---
title: Legacy Authentication Walks Straight Past Your MFA | Datatechs Consulting
description: A tenant can have perfect MFA coverage and still fall to a password spray. Here is how to prove legacy auth is still in use and block it without breaking anyone.
image: https://www.datatechs.co.uk/hubfs/datatechs-blog-legacy-auth.png
---

[Skip to content](https://www.datatechs.co.uk/blog/legacy-authentication-walks-straight-past-your-mfa#main-content)

[![Datatechs home](https://www.datatechs.co.uk/hs-fs/hubfs/Datatech%20Consulting%20Limited.png?width=2130&height=676&name=Datatech%20Consulting%20Limited.png "Datatechs home")](https://www.datatechs.co.uk) 

[![](https://www.datatechs.co.uk/hubfs/Datatech%20Consulting%20Limited%20-%20INVERT.png)](https://www.datatechs.co.uk/)

[Home](https://www.datatechs.co.uk/)

[Services](https://www.datatechs.co.uk/services)

[M365 Security Audit](https://www.datatechs.co.uk/audit) [Professional Services and Consultancy](https://www.datatechs.co.uk/services/professional-services) [IT Helpdesk and Support](https://www.datatechs.co.uk/services/it-helpdesk) [Managed Compliance](https://www.datatechs.co.uk/services/managed-compliance) [Power Platform](https://www.datatechs.co.uk/services/power-platform) [Azure and Cloud Infrastructure](https://www.datatechs.co.uk/services/azure-cloud-infrastructure)

[View all services →](https://www.datatechs.co.uk/services)

[Security Audit](https://www.datatechs.co.uk/audit)

[CIS M365 Benchmark](https://www.datatechs.co.uk/audit/cis-m365) [CIS Intune Benchmark](https://www.datatechs.co.uk/audit/cis-intune) [Cyber Essentials](https://www.datatechs.co.uk/audit/cyber-essentials)

[View the full audit →](https://www.datatechs.co.uk/audit)

[MSP Partners](https://www.datatechs.co.uk/msp-partners)

Resources

Free Downloads

[M365 Security Essentials Checklist](https://www.datatechs.co.uk/resources/m365-security-essentials) [Intune Security Essentials Checklist](https://www.datatechs.co.uk/resources/intune-security-essentials)

[About](https://www.datatechs.co.uk/about) [Blog](https://www.datatechs.co.uk/blog) 

[Contact Us](https://www.datatechs.co.uk/contact)

[Home](https://www.datatechs.co.uk/) [Services](https://www.datatechs.co.uk/services)

[M365 Security Audit](https://www.datatechs.co.uk/audit) [Professional Services and Consultancy](https://www.datatechs.co.uk/services/professional-services) [IT Helpdesk and Support](https://www.datatechs.co.uk/services/it-helpdesk) [Managed Compliance](https://www.datatechs.co.uk/services/managed-compliance) [Power Platform](https://www.datatechs.co.uk/services/power-platform) [Azure and Cloud Infrastructure](https://www.datatechs.co.uk/services/azure-cloud-infrastructure) 

[Security Audit](https://www.datatechs.co.uk/audit)

[CIS M365 Benchmark](https://www.datatechs.co.uk/audit/cis-m365) [CIS Intune Benchmark](https://www.datatechs.co.uk/audit/cis-intune) [Cyber Essentials](https://www.datatechs.co.uk/audit/cyber-essentials) 

[MSP Partners](https://www.datatechs.co.uk/msp-partners) Resources

[M365 Security Essentials Checklist](https://www.datatechs.co.uk/resources/m365-security-essentials) [Intune Security Essentials Checklist](https://www.datatechs.co.uk/resources/intune-security-essentials) 

[About](https://www.datatechs.co.uk/about) [Blog](https://www.datatechs.co.uk/blog) [Contact Us](https://www.datatechs.co.uk/contact)

[← Back to blog](https://www.datatechs.co.uk/blog)

Microsoft 365 Security · Identity and Access

# Legacy Authentication Walks Straight Past Your MFA

Marcus Harris · 21 August 2026

In this article

A client asks whether they are protected. You check the MFA registration report, see ninety-something per cent, and say yes. Three weeks later an account is compromised with nothing more sophisticated than a correct password.

Legacy authentication is why. It is the single widest gap I find, it is invisible in every report a client is likely to look at, and it makes the MFA number meaningless.

---

## The mechanism

Modern authentication hands the sign-in to Entra ID, which evaluates Conditional Access, which can require MFA. That is the path everyone pictures.

Legacy protocols predate all of that. IMAP, POP3, SMTP AUTH, MAPI over HTTP on old clients, ActiveSync on older devices. They present a username and password directly and there is no interactive step in which a second factor could be requested. Conditional Access is not consulted at all, because there is nothing to consult it with.

![Diagram showing modern authentication passing through Conditional Access and MFA to reach the mailbox, while legacy authentication with IMAP, POP3 and SMTP basic auth bypasses both entirely](https://www.datatechs.co.uk/hubfs/datatechs-diagram-legacy-auth.png)

Two routes to the same mailbox. Only one of them is governed by anything you configured.

