Skip to content

We still have app passwords: is that still safe?

App passwords were an MFA workaround for old apps without modern auth. In 2026, almost never needed anymore.

Try this first

  1. 1Inventory which users use app passwords: Entra > Users > Authentication methods column per user, or via PowerShell reporting.
  2. 2Per app password: figure out which application it is for. Ask the user. Usually an old smartphone mail app or a legacy tool.
  3. 3Find the modern equivalent: Outlook mobile, new iOS/Android Mail app, or the vendor's updated version. Almost everything supports OAuth now.
  4. 4Replace and test. Only after the app works without app password, remove it.
  5. 5Then disable app passwords entirely (Entra admin center > Protection > Multifactor authentication > Additional cloud-based MFA settings, or via the legacy MFA portal at account.activedirectory.windowsazure.com).

When to bring us in

Got a legacy line-of-business app that genuinely does not support modern auth? A service account with hard restrictions is safer than app passwords. We can advise.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.