DeltaPulse now has a public MCP server. Add / integrate this tool with your Copilot Agent(s).

MCP Documentation

Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols

Message ID
MC1184649
View in Message Center
Services
SharePoint OnlineMicrosoft OneDrive
Category
Plan for Change
Tags
Major Change User impactAdmin impactRetirement
Act By
January 30, 2026
Rollout
February 2026April 2026May 2026

Summary

Microsoft is retiring the legacy IDCRL authentication protocol in SharePoint Online and OneDrive for Business by May 1, 2026, enforcing modern OpenID Connect and OAuth protocols. Legacy authentication will be blocked starting February 16, 2026, with temporary re-enablement via PowerShell until April 30, 2026. Organizations must migrate to modern authentication.

Details

Updated February 5, 2026: We have updated the timeline. Thank you for your patience. 

[Introduction:]

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

[When this will happen:]

  • Starting February 16, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

[How this affects your organization:]

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting February 16, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

[What you can do to prepare:]

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

[Compliance considerations:]

No compliance considerations identified, review as appropriate for your organization.

Change History

Show
February 5, 2026 at 6:30 PM Updated
Summary
Previous
Microsoft is retiring the legacy IDCRL authentication protocol in SharePoint Online and OneDrive for Business by January 31, 2026, enforcing modern OpenID Connect and OAuth protocols. Legacy authentication will be blocked by default, with temporary re-enablement via PowerShell until April 30, 2026, and permanent retirement from May 1, 2026. Organizations should migrate to modern authentication promptly.
New
Microsoft is retiring the legacy IDCRL authentication protocol in SharePoint Online and OneDrive for Business by May 1, 2026, enforcing modern OpenID Connect and OAuth protocols. Legacy authentication will be blocked starting February 16, 2026, with temporary re-enablement via PowerShell until April 30, 2026. Organizations must migrate to modern authentication.
Last Updated Date
Previous
2026-02-02T16:00:00.977Z
New
2026-02-05T17:48:51.620Z
Body Content
Previous

Updated February 2, 2026: We are updating this post as a reminder. Thank you for your patience. 

[Introduction:]

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

[When this will happen:]

  • Starting January 31, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

[How this affects your organization:]

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting January 31, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

[What you can do to prepare:]

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

[Compliance considerations:]

No compliance considerations identified, review as appropriate for your organization.

New

Updated February 5, 2026: We have updated the timeline. Thank you for your patience. 

[Introduction:]

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

[When this will happen:]

  • Starting February 16, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

[How this affects your organization:]

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting February 16, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

[What you can do to prepare:]

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

[Compliance considerations:]

No compliance considerations identified, review as appropriate for your organization.

February 2, 2026 at 4:31 PM Updated
Last Updated Date
Previous
2026-01-20T17:39:19.757Z
New
2026-02-02T16:00:00.977Z
Body Content
Previous

Updated January 20, 2026: We are updating this post as a reminder. Thank you for your patience. 

[Introduction:]

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

[When this will happen:]

  • Starting January 31, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

[How this affects your organization:]

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting January 31, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

[What you can do to prepare:]

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

[Compliance considerations:]

No compliance considerations identified, review as appropriate for your organization.

New

Updated February 2, 2026: We are updating this post as a reminder. Thank you for your patience. 

[Introduction:]

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

[When this will happen:]

  • Starting January 31, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

[How this affects your organization:]

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting January 31, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

[What you can do to prepare:]

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

[Compliance considerations:]

No compliance considerations identified, review as appropriate for your organization.

January 20, 2026 at 6:30 PM Updated
Last Updated Date
Previous
2026-01-06T17:18:04.740Z
New
2026-01-20T17:39:19.757Z
Body Content
Previous

Updated January 6, 2026: We are updating this post as a reminder. Thank you for your patience. 

[Introduction:]

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

[When this will happen:]

  • Starting January 31, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

[How this affects your organization:]

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting January 31, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

[What you can do to prepare:]

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

[Compliance considerations:]

No compliance considerations identified, review as appropriate for your organization.

New

Updated January 20, 2026: We are updating this post as a reminder. Thank you for your patience. 

[Introduction:]

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

[When this will happen:]

  • Starting January 31, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

[How this affects your organization:]

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting January 31, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

[What you can do to prepare:]

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

[Compliance considerations:]

No compliance considerations identified, review as appropriate for your organization.

January 6, 2026 at 6:30 PM Updated
Last Updated Date
Previous
2025-12-09T17:47:23.010Z
New
2026-01-06T17:18:04.740Z
Body Content
Previous

Updated December 9, 2025: We are updating this post as a reminder. Thank you for your patience. 

[Introduction:]

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

[When this will happen:]

  • Starting January 31, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

[How this affects your organization:]

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting January 31, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

[What you can do to prepare:]

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

[Compliance considerations:]

No compliance considerations identified, review as appropriate for your organization.

New

Updated January 6, 2026: We are updating this post as a reminder. Thank you for your patience. 

[Introduction:]

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

[When this will happen:]

  • Starting January 31, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

[How this affects your organization:]

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting January 31, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

[What you can do to prepare:]

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

[Compliance considerations:]

No compliance considerations identified, review as appropriate for your organization.

December 9, 2025 at 6:31 PM Updated
Last Updated Date
Previous
2025-11-11T00:38:05.263Z
New
2025-12-09T17:47:23.010Z
Tags
Previous
User impact,Admin impact,Retirement
New
Updated message,User impact,Admin impact,Retirement
Body Content
Previous

[Introduction:]

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

[When this will happen:]

  • Starting January 31, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

[How this affects your organization:]

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting January 31, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

[What you can do to prepare:]

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

[Compliance considerations:]

No compliance considerations identified, review as appropriate for your organization.

New

Updated December 9, 2025: We are updating this post as a reminder. Thank you for your patience. 

[Introduction:]

As part of the Microsoft Secure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocol in SharePoint Online and OneDrive for Business. This change helps strengthen your organization’s security posture by enforcing modern authentication standards—OpenID Connect and OAuth—which reduce exposure to outdated and vulnerable authentication methods.

[When this will happen:]

  • Starting January 31, 2026: Legacy client authentication will be blocked by default. Organizations may temporarily re-enable it using PowerShell until April 30, 2026.
  • Starting May 1, 2026: Legacy client authentication will be permanently blocked and cannot be re-enabled.

[How this affects your organization:]

Who is affected:

  • Organizations using clients, scripts, or applications that rely on the legacy IDCRL authentication protocol to access SharePoint Online or OneDrive for Business.
What will happen:
  • Legacy authentication calls using IDCRL will be blocked by default starting January 31, 2026.
  • Temporary re-enablement is possible via PowerShell until April 30, 2026.
  • After May 1, 2026, IDCRL authentication will be permanently retired and cannot be re-enabled.
  • Applications using IDCRL will fail to authenticate unless updated to use modern protocols.

[What you can do to prepare:]

We recommend migrating from legacy authentication protocols to modern authentication as soon as possible. 

To prepare for this retirement:

[Compliance considerations:]

No compliance considerations identified, review as appropriate for your organization.

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.