So the attacker does not defeat MFA. They avoid the code path where MFA lives. This is why password spray campaigns target these endpoints specifically: they are the only place where a correct password is still sufficient.

---

## Prove it before you block it

Do not go straight to a block. You need to know who is actually using it, or you will take down a service account at 2am and find out from the client.

The fastest read is the sign-in logs filtered on client app.

**Where to find it**entra.microsoft.com › Identity › Monitoring & health › Sign-in logs › Add filters › Client app

Select everything under Legacy Authentication Clients and set the window to 30 days.

Better, because you can run it across tenants and keep the output, is KQL against the sign-in logs if the tenant streams them to a Log Analytics workspace:

```
SigninLogs
| where TimeGenerated > ago(30d)
| where ClientAppUsed in ("IMAP4","POP3","SMTP","Exchange ActiveSync",
    "Other clients","Exchange Web Services","Authenticated SMTP",
    "MAPI Over HTTP","Offline Address Book")
| summarize Attempts = count(),
            Success  = countif(ResultType == 0),
            Apps     = make_set(ClientAppUsed),
            IPs      = dcount(IPAddress),
            LastSeen = max(TimeGenerated)
        by UserPrincipalName
| order by Success desc
```

Read that output carefully. High attempts with zero successes on an account you do not recognise is a spray in progress, not a legacy client. High successes on a shared mailbox or a scanner account is a real dependency you have to migrate before you block.

Without Log Analytics, Graph gets you the same picture:

```
Connect-MgGraph -Scopes "AuditLog.Read.All","Directory.Read.All"

$since = (Get-Date).AddDays(-30).ToString("yyyy-MM-ddTHH:mm:ssZ")
Get-MgAuditLogSignIn -Filter "createdDateTime ge $since" -All |
  Where-Object { $_.ClientAppUsed -notin @("Browser","Mobile Apps and Desktop clients") } |
  Group-Object UserPrincipalName, ClientAppUsed |
  Select-Object Count, Name |
  Sort-Object Count -Descending
```

---

## What you will find

Across the tenants I have looked at, the dependencies are remarkably consistent.

**Multifunction printers and scanners** sending scan-to-email over SMTP AUTH. Almost always. Fix is a connector or a dedicated relay, not an exception.

**Line of business applications** that send notifications. Older accounting and practice management software is the usual culprit.

**An old phone or two** using native mail with ActiveSync.

**A former employee's account** still syncing IMAP to a personal client. This one is worth a separate conversation with the client.

What you rarely find is a person who genuinely needs it. Almost every legacy dependency is a device or an application, which means it can be migrated rather than negotiated.

---

## Block it properly

Two layers, and you want both.

**Authentication policies** switch basic auth off at the protocol level in Exchange Online. This is the real block:

```
New-AuthenticationPolicy -Name "Block Basic Auth"

Set-AuthenticationPolicy -Identity "Block Basic Auth" `
  -AllowBasicAuthImap:$false `
  -AllowBasicAuthPop:$false `
  -AllowBasicAuthSmtp:$false `
  -AllowBasicAuthActiveSync:$false `
  -AllowBasicAuthWebServices:$false `
  -AllowBasicAuthMapi:$false `
  -AllowBasicAuthOfflineAddressBook:$false

Set-OrganizationConfig -DefaultAuthenticationPolicy "Block Basic Auth"
```

Note the last line. Setting it as the organisation default applies it to accounts created afterwards as well, which is the bit that stops the gap reopening in six months.

**A Conditional Access policy** gives you the audit trail and catches anything the protocol block misses.

**Where to find it**entra.microsoft.com › Protection › Conditional Access › Policies › New policy

Target all users and all cloud apps. Under Conditions, set Client apps to Exchange ActiveSync clients and Other clients. Grant: Block access.

Run it in report-only for a week first. Exclude your break glass accounts, as you would with any policy.

---

## The order that avoids the 2am call

1. Run the query. Get the real list of users and applications.
2. Migrate the printers to a connector or SMTP relay with modern auth.
3. Update or replace the line of business applications that cannot do modern auth. Some will need a vendor conversation, so start it early.
4. Deploy the Conditional Access policy in report-only. Watch for a week.
5. Enable the CA policy.
6. Apply the authentication policy and set it as the organisation default.
7. Re-run the query in 30 days and confirm it is empty.

Step seven matters more than it looks. Legacy auth has a habit of coming back when somebody adds a device or a new mailbox is provisioned outside the default policy.

---

## The conversation with the client

You do not need to explain protocols. The sentence that lands is this: your MFA works on the front door, and there is a side door with only a password on it. Here is who has used the side door in the last month.

Then show them the query output. It is considerably more persuasive than a percentage.

If you run this across your fleet and find a tenant with zero legacy sign-ins, that tenant is genuinely in good shape. In my experience it is roughly one in five.

