IMAP, POP3, SMTP, and MAPI cannot enforce MFA. While those endpoints remain active, they are an open back door into the directory.

Preface

Legacy authentication protocols are inherently insecure and do not support modern interactive authentication. Strict modern policies elsewhere do not help if legacy endpoints stay enabled.

Problem

Attackers use legacy endpoints for password spray and brute force because no interactive MFA challenge is presented. Successful legacy auth can lead to mailbox access, persistence, and lateral movement, often with weak monitoring coverage.

Solution

Align with CIS Microsoft 365 Foundations Benchmark and NIST SP 800-171:

  1. Block legacy clients in Conditional Access: Target all cloud apps and block "Other clients".
  2. Monitor legacy sign-ins: Audit Entra sign-in logs for non-modern protocol success.
  3. Move clients to modern authentication: OAuth 2.0 for Outlook Mobile, OWA, and related clients.

PowerShell: Review Authentication Method Policies

Connect-MgGraph -Scopes "Policy.Read.All"
Get-MgPolicyAuthenticationMethodPolicy | Select-Object -ExpandProperty AuthenticationMethodConfigurations