Loading...

Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols

Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols

Microsoft is retiring the legacy IDCRL authentication protocol in SharePoint Online and OneDrive for Business by January 31, 2026, enforcing modern OpenID Connect and OAuth protocols. Legacy authentication will be blocked by default, with temporary re-enablement via PowerShell until April 30, 2026, and permanent retirement from May 1, 2026. Organizations should migrate to modern authentication promptly. Introduction: As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods. When this will happen: Starting January 31, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026. Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled. How this affects your organization: Who is affected: Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business. What will happen: Legacy authentication calls using IDCRL will be blocked by default starting January 31, 2026. Temporary re-enablement is possible via PowerShell until April 30, 2026. After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled. Applications using IDCRL will fail to authenticate unless updated to use modern protocols. What you can do to prepare: We recommend migrating from legacy authentication protocols to modern authentication as soon as possible.  To prepare for this retirement: Compliance considerations: No compliance considerations identified, review as appropriate for your organization. Migrate all clients, scripts, and applications to use OpenID Connect or OAuth protocols.  Review current configurations for IDCRL authentication. Notify IT admins, app owners, and security teams about the upcoming retirement. Update internal documentation to reflect the new authentication defaults. Use telemetry to identify usage of legacy authentication protocols and monitor migration progress. Use PowerShell to manage legacy authentication settings if needed: Set AllowLegacyAuthProtocolsEnabledSetting and LegacyAuthProtocolsEnabled to TRUE to […]

The post Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Dynamics 365 Field Service: Automate optimizations with Scheduling Operations Agent

This release expands the optimization capabilities of the Scheduling Operations Agent to include the ability to create recurring optimizations...

14 hours ago

Microsoft Teams: Call quality feedback surveys for Teams Rooms on Android

Microsoft Teams will introduce call quality feedback surveys for Teams Rooms on Android starting November 2026. Users can rate audio, video, a...

15 hours ago

Microsoft Edge: Retiring legacy sign-in implementation on Windows

Microsoft Edge on Windows will retire its legacy direct-WAM sign-in in version 157, fully adopting the OneAuth library to standardize authenti...

15 hours ago

Microsoft Defender Vulnerability Management: Private preview for selected developer package vulnerability coverage

Microsoft Defender Vulnerability Management is privately previewing expanded vulnerability coverage for selected Node.js, Python, and Java pac...

15 hours ago

Microsoft Defender for Office 365: Post-delivery protection for malicious QR codes in Microsoft Teams

Microsoft Defender for Office 365 extends Teams URL protection to detect malicious URLs in QR codes post-delivery, warning users and enabling ...

15 hours ago

Microsoft Teams: Analytics for desk utilization in Teams Pro Management portal

Microsoft Teams Pro Management portal will add desk utilization analytics, showing usage, reservations, occupancy, and peak patterns. Requires...

15 hours ago

‘Record A Skill’ Capability in PowerPoint Copilot

PowerPoint Copilot will introduce a “Record a Skill” feature in October 2026, allowing users to record and reuse workflows for com...

15 hours ago

Microsoft 365: Targeted Release retirement

Microsoft 365 Targeted Release will retire in January 2027, replaced by Frontier, Standard, and Deferred release options. Administrators must ...

15 hours ago

Interim guidance for Manitoba time zone changes

A time zone change affects Windows devices in Manitoba, with Windows releasing a fix in October 2026. Manitoba is permanently moving to UTC-5 ...

15 hours ago

Microsoft Purview DLP: Improved setup and Intune multi-admin approval support for unmanaged apps in Edge for Business

Starting November 2026, Microsoft Purview DLP will improve setup and support Intune multi-admin approval for unmanaged apps in Edge for Busine...

15 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.