web
You’re offline. This is a read only version of the page.
close
Skip to main content
Community site session details

Community site session details

Session Id :
Small and medium business | Business Central, N...
Answered

Setup up SMTP with MFA and the setting to block legacy authentication

(0) ShareShare
ReportReport
Posted on by 1,003

We have set the MFA on our azure and then we also have to setup  the appcode password for Business Central.

This only work if you also set  the setting to block legacy authentication

Here is my problem i cant set  the setting to block legacy authentication, as it seem to require you buy more security option to you Azure account

 or  how else to set this up, with out to buy more.

I have the same question (0)
  • Verified answer
    Marco Mels Profile Picture
    on at
    RE: Setup up SMTP with MFA and the setting to block legacy authentication

    Hello,

    My favorite topic 

    There is a requirement to be 100% compliant as a CSP (if you are a CSP). The requirement here is that all the accounts you did add to your customer tenant (as a CSP) is that you add MFA to these accounts. The customer which you assist as as CSP do not have whereabouts of these accounts that were added (delegated admin for instance). So MFA is a must in that setup. If you are not a CSP, then this really a great idea  to do this as a requirement to all your accounts that access ERP data. 

    More information for CSP's:
    docs.microsoft.com/.../partner-security-requirements

    There is always this misunderstanding:

    1. Azure Policy => not compatible with App Passwords

    2. Not being able to use these Azure Policies => not compliant => SMTP / CRM accounts can no longer be used

    This is not true. Only 1 is true. Related to 2: It does not matter how you enable MFA on your accounts. The only requirement is that you do. Now with these Azure policies you do have the option to assign the policy and exclude the two accounts needed in Dynamics NAV / Dynamics 365 BC. Still you do have to enable MFA. This can be done on a per user base. Enabling MFA on all accounts with exceptions does require Azure Premium licenses. The free Azure policy like the Security Policy does simply switch MFA for all users including the two ones that do require App passwords.

    If you do not need these Azure Premium license, you simply enable MFA on all account on a per user base. This can be done in Azure AD, Users, username or Office 365 Portal, Users, Edit users. Here you can also do this in bulk. 

    The only issue here is that when creating new users, you may forget to enable but you can overcome this by ensuring this does become a managed process. This is where the Azure Premium license do come into place. 

    Thanks.

  • Claus Macali.dk Profile Picture
    1,003 on at
    RE: Setup up SMTP with MFA and the setting to block legacy authentication

    Thanks Marco, very helpfull

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Abhilash Warrier – Community Spotlight

We are honored to recognize Abhilash Warrier as our Community Spotlight honoree for…

Leaderboard > Small and medium business | Business Central, NAV, RMS

#1
Rishabh Kanaskar Profile Picture

Rishabh Kanaskar 4,327

#2
Sumit Singh Profile Picture

Sumit Singh 2,734

#3
Nimsara Jayathilaka. Profile Picture

Nimsara Jayathilaka. 2,599

Last 30 days Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans