Microsoft 365 - Which clients/protocols will be supported?
Table of Contents
- What is a client?
- What is an email protocol?
- What clients/protocols are supported by Office 365 Team?
- Under what other circumstances would these protocols be disabled for an existing account?
- Additional context for the security justification
- Enable/Disable POP Protocol
- What happens if POP protocol is disabled?
- Reasons for disabling POP protocol
What is a client?
A client is an application that is used to connect to your Office 365 account. Some examples include Microsoft Outlook or Edge/Google Chrome.
What is an email protocol?
Email protocol is a method by which a communication channel is established between two computers and email (some protocols also include calendar data) is transferred between them. When an email is transferred, a mail server and two computers are involved. One computer sends the mail and the other one receives it. The mail server stores the mail and lets the receiving device access it and download it if needed.
What clients/protocols are supported by Office 365 Team?
Even though Microsoft provides you with the ability to connect to your Office 365 account using a wide variety of clients/protocols, for the best experience and complete support, Microsoft recommends connecting through one of the following ways:
- Via the Exchange protocol (MAPI) within most current versions of Outlook desktop clients.
- Using the most current version of Outlook App for iOS/Android.
- Connecting to Outlook on the Web using one of the recommended/supported web browsers.
Under what other circumstances would these protocols be disabled for an existing account?
- The POP protocol is disabled by default for any new Office 365 account (NetID or Service Account). Contact the help desk to manage this setting. The UW-Madison Office 365 support team encourages people to only enable the POP protocol if they plan to use it.
- Any account that is found to be compromised by a malicious actor will have all protocols disabled to mitigate an ongoing incident. Default protocols are re-enabled when the account is re-enabled.
- Accounts managed by participating departments that mandate strict policies against the use of some protocols are unable to manage the use of these protocols.
- Accounts that are undergoing deactivation.
Additional context for the security justification:
Abuse of the email service by compromised NetID credentials is a very large and growing issue at UW-Madison. These credentials are used to access mailboxes, send out phishing to other people, and potentially exfiltrate sensitive email messages.
- Disabling the POP protocol helps reduce the risk of accidental deletion of email and data exfiltration due to abuse via compromised credentials.
What does this mean?
Microsoft has not stated that IMAP and POP functionality will end, so the UW-Madison Office 365 team believes that IMAP and POP will continue to function after 2020. However, based on conversations with our Microsoft partners, it is clear that they are advocating strongly for the deprecation of clients and protocols that aren’t capable of using Modern Authentication.
Modern Authentication is what enables enhanced security, in terms of password handling and Multi-Factor Authentication. Microsoft’s position, coupled with UW-Madison’s needs for enhanced security of credentials and authentication flows, means that the UW-Madison Office 365 team is taking the strategic position of encouraging people to use clients capable of Modern Authentication by default.
Are there any policy justifications for this change?
Yes. Some people configure Gmail (or other 3rd party services) to POP email out of their UW-Madison mailbox. This requires Gmail store the password in a decryptable format on their servers.
Technically, this is a violation of UW password policy, however we recognize that many people have been doing this for years, so that is why there are no plans to disable POP for existing accounts.
Enable/Disable POP Protocol
Important: Make sure you have reviewed the "Under what other circumstances would these protocols be disabled for an existing account" section above before proceeding to make changes to any of the protocols.
Post Office Protocol (POP) is a standard protocol that retrieves mail from a remote server. Many POP configurations remove the mail from the remote server upon retrieval. This protocol can only be enabled by contacting the Help Desk and escalating a case to the M365 team.
What happens if POP protocol is disabled?
If POP protocol is disabled for an account, any client that attempts to connect via POP protocol to your Office 365 account will be unable to connect (some type of connection error). Below is a list of errors you may receive:
- Outlook on the web - browsers: "Something went wrong - The mailbox being accessed does not have a valid account state ('ProtocolDisabled')"
- Outlook desktop: You may receive an encryption or connection error.
- Outlook for Android: You will receive a connection error.
- Outlook for iOS: You will receive a connection error.
- ActiveSync - native mobile mail/calendar clients: unable to verify account.
- EWS applications - used by developers via API code: unable to connect or verify account.
- IMAP - any mail client: unable to connect or verify account, or repeatedly prompted for account credentials.
- POP - any mail client: unable to connect or verify account, or repeatedly prompted for account credentials.
- UW SMTP Auth - sending mail via any client/process: error attempting to connect or unable to send message.
If you are receiving following error when attempting to log into your Office 365 account via any Outlook client, "Something went wrong - The mailbox being accessed does not have a valid account state ('ProtocolDisabled')", and your account is eligible for Office 365, please activate missing services on your NetID account. Then wait about an hour and try accessing your account again.
Reasons for Disabling POP Protocol
- Messages deleted via POP bypass the 'Deleted Items' folder and cannot be recovered.
- Departmental policy mandating that only certain protocols be used for security and/or compliance reasons
- Due to compliant with security policy - many SMPH customers have this policy assigned to their UW-Madison Office 365 account.