Microsoft Exchange 365, IMAP incompatible with MFA (Multi-Factor Authentication)

imap365

 

This little tutorial in the form of a testimony after days of fruitless research.

I hope that this page will be useful to others.

I have users on Exchange OnLine 365 who want to use Thunderbird. And so they need IMAP access.

For the past few months, Microsoft has been making MFA identification recommended by going so far as to put this in the default configuration.

 

So if you enable MFA, your users will not be able to use IMAP, do not look, it is not compatible.

To do so, it is necessary either to use conditional access which requires a licence: an Azure Active Directory P1 or P2 licence: https://docs.microsoft.com/fr-fr/azure/active-directory/conditional-access/overview#license-requirements

Either disable the default security settings and sharpen the MFA individually (which is not recommended by Microsoft). I think that at least the administrative counties must be in MFA, it is really a minimum.

 

Here is the procedure:

Disable the default security settings:

https://docs.microsoft.com/fr-fr/azure/active-directory/fundamentals/concept-fundamentals-security-defaults 

To disable the default security settings in your directory:

  1. Log in to  Azure Portal  as security administrator, conditional access administrator or general administrator.
  2. Go to  Azure Active Directory > Properties.
  3. Select Manage Default Security Settings.
  4. Define Enable Default Security Settings on No using the toggle button.
  5. Select Save.

Enable MFA for users who do not use MFA (minimum Adminsitrators)

https://account.activedirectory.windowsazure.com/UserManagement/MultifactorVerification.aspx?BrandContextID=O365

 

Other information:

Note: : With Outlook, no worries with the MFA

If you set the box in Outlook automatically using autodiscover, you can have the MFA enabled because Outlook uses modern authentication and it supports the MFA. 

https://docs.microsoft.com/fr-fr/office365/enterprise/hybrid-modern-auth-overview 

https://docs.microsoft.com/fr-fr/microsoft-365/admin/security-and-compliance/set-up-multi-factor-authentication?view=o365-worldwide 

 

Why is Microsoft pushing for MFA?

Read this article:

IMAP 770x439 c

https://www.cybercureme.com/hackers-bypass-multi-factor-authentication-to-hack-office-365-g-suite-cloud-accounts-using-imap-protocol/

https://www.zdnet.com/article/microsoft-details-the-causes-of-its-recent-multi-factor-authentication-meltdown/

 

Leave a Reply