Check for existing legacy authentication
Do not enable the blocking policy without first checking what may be affected.
- Sign in to the Microsoft Entra admin centre.
- Select Entra ID.
- Go to Monitoring & health.
- Select Sign-in logs.
- Select Add filters.
- Select Client app.
- Select the legacy authentication methods displayed, which may include: Exchange ActiveSync, Exchange Web Services, IMAP, POP, SMTP, MAPI over HTTP and Other clients.
- Select Apply.
- Review both User sign-ins (interactive) and User sign-ins (non-interactive).
- Open each relevant record and identify the user account, the application or device, the legacy protocol being used, the source IP address and whether the attempt succeeded or failed.
Review an appropriate period—preferably at least 7 to 30 days—to account for applications that only run weekly or monthly.
| Legacy client apps to look for |
|---|
| Exchange ActiveSync |
| Exchange Web Services |
| IMAP |
| POP |
| SMTP |
| MAPI over HTTP |
| Other clients |
