Who is still using POP3, IMAP and SMTP in your tenant

02 Aug 2026

Who is still using POP3, IMAP and SMTP in your tenant

Microsoft turned basic authentication off in Exchange Online, so the question feels settled. It isn't. What was disabled is one credential format; the protocols themselves — POP3, IMAP4, SMTP client submission, Exchange ActiveSync, EWS — are still enabled per mailbox in most tenants, still reachable, and still the first thing an attacker tries because they fail predictably and quietly. The honest version of the question is not "do we allow basic auth" but which mailboxes still have legacy protocols switched on, and who is actually connecting through them right now. That answer is in your sign-in logs, and almost nobody reads it.

5
legacy protocols still enabled by default
0
MFA prompts a protocol session ever shows
30d
sign-in log retention on P1 — your whole evidence window
1
field that names them: clientAppUsed

Why a protocol session is a different risk from a browser session

An interactive sign-in goes through the full Entra ID pipeline: Conditional Access evaluates it, MFA can be demanded, sign-in risk can block it, the session can be revoked. A mail client speaking IMAP over OAuth gets a token once and then holds a long-lived session that no policy re-evaluates in practice. A client speaking anything older gets no interactive step at all. Both land in the non-interactive sign-in log — a separate tab most admins have never opened — and neither generates a prompt anyone would notice.

TWO PATHS TO THE SAME MAILBOX Browser / Outlook interactive sign-in Conditional Access device, risk, location MFA challenge second factor required Mailbox mail, contacts, rules POP / IMAP / SMTP protocol session credential check only — no prompt, no re-evaluation
The pattern
Password spraying is not aimed at your login page. It is aimed at the endpoint that answers "wrong password" fastest and tells nobody. A protocol session that succeeds looks exactly like a scanner that has been polling for three years — which is why the real one hides inside the noise of the fake ones.

What each protocol is still doing in a real tenant

Protocol Who genuinely still needs it The replacement
POP3 Nobody. One archived mailbox someone reads on a 2014 phone. Disable tenant-wide, no exceptions list.
IMAP4 Migration tools, ticketing systems, shared-inbox parsers. Graph API app permission, scoped to one mailbox.
SMTP client submission Printers, scanners, line-of-business apps sending "from" a person. OAuth submission, or a connector restricted by IP.
Exchange ActiveSync Native mail apps on unmanaged phones. Outlook mobile + app protection policies.
EWS Backup vendors and signature tools that never modernised. Graph, or a hard vendor conversation.

Every row that survives the audit ends up on a service account, and service accounts are the population least likely to have a second factor registered — the same overlap described in dormant accounts that still hold licences. A shared password, a protocol that never challenges it, and a mailbox full of invoices is the whole business email compromise playbook in three lines.

Naming them, in four passes

1
Read the non-interactive log, not the interactive one.

Filter signIns on clientAppUsed for IMAP4, POP3, Authenticated SMTP, Exchange ActiveSync and the catch-all Other clients. Group by user principal name and by source IP. Two lists come out: the accounts that succeed (your real dependency inventory) and the accounts that only ever fail (someone else's dictionary).

2
Compare it against what is switched on.

The per-mailbox flags (PopEnabled, ImapEnabled, SmtpClientAuthenticationDisabled) are the attack surface; the log is the usage. The interesting set is the difference: mailboxes with a protocol enabled and zero legitimate sessions in 30 days. Those close today, with no change ticket and no user impact.

3
Block legacy clients in Conditional Access — report-only first.

A policy targeting the legacy-client condition, run in report-only mode for two weeks, produces the exception list for you instead of producing an outage. Whatever appears in that report is either a system nobody documented or a device nobody owns. Both are findings.

4
Give the survivors an identity of their own.

The printer that must send mail gets its own mailbox, its own credential, an IP-restricted connector, and no licence it doesn't need. Never a shared human account. Then re-run pass 1 monthly — protocols get re-enabled by migrations, by vendors and by whoever restored a mailbox last quarter.

Why this audit keeps not happening

The data exists in two places that don't talk to each other: the mailbox configuration lives in Exchange Online PowerShell, the usage lives in the Entra sign-in logs, and joining them means an export, a second export, and a spreadsheet. Worse, the sign-in log is the perishable half — 7 days of retention without Entra ID P1, 30 with it — so an audit done twice a year is looking at a window that has already closed. Across a dozen tenants, the same join has to be rebuilt a dozen times, which is exactly why it becomes an annual ritual instead of a monthly check (a cost quantified in the licence waste audit, where the same manual-export tax shows up against money instead of risk).

GraphPaaS syncs sign-in activity, mailbox configuration and licence assignment per tenant on the same schedule, so "which accounts used a legacy protocol this month, and which of them have no second factor" is a filter rather than a project — and the trend survives past the retention window Microsoft gives you.

Key takeaway
Disabling basic auth closed the front door and left the windows open. Until you can name every mailbox with POP, IMAP or SMTP enabled — and say which of them anything actually used last month — you have an inventory problem, not a security posture.
GraphPaaS

See which accounts in your tenant still authenticate over legacy mail protocols — by name, by protocol, by month.

Audit your sign-in activity →

Newsletter

Get the next article by email

Practical M365 & Azure cost pieces like this one. No spam, unsubscribe anytime.