Back to latest version
You're viewing a historical snapshot from Jan 20, 2026. This is not the latest version.

Metadata at Jan 20, 2026

Last Updated

Jan 20, 2026

Published Nov 11, 2025

Service

SharePoint Online
Microsoft OneDrive

Tag

Major change
Updated message
User impact
Admin impact
Retirement

Act by

Jan 30, 2026

MC1184649 - Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols

Message Center

What changed since this version

removed textadded text

Updated January 20,February 5, 2026: We are updating this post as a reminder.have updated the timeline. Thank you for your patience. 

Introduction:

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

When this will happen:

  • Starting January 31,February 16, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

How this affects your organization:

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting January 31,February 16, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

What you can do to prepare:

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

Compliance considerations:

No compliance considerations identified, review as appropriate for your organization.

Snapshot from Jan 20, 2026

Updated January 20, 2026: We are updating this post as a reminder. Thank you for your patience. 

Introduction:

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

When this will happen:

  • Starting January 31, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

How this affects your organization:

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting January 31, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

What you can do to prepare:

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

Compliance considerations:

No compliance considerations identified, review as appropriate for your organization.