Topics: [Microsoft 365 Security](https://www.datatechs.co.uk/blog/tag/microsoft-365-security) [Identity and Access](https://www.datatechs.co.uk/blog/tag/identity-and-access)

Share this article

[LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https://www.datatechs.co.uk/blog/legacy-authentication-walks-straight-past-your-mfa) [X (Twitter)](https://x.com/intent/post?url=https://www.datatechs.co.uk/blog/legacy-authentication-walks-straight-past-your-mfa&text=)

M

Marcus Harris

## Keep reading

[![](https://www.datatechs.co.uk/hs-fs/hubfs/datatechs-blog-ca-baseline.png?width=640&height=360&name=datatechs-blog-ca-baseline.png)](https://www.datatechs.co.uk/blog/deploying-a-conditional-access-baseline-to-any-tenant)

Microsoft 365 Security

### [Deploying a Conditional Access Baseline to Any Tenant](https://www.datatechs.co.uk/blog/deploying-a-conditional-access-baseline-to-any-tenant)

11 September 2026 

[Read more →](https://www.datatechs.co.uk/blog/deploying-a-conditional-access-baseline-to-any-tenant)

[![](https://www.datatechs.co.uk/hs-fs/hubfs/datatechs-blog-tenant-sprawl.png?width=640&height=360&name=datatechs-blog-tenant-sprawl.png)](https://www.datatechs.co.uk/blog/six-global-admins-and-audit-logging-off-inheriting-a-three-year-old-tenant)

Microsoft 365 Security

### [Six Global Admins and Audit Logging Off: Inheriting a Three-Year-Old Tenant](https://www.datatechs.co.uk/blog/six-global-admins-and-audit-logging-off-inheriting-a-three-year-old-tenant)

28 August 2026 

[Read more →](https://www.datatechs.co.uk/blog/six-global-admins-and-audit-logging-off-inheriting-a-three-year-old-tenant)

[![](https://www.datatechs.co.uk/hs-fs/hubfs/datatechs-blog-gdap.png?width=640&height=360&name=datatechs-blog-gdap.png)](https://www.datatechs.co.uk/blog/auditing-delegated-admin-access-across-client-tenants)

Identity and Access

### [Auditing Delegated Admin Access Across Client Tenants](https://www.datatechs.co.uk/blog/auditing-delegated-admin-access-across-client-tenants)

4 September 2026 

[Read more →](https://www.datatechs.co.uk/blog/auditing-delegated-admin-access-across-client-tenants)

GET IN TOUCH

## Looking for help with your Microsoft 365 environment?

Our team works with small and mid-sized organisations to secure, audit, and manage their Microsoft 365 configuration. No jargon, no unnecessary overhead.

[Book a discovery call](https://www.datatechs.co.uk/book-a-call)[View our services →](https://www.datatechs.co.uk/services)

[![Datatechs](https://www.datatechs.co.uk/hs-fs/hubfs/Datatech%20Consulting%20Limited%20-%20INVERT.png?height=56&name=Datatech%20Consulting%20Limited%20-%20INVERT.png)](https://www.datatechs.co.uk/)

Microsoft 365 security and compliance for organisations and MSPs.

Services

- [M365 Security Audit](https://www.datatechs.co.uk/audit)
- [Professional Services](https://www.datatechs.co.uk/services/professional-services)
- [IT Helpdesk and Support](https://www.datatechs.co.uk/services/it-helpdesk)
- [Managed Compliance](https://www.datatechs.co.uk/services/managed-compliance)
- [Power Platform](https://www.datatechs.co.uk/services/power-platform)
- [Azure and Cloud Infrastructure](https://www.datatechs.co.uk/services/azure-cloud-infrastructure)

Resources

- [Blog](https://www.datatechs.co.uk/blog)
- [M365 Security Checklist](https://www.datatechs.co.uk/resources/m365-security-essentials)

Company

- [About](https://www.datatechs.co.uk/about)
- [MSP Partners](https://www.datatechs.co.uk/msp-partners)
- [Contact](https://www.datatechs.co.uk/contact)
- [Book a call](https://www.datatechs.co.uk/book-a-call)

Contact

- [hello@datatechs.co.uk](mailto:hello@datatechs.co.uk)
- United Kingdom

© 2026 Datatechs Consulting Limited. Registered in England and Wales, company number 16868376. Registered office: Belmont Suite, Paragon Business Park, Chorley New Road, Horwich, Bolton, BL6 6HG.

[Privacy Policy](https://www.datatechs.co.uk/privacy-policy) [Terms](https://www.datatechs.co.uk/terms)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Marcus Harris",
    "url" : "https://www.datatechs.co.uk/blog/author/marcus-harris"
  },
  "dateModified" : "2026-09-18T08:35:36.690Z",
  "datePublished" : "2026-08-21T08:00:00.000Z",
  "headline" : "Legacy Authentication Walks Straight Past Your MFA",
  "image" : [ "https://www.datatechs.co.uk/hubfs/datatechs-blog-legacy-auth.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.datatechs.co.uk/blog/legacy-authentication-walks-straight-past-your-mfa",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.datatechs.co.uk/hubfs/Datatech%20Consulting%20Limited.png"
    }
  }
}
```