Microsoft to end Client Access Rules support in Exchange Online by 2023
The deprecation process will begin as early as October 2022, according to reports

Microsoft has announced it will retire Client Access Rules (CARs) in its Exchange Online platform by September 2023.
CARs allow Microsoft 365 administrators to filter client access to Exchange Online by combining conditions, exceptions, actions, and priorities.
RELATED RESOURCE
Move to business messaging and let richer connections begin
Creating better customer relationships with high-value conversations
"Today, we are announcing the retirement of CARs in Exchange Online, to be fully deprecated by September 2023," the Exchange Team said.
"We will send Message Center posts to tenants using client access rules to start the planning process to migrate their rules."
Per reports, beginning October 2022, the company will disable client access rules for unused tenants. By September 2023, Microsoft will assist all remaining tenants in migrating from CARs to newer access control features such as continuous access evaluation (CAE)
"Now with new features, like Continuous Access Evaluation (CAE) that allows Azure Active Directory applications to subscribe to critical events, that can then be evaluated and enforced in near real time; you can have better control while also adding resiliency to your organization," the Exchange Team added.
As part of its effort to bolster Exchange Online’s safeguards, Microsoft has also warned customers that basic authentication will be disabled by October 1, for randomly selected tenants.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
"Thinly spread": Questions raised over UK government’s latest cyber funding scheme
The funding will go towards bolstering cyber skills, though some industry experts have questioned the size of the price tag
By George Fitzmaurice Published
-
Modern enterprise cybersecurity
whitepaper Cultivating resilience with reduced detection and response times
By ITPro Published
-
IDC InfoBrief: How CIOs can achieve the promised benefits of sustainability
whitepaper CIOs are facing two conflicting strategic imperatives
By ITPro Published
-
The complete guide to the NIST cybersecurity framework
Whitepaper Find out how the NIST Cybersecurity framework is evolving
By ITPro Published
-
Are you prepared for the next attack? The state of application security in 2024
Webinar Aligning to NIS2 cybersecurity risk-management obligations in the EU
By ITPro Published
-
The economics of penetration testing for web application security
whitepaper Get the most value from your security solution
By ITPro Published
-
How to extend zero trust to your cloud workloads
Whitepaper Implement zero trust-based security across your entire ecosystem
By ITPro Published
-
Four requirements for a zero trust branch
Whitepaper Effectively navigate the complex and ever-changing demands of security and network connectivity
By ITPro Published