ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    1. Topics
    2. Tags
    3. basic authentication
    Log in to post
    • All categories
    • JaredBuschJ

      Tenant disabling of Basic Auth cause OAUTH iPhone to break

      IT Discussion
      • microsoft o365 exchange online basic authentication • • JaredBusch
      8
      1
      Votes
      8
      Posts
      874
      Views

      1

      @JaredBusch said in Tenant disabling of Basic Auth cause OAUTH iPhone to break:

      Disabling of Basic Auth should have done nothing.

      If the security setting are changed on an account it makes sense to force users to reauthenticate. It might even be best practice.

      I think it works the same on other providers.

      But there should be some better mechanism regarding authentication in ios and android.

    • JaredBuschJ

      Solved Does the end of O365 Basic Authentication mean no more app passwords

      IT Discussion
      • o365 office 365 basic authentication app password imap4 imap • • JaredBusch
      7
      3
      Votes
      7
      Posts
      877
      Views

      1

      @scottalanmiller said in Does the end of O365 Basic Authentication mean no more app passwords:

      @Pete-S said in Does the end of O365 Basic Authentication mean no more app passwords:

      @JaredBusch said in Does the end of O365 Basic Authentication mean no more app passwords:

      Customer has a LoB application called Enfocus Switch.

      It has a mail retrieval function that connects via IMAP using an app password on a normal O365 email account with MFA enabled.

      It stopped retrieving email on the morning of Wednesday October 12th.

      Since Microsoft finally killed Basic Auth on Tuesday, I assume this is related, but I can find no information on this at all.

      The vendor do what they do, but I noticed that most applications that need this kind of functionality uses mail forwards from customers mailboxes to their own IMAP mailboxes.

      That can be a way to solve this when microsoft kills it. Redirect from customers O365 mailbox to another provider that supports IMAP with normal authentication. Have the LoB application use that inbox instead.

      We have customers doing that. Setting up MailCow to get past all the primary vendor security systems.

      That makes sense.

      I think you could probably run a bare mailserver with just dovecot as well. Since it only needs to handle incoming email from Microsoft and be an IMAP server, there's a lot things that becomes irrelevant - like spam detection, ip reputation etc.

    • 1 / 1