day experience. It's a silent gap.

Microsoft has been actively pushing tenants away from Basic Authentication (the umbrella term Microsoft uses for these legacy protocols) for exactly this reason, with deprecation timelines that have been tightening for the past several years — which is part of why this is worth checking now rather than treating it as a someday item.

How to check without breaking anything

The cautious approach: don't disable legacy auth blindly. First, check the tenant's actual sign-in logs for legacy authentication attempts over a recent window — if something is still using it, you'll see it there before you turn it off and find out the hard way. If nothing shows up, blocking it (via a Conditional Access policy, or as part of Security Defaults if the tenant doesn't have Conditional Access) is close to risk-free. If something is still using it, that's your cue to migrate that one thing first, then close the door.

ScopedIQ's scan checks for legacy authentication activity as part of every report, specifically so this doesn't stay an invisible gap between reviews.