Advisory Note
Microsoft 365 Is Dropping Legacy Authentication: What SME Leaders Need to Do
Microsoft is removing older authentication methods from Microsoft 365, including SMS-based MFA. Here is what the change means in practice and where to focus first.

Microsoft is retiring legacy authentication protocols across Microsoft 365. For SME leaders with day-to-day IT responsibility, this is not an abstract platform update — it is a concrete prompt to audit how your organization currently handles identity and access.
What Is Actually Changing
Legacy authentication refers to older sign-in protocols that do not support modern conditional access controls. Microsoft has been phasing these out incrementally, and the current wave extends that deprecation to weaker multi-factor authentication methods, including SMS-based MFA.
SMS codes remain widely used because they are familiar and easy to set up, but they are also susceptible to SIM-swapping and interception attacks — a risk that is well-documented and increasingly exploited.
The direction of travel is toward stronger, phishing-resistant authentication methods: Microsoft Authenticator app-based approval, FIDO2 hardware keys, and certificate-based authentication are the recommended replacements. Organizations still relying on stored credentials or basic MFA configurations will find these options progressively restricted.
Key Dates & Enforcement Milestones October 2022 — Microsoft disabled Basic Authentication for most protocols in Exchange Online (with limited, temporary re-enablement options). 2023–2025 (ongoing) — Security Defaults and Conditional Access increasingly block legacy protocols and enforce MFA across tenants. 2024–2026 — Progressive tightening of authentication standards, including reduced reliance on SMS MFA and stronger enforcement of phishing-resistant methods. May 1, 2026 — Final retirement of legacy SharePoint authentication (IDCRL), with no option to re-enable.
These dates are part of Microsoft’s broader shift to Modern Authentication (OAuth 2.0 / OpenID Connect) as the baseline for all Microsoft 365 access.
What This Means for Your Organization
The practical exposure here is straightforward. If your staff authenticate using SMS codes — or if any service accounts, shared mailboxes, or third-party integrations rely on basic username-and-password flows — those pathways are becoming either unsupported or materially less secure as Microsoft tightens controls.
The priority actions are:
Audit your current MFA configuration Identify which users and accounts are using SMS-based MFA or have no MFA at all. Review service and shared accounts These are frequently overlooked and often have weaker controls than user accounts. Plan the migration to app-based or hardware-token MFA Microsoft Authenticator is the lowest-friction starting point for most SMEs. Check third-party integrations Any application connecting to Microsoft 365 using legacy protocols will need to be updated or replaced. The Right Frame for This Decision
This is not an emergency, but it is time-bounded work. Leaving legacy authentication in place is not a neutral choice — it is an accumulating identity risk surface that becomes significantly harder to remediate after an incident than before one.
The transition is well-supported by Microsoft’s own tooling, and for most SMEs the scope is manageable if approached methodically rather than reactively.
If you are unsure where your organization currently stands, an identity and access audit is the sensible first step.
Tags