Site icon TheCyberThrone

Microsoft will end TLS 1.1 Finally in O365

Advertisements

Microsoft has set the official retirement date for the insecure Transport Layer Security (TLS) 1.0 and 1.1 protocols in Office 365 starting with October 15, 2020, after temporarily halting deprecation enforcement for commercial customers due to COVID-19.

“As companies have pivoted their supply chains and countries have started to re-open we have re-established a retirement date for TLS 1.0 and 1.1 in Office 365 to be October 15, 2020,” the company said in the MC218794 Microsoft 365 admin center announcement on Friday.

“As previously communicated [..], we are moving all of our online services to Transport Layer Security (TLS) 1.2+ to provide best-in-class encryption, and to ensure our service is more secure by default.”

The TLS 1.0/1.1 retirement was first announced in December 2017 and, as explained by Microsoft, the effect of this change for end-users is expected to be minimal.

TLS 1.0 and 1.1 retirement

TLS 1.0/1.1 retirement guidance

IT administrators can use the official KB4057306 documentation to prepare for TLS 1.2 in Office 365 and Office 365 GCC.

They can also download this Office 365 TLS deprecation report to quickly identify the users and devices that connect to Exchange servers via TLS 1.0/1.1.

At the moment, users of the following clients are advised to update to the latest versions as they are known to be unable to use TLS 1.2:

Microsoft also provides a whitepaper with guidance on how to identify and remove TLS 1.0 dependencies in software built on top of Microsoft operating systems as a starting point for a migration plan to a TLS 1.2+ environment.

Microsoft recommends including the following:

Microsoft has already begun deprecating insecure TLS for any clients, devices, or services connecting to Office 365 through TLS 1.0 or 1.1 DoD or GCC High instances as of January 2020.

The two protocols will also become unsupported for commercial Office 365 customers, with the company recommending “that all client-server and browser-server combinations use TLS 1.2 (or a later version) in order to maintain connection to Office 365 services.”

Exit mobile version