Who actually still uses legacy auth?
Before you flip the block-legacy-auth policy, see who breaks. This reads your sign-in logs for legacy protocol traffic — IMAP, POP, authenticated SMTP, ActiveSync, "other clients" — and shows which accounts and apps used them, with successes and failures separated (failures on legacy protocols are usually password spray). Read-only, rendered in your browser only.
Sign in with a work account holding Security Reader, Reports Reader, or higher. Reading sign-in logs via Graph requires the tenant to have at least one Entra ID P1 licence (included in Business Premium, E3, E5).
legacy sign-ins by account
| account | protocol | app | last seen | ok | fail |
|---|
Ready to block it? ./ca-policy-check verifies your Conditional Access covers legacy auth — and the fixed-price assessment closes the rest → ./view pricing
questions before you sign in
▸What exactly am I consenting to?
▸How do I verify nothing leaves my browser?
▸Why might results be incomplete?
▸How do I revoke access afterwards?
Reads /auditLogs/signIns via Microsoft Graph with delegated permissions. Legacy protocols checked: Exchange ActiveSync, IMAP4, POP3, Authenticated SMTP, Other clients. Results render entirely client-side; nothing is transmitted or stored.