Opens in a new tab
vmblog logo 2024 wht (updated)

How the Move to Modern Authentication Is Impacting Migrations

Share: 

David Marshall | Published: December 27, 2022

By Stacey Farrar, Product Marketing Manager at BitTitan

The final deadline for the transition to Modern Authentication (Modern Auth) is imminent. Microsoft turned off Basic Authentication (Basic Auth) for specific protocols in Exchange Online in October. However, IT professionals who have taken advantage of the one-time extension have been able to temporarily re-enable a Basic Auth protocol on accounts used for incoming email configurations.

But after Dec 31, 2022, the bandaid is getting ripped off, and all those exceptions will be permanently disabled once and for all. This will directly impact the ability to migrate mailboxes at organizations that haven’t made provisions for the change.

In this post, we will:

  • Briefly review why the switch to Modern Auth is happening
  • Examine what workloads and tenants will be impacted by the move to Modern Auth
  • Review what IT professionals should plan for when migrating to Modern Auth

Why is Microsoft deprecating Basic Authentication?

From a cybersecurity perspective, the switch to Modern Auth is not just necessary but overdue. Basic Auth, which is used to connect servers, services, and API endpoints, is unavoidably insecure for the simple reason that it sends the user’s login credentials over the network with every request, which multiplies the opportunities for attackers to intercept credentials.

Basic Auth has been around for a very long time-more than 25 years. Given the current state of cybersecurity threats, it has become indefensible. Not only are user names and passwords sent to authenticate to every separate server, but the credentials are often stored by the user’s web browser and/or held on the servers to which they connect.

Because users all too often use easily guessed passwords or reuse their passwords across multiple sites, one exposure at any given point can expose dozens or hundreds of other accounts. Compromised credentials often find their way to the “dark web,” where they’re made available for sale.

Modern Authentication Is About Security and UX

Microsoft recommends adopting an organizational security strategy such as a zero-trust protocol. And Modern Auth equips you to do this, as it allows for a number of forms of multifactor identification, including Windows Hello, using an app to receive a PIN, and receiving a code on your phone. This added layer of security can help prevent unauthorized access to sensitive information.

But the move to Modern Auth isn’t solely about security. It’s also about ease of use. Modern Auth enables Single Sign-On (SSO), which allows users to access multiple applications with a single set of credentials. This can greatly improve user experience (UX) by making it easier for users to access the resources they need.

How Workloads and Tenants Will Be Impacted

To avoid potential Exchange Online migration obstacles-which could include Microsoft tools not working after you move the data-you want to make sure that you have Modern Auth enabled on both ends. And also to ensure that the migration tool you’re using is able to connect to both the source and destination.

You’ll also want to ensure that your staff is properly trained on the use of Modern Auth, specifically how to access services and applications using the new method.

But whatever method of multi-factor authentication your organization uses, it shouldn’t be all too unfamiliar for your users. After all, their computers already have thumb-readers, and they already use their phones to receive and enter security PINs.

Factors to Keep In Mind While Making the Change

IT professionals can take certain steps to make the transition to Modern Auth go as smoothly as possible, but first and foremost, it’s about communication. It’s a matter of communicating clearly with your team and your organization as a whole about what the transition to Modern Auth looks like and when it’s happening.

As long as the everyday users in your organization know what to expect in terms of timing, they otherwise won’t be broadly affected because they’ve been getting acclimated to this transition for a while. Already, when they go to sign into any Microsoft application, they know they’re going to get a text message. That’s part of two-factor authentication.

Make Sure Your Migration Tools Support Modern Authentication

But from the perspective of the IT professional, successfully carrying out a migration depends on far more than great communication. Indeed, the keys to ensuring a smooth transition from legacy authentication to Modern Auth boil down to thorough planning and proper tools.

Because the vast majority of administrators are migrating data from an Exchange tenant that uses Modern Auth, it’s necessary to have a migration tool that supports Modern Auth. You should re-evaluate your current licenses and double-check that your migration solutions support Modern Auth. If they don’t, you should research and adopt a migration tool that does. By adopting a migration tool that supports Modern Auth, you can avoid major setbacks during a migration.

If you’re planning an Exchange Online migration and you haven’t done one since Microsoft has implemented this change, give yourself some extra time. Make sure your source and destination are where they need to be. Complete your planning for the stages of migration, do your due diligence, and everything will be set up for success.

##

ABOUT THE AUTHOR

Stacey-Farrar 

Stacey Farrar is a product marketing manager at BitTitan, where he oversees go-to-market strategy and product messaging for MigrationWiz. His areas of expertise include cloud automation, SaaS, product marketing and management, digital marketing, customer engagement, and business development.