Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderM365 ReportPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderM365 ReportPortfolio

Connect

© 2026 M365 Message Center. Created with ❤ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1184649

Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols

Plan for Change
Major Change

Message ID

MC1184649
View in Admin Center

Services

SharePoint Online
Microsoft OneDrive

Summary

Microsoft is retiring the legacy IDCRL authentication protocol in SharePoint Online and OneDrive for Business by May 1, 2026, enforcing modern OpenID Connect and OAuth protocols. Legacy authentication will be blocked starting February 16, 2026, with temporary re-enablement via PowerShell until April 30, 2026. Organizations must migrate to modern authentication.

Details

Updated February 5, 2026: We have updated the timeline. Thank you for your patience. 

Introduction:

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

When this will happen:

  • Starting February 16, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

How this affects your organization:

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting February 16, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

What you can do to prepare:

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

  • Migrate all clients, scripts, and applications to use OpenID Connect or OAuth protocols. 
  • Review current configurations for IDCRL authentication.
  • Notify IT admins, app owners, and security teams about the upcoming retirement.
  • Update internal documentation to reflect the new authentication defaults.
  • Use telemetry to identify usage of legacy authentication protocols and monitor migration progress.
  • Use PowerShell to manage legacy authentication settings if needed:
    • Set AllowLegacyAuthProtocolsEnabledSetting and LegacyAuthProtocolsEnabled to TRUE to temporarily allow legacy authentication until April 30, 2026.
  • Learn more:
    • Migrating from IDCRL authentication to modern authentication in SharePoint | Microsoft 365 Developer Blog | Microsoft Dev Blogs
    • Set-SPOTenant (Microsoft.Online.SharePoint.PowerShell) | Microsoft Learn

Compliance considerations:

No compliance considerations identified, review as appropriate for your organization.

Timeline

Published
Nov 11, 2025
Message published to Message Center
Action Required By
Jan 30, 2026
Action deadline
Updated
Feb 5, 2026
Message content updated
End Date
Jun 1, 2026
Message timeline ends

Tags

#Updated message#User impact#Admin impact#Retirement

Category

Plan for Change

Related Messages

Similar updates

MC1243549â—Ź

Retirement of SharePoint One-Time Passcode (SPO OTP) and transition to Microsoft Entra B2B

Mar 4, 2026
MC542767â—Ź

SharePoint 2013 workflow retirement

Apr 17, 2023
MC1188599

Microsoft 365: Modern Access Request and Access Denied web page

Nov 21, 2025
MC1097272â—Ź

Microsoft 365 Upcoming Secure by Default Settings Changes

Jun 17, 2025
MC1089315â—Ź

Resharing to external users required after enabling Microsoft SharePoint integration with Microsoft Entra B2B

Jun 6, 2025