MC1490911: Microsoft Edge Retires Legacy Windows Sign-In and Shifts to OneAuth Authentication

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
59
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
▶ What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Microsoft 365 AdminsTenant AdminsIT ManagersSecurity TeamsService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
This retirement replaces the legacy WAM sign-in flow in Microsoft Edge with OneAuth starting in version 157, affecting identity, sign-in and SSO handling on Windows. Admins need to test and verify migration, adjust Edge configuration flags, and communicate to support teams, leading to moderate-to-high admin and implementation impact. Users will rarely need to reauthenticate, so user disruption remains moderate. The rollout is planned within a month, making it timely but not critical yet.
70
🛡️ Admin Impact
35
👥 User Impact
60
⚡ Urgency
55
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Microsoft Edge version 157 retires the legacy direct-WAM sign-in method on Windows, moving all profiles to OneAuth for standardised authentication and improved reliability.
👥

END USERS

Some users may need to sign in again after updating to Edge version 157.
🛡️

IT ADMINS

Check for profiles still using WAM and test the OneAuth transition before Edge version 157 rollout.
📅

ROLLOUT TIMELINE

Start:
November 2026

📢 Official Microsoft Message Center Announcement


Microsoft Edge: Retiring legacy sign-in implementation on Windows
Message ID: MC1490911

[What and Why:]

Microsoft Edge is retiring its legacy direct-WAM sign-in implementation on Windows starting with Microsoft Edge version 157, completing the consolidation onto the OneAuth authentication library.

This change standardizes authentication flows across Microsoft 365 client applications, simplifies platform supportability, eliminates dual-stack authentication code paths, and provides improved diagnostic and recovery mechanisms. Windows Web Account Manager (WAM) itself is not being deprecated; OneAuth continues to use Windows WAM.

[Rollout Schedule:]

General Availability (Worldwide, GCC): Rollout begins in early November 2026 and is expected to complete in early November 2026.

[Impact on Your Organization:]

Who is affected:

  • Organizations using Microsoft Edge on Windows.
  • Users with Edge profiles that have not yet automatically migrated to OneAuth.
  • Organizations that explicitly disabled OneAuth WAM using --disable-features=msOneAuthWAM.

Platforms/Services:

  • Microsoft Edge on Windows
  • Browser sign-in, identity, token fetch, Single Sign-On, and account synchronization experiences

What will happen:

  • Starting with Microsoft Edge version 157, all remaining profiles will transition directly to OneAuth authentication.
  • The fallback legacy WAM path will default off under all circumstances.
  • Most users will transition transparently.
  • In rare cases, users may need to sign in to Microsoft Edge again.

[Action Required/Recommendations:]

We recommend that admins identify unmigrated profiles and test the transition before Microsoft Edge version 157 reaches their environment.

  • Navigate to edge://signin-internals in Microsoft Edge.
  • Under Edge Auth Library Information > Library, confirm whether the profile shows OneAuth or WAM.
  • If OneAuth is displayed, the profile is already using the modern path and no action is required.
  • If WAM is displayed, the profile is still using the legacy path.

On pilot test devices running Microsoft Edge version 155 or later, admins can test the transition before version 157 by launching Edge with this force flag:

msedge.exe --enable-features=msForceOneAuthWAM

Verify that edge://signin-internals reflects OneAuth, and confirm that browser sign-in, Single Sign-On, and account synchronization work as expected.

Inform support teams that a small number of users might see a sign-in action on the profile menu after updating to Edge version 157. If users experience sign-in issues, collect OneAuth logs with:

msedge.exe --enable-features=msForceOneAuthWAM --enable-logging -v=1 --oneauth-log-level=5

Default log location: %LOCALAPPDATA%\Microsoft\Edge\User Data\chrome_debug.log

[Compliance considerations:]

Does the change include an admin control, and can it be controlled through Entra ID group membership?Admins can validate and manage the transition through Microsoft Edge configuration and feature flags. Review your Microsoft Edge deployment and policy management practices for group-based rollout controls.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update