User agent in Azure AD Sign-in logs

Natália Lima 86 Reputation points
2021-09-09T20:05:07.607+00:00

I have looked at user logs and found many login attempts with the BAV2ROPC user agent. What is this agent?
I didn't find any Microsoft documentation about this user agent.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,389 questions
0 comments No comments
{count} votes

Accepted answer
  1. VipulSparsh-MSFT 16,231 Reputation points Microsoft Employee
    2021-09-10T05:06:25.397+00:00

    @Natália Lima Thanks for reaching out.

    This user agent BAV2ROPC signifies the client apps used in legacy protocols like POP3, IMAP, SMTP legacy and are capable of understanding storing password if they user logged into them at some period.

    If you still allow legacy protocol in your organization than you should be seeing a lot of this.
    But if you have blocked all the legacy protocols in Office 365 exchange and still see some user agent like this, you need to investigate further.

    -----------------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Sankar, Prabhudeva 0 Reputation points
    2023-05-11T08:50:36.6366667+00:00

    Hi Team,

    please share the document or link to block legacy protocols in Office 365 exchange, we are facing the same issue.