Table of Contents
Summary
- Support for legacy TLS versions (1.0 and 1.1) for POP3 and IMAP4 connections to Exchange Online is being retired.
- Connections will require TLS 1.2 or later; older connections will fail.
- Modern email clients are unlikely to be affected, but legacy applications or devices may stop connecting.
- Organizations need to ensure email clients and applications support TLS 1.2 or later.
- No action is required if all connections already use TLS 1.2 or later.
Admin Impact: High
User Impact: High
Release Start: 01 Jul 2026
Release End: 31 Dec 2026
Services: Exchange
Category: Plan for change
Tags: User Adoption, Admin Action, Retirement
History
4/27/2026 Item Added to Message Center
Microsoft Message
Introduction
We are retiring support for legacy Transport Layer Security (TLS) versions for POP3 and IMAP4 connections to Exchange Online. This change improves security and aligns with current industry standards. TLS 1.0 and TLS 1.1 are no longer considered secure. Most modern email clients already use TLS 1.2 or later.
When this will happen
- Rollout start: July 1, 2026
- Rollout end: December 31, 2026
The rollout will occur gradually worldwide.
How this affects your organization
Who is affected
- Microsoft 365 tenants using POP3 or IMAP4 with Exchange Online
- Admins managing email clients, applications, or devices that use POP or IMAP
What will happen
- POP3 and IMAP4 connections will require TLS 1.2 or later.
- Connections using TLS 1.0 or TLS 1.1 will fail.
- Modern email clients are not expected to be affected.
- Legacy applications or devices may stop connecting.
- Custom or embedded systems may require updates.
What you can do to prepare
- If you use POP or IMAP with Exchange Online, ensure email clients, applications, and libraries support TLS 1.2 or later and do not use legacy TLS endpoints.
- Review all POP and IMAP clients in your organization.
- Confirm support for TLS 1.2 or later.
- Update or replace clients that rely on legacy TLS.
- Validate TLS support with third‑party vendors.
- Inform helpdesk and operations teams.
- No action is required if all connections already use TLS 1.2 or later.
Compliance considerations
No compliance considerations identified. Review as appropriate for your organization.