April 27, 2025
Trending News

Microsoft is working to update iOS to improve Exchange Online’s security

  • June 17, 2022
  • 0

Traditional authentication is an old industry standard used to authenticate client-server connections. However, in recent years it has proven to be a significant attack vector for data security

Traditional authentication is an old industry standard used to authenticate client-server connections. However, in recent years it has proven to be a significant attack vector for data security breaches. As a result, most software vendors are abandoning the old mechanism and striving for modern authentication based on OAuth 2.0 to improve security.

This also applies to Apple Mail, which switched to modern authentication a few years ago. However, this meant that only new accounts added to the device after switching from basic to modern authentication could enjoy the benefits of better security, while older accounts would stick to basic authentication. This issue even applied to the original configuration applied to new devices and backups. Now, Microsoft is working with Apple to solve this problem radically.

While the details are a bit technical, what will mostly happen is that Apple will integrate Resource Owner Password Credential (ROPC) support in a future iOS update. This handler ensures safe use of credentials stored on your device.

After this update, the mail program uses ROPC to use your credentials to create an authentication flow for your Exchange Online account using Azure Active Directory. In return, you will receive OAuth tokens, your account will be configured to continue using modern authentication, and finally the normal authentication credentials will be deleted. Source

Source: Port Altele

Leave a Reply

Your email address will not be published. Required fields are marked *

Exit mobile version