Updated May 13, 2026: We have initiated the deprecation rollout and expect to reach 100% production coverage in the next few weeks. We strongly recommend that customers transition to modern authentication at the earliest opportunity. Thank you for your patience.
[Introduction:]
As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.
[When this will happen:]
- Starting February 16, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
- Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.
[How this affects your organization:]
Who is affected:
- Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
- Legacy authentication calls using IDCRL will be blocked by default starting February 16, 2026.
- Temporary re-enablement is possible via PowerShell until April 30, 2026.
- After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
- Applications using IDCRL will fail to authenticate unless updated to use modern protocols.
[What you can do to prepare:]
We recommend migrating from legacy authentication protocols to modern authentication as soon as possible.
To prepare for this retirement:
- Migrate all clients, scripts, and applications to use OpenID Connect or OAuth protocols.
- Review current configurations for IDCRL authentication.
- Notify IT admins, app owners, and security teams about the upcoming retirement.
- Update internal documentation to reflect the new authentication defaults.
- Use telemetry to identify usage of legacy authentication protocols and monitor migration progress.
- Use PowerShell to manage legacy authentication settings if needed:
- Set
AllowLegacyAuthProtocolsEnabledSettingandLegacyAuthProtocolsEnabledtoTRUEto temporarily allow legacy authentication until April 30, 2026.
- Set
- Learn more:
[Compliance considerations:]
No compliance considerations identified, review as appropriate for your organization.
Source: Microsoft
<<< [MC1184649] Archive
Tooltip: View earlier revisions of this post
Latest Posts
- Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols [MC1184649]
![Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols [MC1184649] 2 pexels adrien olichon 1257089 3709370](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- (Updated) Microsoft Teams: Meeting Participants Can Request Collaborative Annotation Sessions [MC1019312]
![(Updated) Microsoft Teams: Meeting Participants Can Request Collaborative Annotation Sessions [MC1019312] 3 pexels yankrukov 5215398](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- (Updated) Microsoft 365 Copilot Mobile App: Capability to drive awareness via Notifications on M365 Admin Center [MC1308856]
![(Updated) Microsoft 365 Copilot Mobile App: Capability to drive awareness via Notifications on M365 Admin Center [MC1308856] 4 tourists 6887737 1920](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Announcing Region Expansion of P5.48xl instances on SageMaker Studio notebooks

![Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols [MC1184649] 1 Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols [MC1184649]](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-adrien-olichon-1257089-3709370-1024x683.webp)
![Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols [MC1184649] 2 pexels adrien olichon 1257089 3709370](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-adrien-olichon-1257089-3709370-150x150.webp)
![(Updated) Microsoft Teams: Meeting Participants Can Request Collaborative Annotation Sessions [MC1019312] 3 pexels yankrukov 5215398](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-yankrukov-5215398-150x150.webp)
![(Updated) Microsoft 365 Copilot Mobile App: Capability to drive awareness via Notifications on M365 Admin Center [MC1308856] 4 tourists 6887737 1920](https://mwpro.co.uk/wp-content/uploads/2025/06/tourists-6887737_1920-150x150.webp)
