Back to glossary

Legacy authentication

1 min read

Legacy authentication is any sign in protocol that sends a username and password directly to the service without supporting modern authentication, so it cannot prompt for a second factor and is not evaluated by conditional access. In Microsoft 365 estates it is the path that quietly bypasses the controls the organisation believes it has deployed.

July 29, 2026
Compartir:

The protocols involved are the older mail and client access ones: POP, IMAP, SMTP submission, and the client protocols that predate token based sign in. Each accepts a password and returns access. Because no interactive prompt is possible, multi-factor authentication cannot be enforced on that path, and policies that grant or deny access based on device state and location never evaluate it.

That combination is why it is the preferred target for password spraying. A single common password tried against every mailbox produces no prompts, no user notification, and in many estates no alert, because the sign in is recorded as a protocol event rather than an interactive logon. One success is a readable mailbox, and a readable mailbox is where invoice fraud starts.

Microsoft has retired basic authentication for most of these protocols in Exchange Online, which has closed the default case, but the finding has not disappeared: submission for applications and devices can still be enabled per mailbox, hybrid and on premises deployments keep their own paths, and other platforms have equivalents. What we check is not whether the tenant policy says it is blocked but what the sign in logs show actually authenticating, and that is part of the Microsoft 365 hardening work where these protocols are found and closed.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.