Jump to content

Recommended Posts

Posted

Source: https://blogs.technet.microsoft.com/exchange/2018/02/09/an-update-on-office-365-requiring-tls-1-2

 

In December 2017 it was announced Office 365 planned to discontinue support for TLS 1.0 and TLS 1.1 connections on 1st March 2018, and after that time only TLS 1.2 connections would be allowed when interacting with Office 365.

 

Many of you have been asking for additional detail on what this meant for on-premises deployments in hybrid mode or what happens if you do business with customers whom use Office 365 as their collaboration platform.

 

We would like to bring to your attention an update on Office 365’s plans to enforce TLS 1.2, which has now been communicated in this KB article (KB4057306). The end of support for TLS 1.0 and TLS 1.1 has been moved from 1st March 2018 to 31st October 2018 to allow for more time to prepare.

 

Though this date has been pushed back a bit, we will continue our Exchange Server TLS guidance blog post series soon. We also ask that you continue your preparations for this change, so you are in a position to not be impacted upon its completion.

 

https://dirteam.com/dave/2018/01/10/office-365-only-allows-tls-1-2

 

Microsoft warns that client-server and browser server combinations must use at least TLS1.2. Most connections to Office 365 already use TLS1.2 according to Microsoft. The change also impacts any on-premises architecture such as Active Directory Federation Services (ADFS) and Exchange Hybrid. These would require inbound and outbound TLS1.2 connections. You do not have to disable TLS1.0/1.1 on your on-premises environment. When you disable TLS 1.0 or 1.1 you might result into issues. Being up-to-date with software that is still in support is important. Check if TLS1.2 is actually enabled after updates.

 

In another article Microsoft explains a little bit what the impact might be regarding different Windows OSes. The article does not explicitly mention non-Microsoft solutions that connect with Office 365. I fear some of those solution will not be checked. The longer I thought about those scenarios, I got a little bit worried that some organizations might run into issues when this change comes into effect. The support article does not specify any particular protocol. Therefore I assume that every protocol is affected. I can think of HTTPS, POP/IMAP and SMTP when regarding Exchange Online. I will only focus on these protocol, but that doesn’t mean other protocols or services might have some impact specifically for that service (Skype for Business Online for instance).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...