Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

End of Basic Authentication - Microsoft - Retrieve mails

Pascal Engel July 19, 2022

Hello,
Unfortunately, Microsoft is discontinuing Basic Authentication as of October 2022. Is there a solution from Atlassian to change this to the new method from Microsoft?
Many thanks
Pascal Engel

1 answer

0 votes
Derrix Reynolds July 19, 2022

For many years, applications have used Basic authentication to connect to servers, services, and API endpoints. Basic authentication simply means the application sends a username and password with every request, and those credentials are also often stored or saved on the device. Traditionally, Basic authentication is enabled by default on most servers or services, and is simple to set up.

Simplicity isn't at all bad, but Basic authentication makes it easier for attackers to capture user credentials (particularly if the credentials are not protected by TLS), which increases the risk of those stolen credentials being reused against other endpoints or services. Furthermore, the enforcement of multifactor authentication (MFA) is not simple or in some cases, possible when Basic authentication remains enabled.

Basic authentication is an outdated industry standard. Threats posed by it have only increased since we originally announced that we were going to turn it off (see Improving Security - Together) There are better and more effective user authentication alternatives.

We actively recommend that customers adopt security strategies such as Zero Trust (Never Trust, Always Verify), or apply real-time assessment policies when users and devices access corporate information. These alternatives allow for intelligent decisions about who is trying to access what from where on which device rather than simply trusting an authentication credential that could be a bad actor impersonating a user.

With these threats and risks in mind, we're taking steps to improve data security in Exchange Online.

Note

The deprecation of basic authentication will also prevent the use of app passwords with apps that don't support two-step verification.  MyTHDHR Workday Login

Pascal Engel July 21, 2022

Thanks for your answer but I didn't ask anything about that.
I was more interested in whether there is a possibility for Jira to exchange or update the Basic Authentication against the current standard (MFA).

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
VERSION
8.22.2
TAGS
AUG Leaders

Atlassian Community Events