Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

(Updated) Exchange Online: Retirement of legacy TLS versions for POP and IMAP connections

Message ID
MC1293480
View in Message Center
Service
Exchange Online
Category
Plan for Change
Tags
Major Change User impactAdmin impactRetirement
Act By
July 31, 2026
Rollout
August 2026September 2026October 2026November 2026December 2026

Summary

Exchange Online will retire legacy TLS versions (1.0 and 1.1) for POP3 and IMAP4 connections from August 1 to December 31, 2026. Connections must use TLS 1.2 or later; older versions will fail. Organizations should ensure all email clients and applications support TLS 1.2+ and update legacy systems accordingly.

Details

Updated July 7, 2026: We have updated the timeline. Thank you for your patience. 

[Introduction]

We are retiring support for legacy Transport Layer Security (TLS) versions for POP3 and IMAP4 connections to Exchange Online. This change improves security and aligns with current industry standards. TLS 1.0 and TLS 1.1 are no longer considered secure. Most modern email clients already use TLS 1.2 or later. 

[When this will happen]

  • Rollout start: August 1, 2026
  • Rollout end: December 31, 2026

The rollout will occur gradually worldwide.

[How this affects your organization]

Who is affected

  • Microsoft 365 tenants using POP3 or IMAP4 with Exchange Online
  • Admins managing email clients, applications, or devices that use POP or IMAP

What will happen

  • POP3 and IMAP4 connections will require TLS 1.2 or later.
  • Connections using TLS 1.0 or TLS 1.1 will fail.
  • Modern email clients are not expected to be affected.
  • Legacy applications or devices may stop connecting.
  • Custom or embedded systems may require updates.

[What you can do to prepare]

  • If you use POP or IMAP with Exchange Online, ensure email clients, applications, and libraries support TLS 1.2 or later and do not use legacy TLS endpoints.
  • Review all POP and IMAP clients in your organization.
  • Confirm support for TLS 1.2 or later.
  • Update or replace clients that rely on legacy TLS.
  • Validate TLS support with third‑party vendors.
  • Inform helpdesk and operations teams.

No action is required if all connections already use TLS 1.2 or later.

[Compliance considerations]

No compliance considerations identified. Review as appropriate for your organization.

Change History

Show
July 7, 2026 at 10:30 PM Updated
Title
Previous
Exchange Online: Retirement of legacy TLS versions for POP and IMAP connections
New
(Updated) Exchange Online: Retirement of legacy TLS versions for POP and IMAP connections
Summary
Previous
Exchange Online will retire support for legacy TLS 1.0 and 1.1 on POP3 and IMAP4 connections between July 1 and December 31, 2026. Connections must use TLS 1.2 or later; legacy clients may fail. Organizations should ensure all email clients and systems support TLS 1.2+ and update if needed.
New
Exchange Online will retire legacy TLS versions (1.0 and 1.1) for POP3 and IMAP4 connections from August 1 to December 31, 2026. Connections must use TLS 1.2 or later; older versions will fail. Organizations should ensure all email clients and applications support TLS 1.2+ and update legacy systems accordingly.
Last Updated Date
Previous
2026-04-27T22:15:07.990Z
New
2026-07-07T20:14:00.540Z
Tags
Previous
User impact,Admin impact,Retirement
New
Updated message,User impact,Admin impact,Retirement
Body Content
Previous
<p><b>[Introduction]</b></p><p>We are retiring support for legacy Transport Layer Security (TLS) versions for POP3 and IMAP4 connections to Exchange Online. This change improves security and aligns with current industry standards. TLS 1.0 and TLS 1.1 are no longer considered secure. Most modern email clients already use TLS 1.2 or later.&nbsp;</p><p><b>[When this will happen]</b></p><ul><li>Rollout start: <b>July 1, 2026</b></li><li>Rollout end: <b>December 31, 2026</b></li></ul><p>The rollout will occur gradually worldwide.</p><p><b>[How this affects your organization]</b></p><p><i>Who is affected</i></p><ul><li>Microsoft 365 tenants using <b>POP3 or IMAP4 with Exchange Online</b></li><li>Admins managing email clients, applications, or devices that use POP or IMAP</li></ul><p><i>What will happen</i></p><ul><li>POP3 and IMAP4 connections will require<b> TLS 1.2 or later</b>.</li><li>Connections using TLS 1.0 or TLS 1.1 will fail.</li><li>Modern email clients are not expected to be affected.</li><li>Legacy applications or devices may stop connecting.</li><li>Custom or embedded systems may require updates.</li></ul><p><b>[What you can do to prepare]</b></p><ul><li>If you use POP or IMAP with Exchange Online, ensure email clients, applications, and libraries support TLS 1.2 or later and do not use <a href="https://learn.microsoft.com/exchange/clients-and-mobile-in-exchange-online/opt-in-exchange-online-endpoint-for-legacy-tls-using-pop3-or-imap4" target="_blank">legacy TLS endpoints</a>.</li><li>Review all POP and IMAP clients in your organization.</li><li>Confirm support for TLS 1.2 or later.</li><li>Update or replace clients that rely on legacy TLS.</li><li>Validate TLS support with third‑party vendors.</li><li>Inform helpdesk and operations teams.</li></ul><p>No action is required if all connections already use TLS 1.2 or later.</p><p><b>[Compliance considerations]</b></p><p>No compliance considerations identified. Review as appropriate for your organization.</p>
New
<p>Updated July 7, 2026: We have updated the timeline. Thank you for your patience.&nbsp;</p><p><b>[Introduction]</b></p><p>We are retiring support for legacy Transport Layer Security (TLS) versions for POP3 and IMAP4 connections to Exchange Online. This change improves security and aligns with current industry standards. TLS 1.0 and TLS 1.1 are no longer considered secure. Most modern email clients already use TLS 1.2 or later.&nbsp;</p><p><b>[When this will happen]</b></p><ul><li>Rollout start: <b>August 1, 2026</b></li><li>Rollout end: <b>December 31, 2026</b></li></ul><p>The rollout will occur gradually worldwide.</p><p><b>[How this affects your organization]</b></p><p><i>Who is affected</i></p><ul><li>Microsoft 365 tenants using <b>POP3 or IMAP4 with Exchange Online</b></li><li>Admins managing email clients, applications, or devices that use POP or IMAP</li></ul><p><i>What will happen</i></p><ul><li>POP3 and IMAP4 connections will require<b> TLS 1.2 or later</b>.</li><li>Connections using TLS 1.0 or TLS 1.1 will fail.</li><li>Modern email clients are not expected to be affected.</li><li>Legacy applications or devices may stop connecting.</li><li>Custom or embedded systems may require updates.</li></ul><p><b>[What you can do to prepare]</b></p><ul><li>If you use POP or IMAP with Exchange Online, ensure email clients, applications, and libraries support TLS 1.2 or later and do not use <a href="https://learn.microsoft.com/exchange/clients-and-mobile-in-exchange-online/opt-in-exchange-online-endpoint-for-legacy-tls-using-pop3-or-imap4" target="_blank">legacy TLS endpoints</a>.</li><li>Review all POP and IMAP clients in your organization.</li><li>Confirm support for TLS 1.2 or later.</li><li>Update or replace clients that rely on legacy TLS.</li><li>Validate TLS support with third‑party vendors.</li><li>Inform helpdesk and operations teams.</li></ul><p>No action is required if all connections already use TLS 1.2 or later.</p><p><b>[Compliance considerations]</b></p><p>No compliance considerations identified. Review as appropriate for your organization.</p>

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.