ID-02: Block Legacy Authentication
Frequently asked questions about implementing and managing the ID-02 security control in Microsoft 365 and Entra ID.
QWhat is ID-02 (Block Legacy Authentication)?▼
ID-02 is a security control that legacy protocols like imap and pop3 cannot enforce mfa. attackers specifically target these protocols to bypass your mfa policies. blocking them closes a major attack vector. It requires that a conditional access policy blocks legacy authentication protocols (imap, pop3, smtp, older office clients) and no exceptions for legacy protocols except documented service accounts.
QWhy is Block Legacy Authentication important for Microsoft 365 security?▼
Legacy protocols like IMAP and POP3 cannot enforce MFA. Attackers specifically target these protocols to bypass your MFA policies. Blocking them closes a major attack vector.
QHow do I implement ID-02 in my tenant?▼
TrueConfig provides one-click remediation for ID-02. Creates a Conditional Access policy blocking legacy authentication for all users
QWhat license do I need for ID-02?▼
This control can be implemented with any Microsoft 365 subscription, including free Azure AD.
QWhich security baseline includes ID-02?▼
ID-02 is included in the TrueConfig Recommended Secure baseline (Level 1). This is the foundation level suitable for most organizations.
5
Questions
1
Related Controls
—
Categorized
Related Resources
Still have questions?
Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.
Start Free Trial