Legacy Authentication guides
Old authentication protocols (basic auth POP/IMAP/SMTP, Exchange ActiveSync basic) that bypass modern security controls. See the glossary entry →
5 guides touch on legacy authentication.
- Conditional Access for Microsoft 365 admin accounts
Conditional Access policies for admin accounts: phishing-resistant MFA, managed devices, short sessions, no legacy auth, plus exclusions and rollout order.
- Entra ID Conditional Access design
Designing a Conditional Access baseline: the policies, the principles, the order to write them in, and the habits that keep the estate healthy.
- How to block legacy authentication with Conditional Access
How to block legacy authentication in Entra ID with Conditional Access: find who still uses it, build the block policy, run report-only, then enforce.
- Microsoft Entra ID Recommendations
The Entra ID Recommendations dashboard surfaces tenant-specific improvement actions based on Microsoft's analysis.
- Setting up Microsoft 365 from scratch
The setup order for a brand-new Microsoft 365 tenant — tenant, domain, identity, security baseline, then data and clients. Sequence matters more than speed.