Hi Kuronuma,
Let me provide a different perspective:
- don't disable Modern Authentication
- really put some time into learning the features of conditional access and how to set the sign in frequency. Great article here:
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
In Microsoft365, the modern authentication function allows you to access Outlook and Teams without authentication if you have signed in to a computer or account once. *I think the period is currently set to 90 days. I was considering turning off this modern authentication function, but at the time of implementation, the vendor told me that the function was not available and that I could not set the period to 0 days, so I gave up. questions Is it possible to turn off the modern authentication function? I recently found the following article. https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/enable-or-disable-modern-authentication-in-exchange-online
If the above is possible, what will happen to modern authentication for other Microsoft365 services such as Teams?
I am using IIj as my authentication infrastructure. Are there any possible effects?
Are there any effects or disadvantages to turning off the modern authentication function?
If you turn it off, what will be the scope? (Per account, per tenant, per function such as Outlook, etc.)
Hi Kuronuma,
Let me provide a different perspective:
Hi @Kuronuma ,
Welcome to the Microsoft Q&A platform!
For your concerns, I have the following to share with you.
It is possible to turn off modern authentication for Exchange Online by the article you provided above. And if you disable modern authentication for one service, it doesn’t automatically disable it for other services.
There are several disadvantages when you turn off modern authentication.
The scope of turning off modern authentication typically applies at the service level for the entire tenant. For example, if you disable modern authentication for Exchange Online via the Microsoft 365 admin center or PowerShell, it will affect all users in your tenant who use that service.
If the answer is helpful, please click "Accept Answer" and kindly upvote it.
Hello Kuronuma
My name is Muffuh Bertrand and i'm a Cloud Infrastructure Engineer and a Microsoft user like you.
Regarding your issue, please note Modern authentication in Microsoft 365 enables features like multi-factor authentication (MFA), certificate-based authentication, and OAuth-based authentication for applications like Outlook and Teams. It enhances security by requiring users to reauthenticate periodically or when accessing sensitive resources.
If you wish to disable modern authentication or adjust its settings, including reducing the token lifetime (the period after which users need to reauthenticate), you typically need administrative access to the Microsoft 365 Admin Center or Azure Active Directory (Azure AD) portal. Here’s a general approach to disabling modern authentication:
Keep in mind that turning off modern authentication affects the way users authenticate to Microsoft applications, and it is generally not recommended due to security vulnerabilities associated with basic authentication.
If you also want to adjust settings regarding the authentication period, you typically cannot set it to 0 days. The default authentication period is indeed often set to 90 days, and this is primarily determined by security policies within Microsoft 365. For more granular control over user sessions, you might look into configuring specific conditional access policies that meet your organization's needs.
Hope this helps. Please feel free to repost or submit your vote. Your vote will make your post superior content and help other users in the community facing the same issue.
in good faith,
Bertrand