News: 1662362827

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft: The deadline to get off Basic Auth is approaching

(2022/09/05)


Don't say you weren't warned.

Three years ago, Microsoft [1]announced that it was going to start weaning its software offerings off Basic Authentication for more modern and secure user authentication methods. Since then, the software giant has moved a number of customer-facing applications, including Outlook Desktop and Outlook Mobile App, to Modern Auth via security updates.

Now Microsoft is telling users that on October 1 it is going to start disabling Basic Auth for protocols in Exchange Online that have yet to be turned off, including MAPI, RPC, Offline Address Book, Exchange Web Services, POP, IMAP, Exchange ActiveSync, and Remote PowerShell.

[2]

Millions of users already have moved away from Basic Auth over the past three years and Microsoft has disabled it in millions of tenants. However, many are still using it, despite additional reminders in [3]September 2021 and again in [4]May .

[5]

[6]

Redmond is giving those who have yet to move off Basic Auth a three-month reprieve of sorts. In a [7]blog post this week, Microsoft said it is updating its plan for customers who don't know about, or are not ready for, the change.

After Basic Auth is turned off October 1, customers will be able to use a self-service diagnostic to re-enable it for whatever protocols they need. This can only be done once per protocol, with the re-enablement starting once the diagnostic is run. That said, it will only last through the end of December. During the first week of January 2023, Basic Auth will be permanently turned off for all protocols.

[8]

"We recognize that unfortunately there are still many tenants unprepared for this change," the Exchange Team wrote. "Despite multiple blog posts, Message Center posts, interruptions of service, and coverage via tweets, videos, conference presentations and more, some customers are still unaware this change is coming. There are also many customers aware of the deadline who simply haven't done the necessary work to avoid an outage."

Microsoft updated its plan with the extra three months re-enablement because "we understand that email is a mission-critical service for many of our customers and turning off basic auth for many of them could potentially be very impactful," the team wrote.

To keep Basic Auth for any protocols, users will be able to run the diagnostics during September and Microsoft will not disable it for those specific protocols, though it will be ended for the other protocols. However, customers will be able to re-enable those protocols after October 1 until the end of the year.

[9]

Microsoft will announce the move again in the Windows Message Center seven days before the disabling begins and tenants will be alerted through the Service Health Dashboard notifications when Basic Auth is turned off.

[10]Start using Modern Auth now for Exchange Online

[11]Microsoft delays disabling Basic Authentication for several Exchange Online protocols 'until further notice'

[12]Two-factor auth totally locks down Office 365? You may want to check all your services...

Basic Auth essentially is a legacy authentication method that involves sending credentials in plain text to systems and often which was offered by default. It doesn't naturally support multi-factor authentication (MFA), making it difficult for organizations using Basic Auth to use the modern security tool.

Shifting to Modern Auth is important as threat groups and cybercriminals use increasingly sophisticated means to steal credentials as companies continue to migrate to the cloud, embrace remote work models, and expand third-party access to corporate resources. According to a [13]report by cybersecurity vendor CyberArk last year, 97 percent of senior security executives said attackers are ramping up efforts to steal one or more types of credentials.

Microsoft defines modern authentication as an umbrella term for methods between a client endpoint and a server or security measures that include such access policies as MFA, smart cards, Open Authorization, mobile access management, and certificate-based authentication.

In June the US Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory

[14]PDF

that federal executive civilian agencies like the Federal Communications Commission, Federal Trade Commission and departments as Homeland Security and Justice are required to [15]move off Basic Auth . At the same time, the agency also urged private organizations to do the same.

John Bambenek, principal threat hunter at cybersecurity company Netenrich, told The Register that making the switch to Modern Auth is a trivial matter for administrators but more challenging for apps and users that are still using legacy protocols, and that much of the focus will need to be.

"With encryption advances, password theft is becoming more difficult," Bambenek said. "Legacy methods don't have some of the same protections. This is why so many attacks are using legacy methods. At this point, it's a basic best practice, but changing now will also prevent disruption in October when Microsoft disables legacy protocols."

Many attacks begin with stolen credentials, he said, adding that moving to more modern authentications methods "makes it incrementally more difficult for attackers." ®

Get our [16]Tech Resources



[1] https://techcommunity.microsoft.com/t5/exchange-team-blog/improving-security-together/ba-p/805892

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YxXIvM39oenbQ5QKIjtjvAAAAAk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://techcommunity.microsoft.com/t5/exchange-team-blog/basic-authentication-and-exchange-online-september-2021-update/ba-p/2772210

[4] https://techcommunity.microsoft.com/t5/exchange-team-blog/basic-authentication-deprecation-in-exchange-online-may-2022/ba-p/3301866

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YxXIvM39oenbQ5QKIjtjvAAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YxXIvM39oenbQ5QKIjtjvAAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://techcommunity.microsoft.com/t5/exchange-team-blog/basic-authentication-deprecation-in-exchange-online-september/ba-p/3609437

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YxXIvM39oenbQ5QKIjtjvAAAAAk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/oses&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YxXIvM39oenbQ5QKIjtjvAAAAAk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2022/06/29/cisa-microsoft-modern-auth/

[11] https://www.theregister.com/2021/02/05/exchange_online_basic_authentication/

[12] https://www.theregister.com/2018/07/13/2fa_o365_bypass_attacks/

[13] https://investors.cyberark.com/press-releases/press-release-details/2021/New-CISO-View-Survey-on-Zero-Trust-Highlights-Credential-Theft-Trends-for-New-Types-of-Identities/default.aspx

[14] https://www.cisa.gov/sites/default/files/publications/switch-to-modern-authentication-in-exchange-online-062822-508.pdf

[15] https://www.theregister.com/2022/06/29/cisa-microsoft-modern-auth/

[16] https://whitepapers.theregister.com/



Psy-Q

I wish they wouldn't call it basic auth when it has nothing to do with HTTP basic auth.

Anonymous Coward

Thanks, I couldn't make sense of the article.

Even I...

Joe W

... don't fault MS. This time.

Seriously. While I did not see the blog entries and all the other suff, my Outlook mail account (from when I had a windows phone, which I still miss) did complain when installing a new machine (and cell phone app). The (non-MS) mail readers did offer me a quick new setup, and it just... works. Good job everyone (also the programmers for the email software), have one!

A Non e-mouse

We've been forcing users onto MFA. As we do, we're finding the number of hacked accounts dropping. There are some who complain that it's too hard, too intrusive, etc, but the benefits are far outwaying the complainers.

So does this mean Everyone now has to use 2FA?

Anonymous Coward

Asking for a lazy friend - so does this mean everyone on M365 now has to use 2FA? Either register a mobile phone number or use an app?

Or is this just "stop using IMAP"?

I know of a few offices where only Outlook on the desktop is used. Do they all need to add mobile phone numbers or an Auth App even if it is only ever Outlook that logs in from the desktop?

Some clients are easy to bump into more secure MFA - but some are just a pain to deal with....

<Overfiend> Thunder-: when you get { MessagesLikeThisFromYourHardDrive }
<Overfiend> Thunder-: it either means { TheDriverIsScrewy }
<Overfiend> or
<Overfiend> { YourDriveIsFlakingOut BackUpYourDataBeforeIt'sTooLate
PrayToGod }