Skip to content

At least one Conditional Access policy is configured to block legacy authentication for Exchange ActiveSync

Why This Matters

Legacy authentication protocols, such as Exchange ActiveSync, do not support modern security features like multifactor authentication (MFA). Attackers commonly exploit these protocols to bypass Conditional Access policies and gain unauthorized access to mailboxes. Without a policy blocking legacy authentication for Exchange ActiveSync, your organization remains vulnerable to credential theft and data breaches.

What Aether365 Checks

Aether365 verifies that at least one Conditional Access policy in your Microsoft 365 tenant is configured to block legacy authentication for Exchange ActiveSync. This check appears in your Aether365 dashboard under the microsoft-365 section.

Microsoft references

Was this page helpful?