Loading...

Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols

Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols

Microsoft is retiring the legacy IDCRL authentication protocol in SharePoint Online and OneDrive for Business by January 31, 2026, enforcing modern OpenID Connect and OAuth protocols. Legacy authentication will be blocked by default, with temporary re-enablement via PowerShell until April 30, 2026, and permanent retirement from May 1, 2026. Organizations should migrate to modern authentication promptly. Introduction: As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods. When this will happen: Starting January 31, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026. Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled. How this affects your organization: Who is affected: Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business. What will happen: Legacy authentication calls using IDCRL will be blocked by default starting January 31, 2026. Temporary re-enablement is possible via PowerShell until April 30, 2026. After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled. Applications using IDCRL will fail to authenticate unless updated to use modern protocols. What you can do to prepare: We recommend migrating from legacy authentication protocols to modern authentication as soon as possible.  To prepare for this retirement: Compliance considerations: No compliance considerations identified, review as appropriate for your organization. Migrate all clients, scripts, and applications to use OpenID Connect or OAuth protocols.  Review current configurations for IDCRL authentication. Notify IT admins, app owners, and security teams about the upcoming retirement. Update internal documentation to reflect the new authentication defaults. Use telemetry to identify usage of legacy authentication protocols and monitor migration progress. Use PowerShell to manage legacy authentication settings if needed: Set AllowLegacyAuthProtocolsEnabledSetting and LegacyAuthProtocolsEnabled to TRUE to […]

The post Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols appeared first on M365 Admin.

Published on:

Learn more
M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Copilot (Microsoft 365): Chat History Landing page: Filtering UI Refresh

To help you quickly find the conversations that matter, we’re updating the Chat History filtering experience. This refresh makes the interface...

1 hour ago

Microsoft Copilot (Microsoft 365): Capture voice notes in the Microsoft 365 Copilot mobile app

With a Microsoft 365 Copilot license, transform offline discussions into structured, actionable, and searchable content with voice notes in Co...

1 hour ago

Microsoft Graph PowerShell SDK V2.34 Makes WAM the Default

The Web Account Manager (WAM) authentication broker becomes the default method for handling interactive Microsoft Graph PowerShell SDK connect...

5 hours ago

Microsoft 365: New functionality and prices in 2026

A range of security and AI enhancements have been announced for the Microsoft 365 suite of products in 2026, along with some small price incre...

1 day ago

Automating Microsoft 365 with PowerShell Update 19

Update #19 of the Automating Microsoft 365 with PowerShell eBook is now available. Subscribers can download the updated PDF and EPUB files fro...

1 day ago

Teams admin center: Auto‑updates for Teams Android device firmware and apps will be paused during year‑end holidays

Auto-updates for Teams Android device firmware and apps via Teams admin center will pause from December 20, 2025, to January 12, 2026, to ensu...

2 days ago

OpenAI’s GPT-Image-1.5 model is now available in Microsoft 365 Copilot

Microsoft 365 Copilot will replace GPT-4o with OpenAI’s GPT-Image-1.5 from mid-December 2025 to late January 2026, enhancing image generation ...

2 days ago

Teams admin center: Messaging safety defaults changing to “On” by default

Starting January 12, 2026, Microsoft Teams will enable messaging safety features by default, including weaponizable file type protection, mali...

2 days ago

Microsoft Defender for Office 365: Admins can block external users in Microsoft Teams from Defender Portal

Admins can now block external users in Microsoft Teams via the Tenant Allow/Block List in the Microsoft Defender portal, controlling access an...

2 days ago

Microsoft Copilot (Microsoft 365): Word Agent

Word Agent helps you handle research, structure, and formatting so you can stay focused on your ideas. Use multi‑turn chat to refine your draf...

2 days ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy