Part of the Okta-M365 Integration guide
All Entra ID service accounts on the domain you will be federating with Okta β such as those for printers or MSP tools β must be either configured to use Modern Auth before they are imported to Okta, or moved to a different domain that will not be federated, such as the *.onmicrosoft.com domain. This procedure shows you how to identify accounts associated with legacy authentication sign-on activity.
WARNING
IMAP, SMTP, and POP3 are not supported by the integration. Use of these protocols for service accounts imported into Okta can result in service failure.
BEFORE YOU BEGIN
As part of the Okta-M365 Integration guide, this procedure assumes you have already created the dedicated Entra ID service account for the integration.
Steps
Log into the Microsoft Entra admin center as an administrator.
Under Identity, click Users > All users.
Click Sign-in logs.
Click the Date filter (default: Last 7 days), select Last 1 month, and click Apply.
Click Add Filters, select Client app, and click Apply.
Click the Client app filter (default: None selected).
Under Legacy Authentication Clients, select every option in the list and click Apply.
The table now lists all sign-ins attempted in the last month that used legacy authentication. Click a value in the Request ID column to review details about a specific account.
Work through the list of accounts using legacy authentication. For each account, either:
Move it to a Windows domain that will not be federated with Okta, or
Configure it to use Modern Auth.
NEXT STEPS
Completing the Okta-M365 Integration? Continue to Set the *.OnMicrosoft domain as the default.
