Category
planForChange
Severity
normal
Major change
True
Last modified
2025-09-18 23:48:54
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
—
Action by (AI)
—
Services
Microsoft 365 suite
Tags
User impact, Admin impact, Retirement
Master tags
Security
Roadmap IDs
One-line summary
Microsoft 365 will enforce stricter TLS cipher suite policies, deprecating legacy suites without forward secrecy starting October 20, 2025; unsupported connections will fail.
Similar updates
More like thisMC1154299 Reminder - Support for Office 2016, Office 2019, and additional apps will end on October 14, 2025
Reminder - Support for Office 2016, Office 2019, and additional apps will end on October 14, 2025 Support for Office 2016, Office 2019, Visio 2016/2019, and Project 2016/2019 ends October 14, 2025; upgrade to Microsoft 365 Apps or Office LTSC 2024 to maintain security[What you can do to prepare:] To mitigate these risks while maintaining access.
MC1056260 Support for Office 2016, Office 2019, and additional apps will end on October 14, 2025
Co... [What you need to do to prepare:] To mitigate these risks while maintaining access to desktop Office apps, we recommend upgrading devices to a Microsoft 365 or Office 365 suite that includes Microsoft 365 Apps (for enterprise or for business). Microsoft 365 Apps provides always-up-to-date versions of familiar apps like Word, Excel, and.
MC994282 Legacy Microsoft Outlook for Mac: Support will end
Legacy Microsoft Outlook for Mac: Support will end Legacy Outlook for Mac will no longer be usable with Microsoft 365 subscriptions after October 2025; users must switch to the new Outlook for Mac. After October 2025, Microsoft 365 subscriptions associated with a Microsoft 365 account (personal, work, or school) will no longer be able to use.
MC1184649 Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols
...ure Future Initiative (SFI) and in alignment with the “Secure by Default” principle, we’re retiring the legacy IDCRL (Identity Client Run Time Library) authentication protocolLearn more: Migrating from IDCRL authentication to modern authentication in SharePoint | Microsoft 365 Developer Blog | Microsoft Dev Blogs Set-SPOTenant.
MC1143929 Certificate-based authentication changes on Windows domain controllers - coming September 2025
Certificate-based authentication changes on Windows domain controllers - coming September 2025 Starting with September 2025 Windows updates, strict certificate mapping will be enforced on AD CS and domain controllers, blocking authentication if requirements aren't met. Since 2023, Microsoft has been sharing reminders of changes coming to.
MC676299 (Updated) Retirement of Exchange Web Services in Exchange Online
(Updated) Retirement of Exchange Web Services in Exchange Online Exchange Online will block Exchange Web Services (EWS) requests starting October 1, 2026; migrate all EWS apps to Microsoft Graph as soon as possible. In 2018, we announced that we were no longer making feature updates to Exchange Web Services (EWS) in Exchange Online, and we.
Details
Summary
Microsoft 365 will deprecate legacy TLS cipher suites lacking forward secrecy on October 20, 2025, supporting only specified TLS 1.3 and 1.2 cipher suites. Organizations must update systems and configurations to maintain connectivity and security compliance.
Body (from Message Center)
[Introduction]
To strengthen encryption standards and uphold customer trust, Microsoft is deprecating support for legacy TLS cipher suites that do not offer forward secrecy. This change aligns with our ongoing commitment to security and data protection across Microsoft 365 services.
[When this will happen:]
Starting October 20, 2025, Microsoft 365 services will enforce stricter TLS cipher suite policies.
[How this affects your organization:]
Who is affected:
- Admins managing Microsoft 365 services across commercial, GCC, and GCC High tenants.
- Organizations using legacy operating systems or custom TLS configurations.
What will happen:
- Microsoft 365 services will only support the following TLS cipher suites:
- TLS 1.3
- TLS_AES_256_GCM_SHA384
- TLS_AES_128_GCM_SHA256
- TLS 1.2
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
- Connections using deprecated cipher suites will fail.
- Clients supporting at least one listed TLS 1.2 cipher suite will continue to connect.
- Ensure all client systems are running supported operating systems that include the required cipher suites.
- Upgrade legacy systems (e.g., Windows 8, Windows Server 2012) to supported versions.
- Review and update Group Policy or security configurations to confirm required cipher suites are enabled.
- Communicate this change to helpdesk and infrastructure teams.
- Reference the following resources for configuration guidance:
No compliance considerations identified, review as appropriate for your organization.
Raw JSON (for debugging)
Expand/collapse the full payload below.
Show/hide raw
{
"snapshot_item": {
"action_required_by": null,
"ai_action_required_by": null,
"ai_actions": [
"Upgrade legacy client and server OS",
"Enable required TLS cipher suites",
"Update Group Policy/security configs",
"Notify helpdesk and infrastructure teams"
],
"ai_master_tags": [
"Security"
],
"ai_model": "gpt-4.1",
"ai_summary": "Microsoft 365 will enforce stricter TLS cipher suite policies, deprecating legacy suites without forward secrecy starting October 20, 2025; unsupported connections will fail.",
"ai_topics": [
"Microsoft 365"
],
"category": "planForChange",
"details_map": {
"Summary": "Microsoft 365 will deprecate legacy TLS cipher suites lacking forward secrecy on October 20, 2025, supporting only specified TLS 1.3 and 1.2 cipher suites. Organizations must update systems and configurations to maintain connectivity and security compliance."
},
"id": "MC1155427",
"importance": 5,
"is_major_change": true,
"last_modified": "2025-09-18T23:48:54Z",
"ms_products": [
"Microsoft 365"
],
"platforms": null,
"roadmap_ids": [],
"services": [
"Microsoft 365 suite"
],
"severity": "normal",
"tags": [
"User impact",
"Admin impact",
"Retirement"
],
"title": "Legacy TLS cipher suites will be deprecated in M365 services on October 20, 2025"
}
}