Depreciation of basic authentication in Exchange On Prem ?

Steph 1 Reputation point
2022-08-31T08:44:17.917+00:00

Hello,

I was wondering if it was possible to secure Exchange On Premise in the same way that Microsoft does by disabling basic authentication in Exchange Online?

What are the alternatives to disable basic authentication and use a more secure authentication to read mailboxes in IMAP for example?

One of my customers uses IMAP to read Exchange mailboxes by his software that he develops internally. We were able to read the Online mailboxes via OAuth 2.0 and in IMAP.

I checked if we can use OAuth 2.0 on a local exchange, but if I believe this article it is a protocol specific to Exchange Online:

https://learn.microsoft.com/en-us/exchange/client-developer/exchange-web-services/authentication-and-ews-in-exchange?redirectedfrom=MSDN

My research led me to this other article :

https://learn.microsoft.com/en-us/microsoft-365/enterprise/hybrid-modern-auth-overview?view=o365-worldwide

I have the impression that it's quite tedious and I'm not sure that it's really equivalent, I don't see any Azure application, token like on EXO etc...

If we have to go through Azure no matter what, it means that we need Azure AD licenses?

Thank you for your help and clarification.

Exchange | Exchange Server | Management
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2022-08-31T11:23:21.193+00:00
    0 comments No comments

  2. Joyce Shen - MSFT 16,701 Reputation points
    2022-09-01T05:25:39.343+00:00

    Hi @Steph

    Yes, POP and IMAP do not support modern authentication with on-prem Exchange. The official document introduces this as below:
    Hybrid modern authentication overview and prerequisites for using it with on-premises Skype for Business and Exchange servers

    Clients and/or protocols that are not listed (for example, POP3) do not support modern authentication with on-premises Exchange and continue to use legacy authentication mechanisms even after modern authentication is enabled in the environment.


    If an Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.