Full Breakdown
Microsoft to Block Legacy TLS 1.0/1.1 for POP3 and IMAP4 on Exchange Online in July 2026
4/30/2026, 12:21:49 PM
Block on Legacy TLS Connections Set for July 2026
Microsoft announced that, beginning in July 2026, it will block POP3 and IMAP4 connections to Exchange Online that use TLS 1.0 or TLS 1.1. The block follows a limited opt-in period; customers who did not opt in will lose connectivity for those protocols.
Background and Timeline of TLS Deprecation
TLS 1.0 debuted in 1999 and TLS 1.1 in 2006. Both were deprecated in 2021, and Microsoft said they are no longer considered secure. Exchange Online ceased support for these versions in 2020. In 2023, Microsoft announced plans to disable TLS 1.0/1.1 for POP3 and IMAP4 clients, while offering an opt-in endpoint for customers whose software could not yet support TLS 1.2. The opt-in window ends in July 2026, when the block will be enforced. Browsers Firefox and Edge announced the end of legacy TLS support in 2018, and Google Workspace documentation lists TLS 1.0/1.1, advising newer protocols.
Adoption, Security Rationale, and Impact
Microsoft states that email clients and libraries already support TLS 1.2 or higher, and that the majority of POP and IMAP traffic to Exchange Online now uses these newer protocols. Removing TLS 1.0/1.1 improves security by eliminating vulnerabilities. However, legacy devices or software lacking TLS 1.2 support may experience connection failures once the block is applied, requiring upgrades or configuration changes.
Official Statements and Responses
Microsoft emphasizes that only customers who explicitly opted into the legacy endpoints will be affected by the deprecation. The company frames the change as a compliance and security measure consistent with its earlier TLS deprecation timeline, noting that most POP and IMAP traffic already uses TLS 1.2 or newer, which should limit disruption.
Potential Disruption for Legacy Systems
Legacy devices or software might stop working as connections fail, indicating that some customers could experience service interruptions when the block is enforced. This risk highlights the need for affected users to verify their client configurations before the deadline.
Verbatim Quotes
- "We will start to block legacy version connections starting in July 2026." — Microsoft, spokesperson
- "Modern email clients and libraries already support TLS 1.2 or higher." — Microsoft, spokesperson
- "And the vast majority of POP and IMAP traffic to Exchange Online today uses these newer protocols." — Microsoft, spokesperson
- "Our expectation is that only customers who have explicitly opted into using those legacy endpoints are impacted by the deprecation." — Microsoft, spokesperson
- "are no longer considered secure." — Microsoft, security statement
What’s Next
Customers who have enabled the legacy endpoint should review their email client configurations and upgrade to TLS 1.2-compatible software before July 2026. Microsoft warned that users may need support if failures occur after the block is applied.
