Skip to Content

MC1490911 Microsoft Edge Retiring legacy sign-in implementation on Windows

Summary

Microsoft Edge on Windows will retire its legacy direct-WAM sign-in in version 157, fully adopting the OneAuth library to standardize authentication. Rollout starts and completes in November 2026. Admins should identify unmigrated profiles, test transitions, and prepare for possible user sign-in prompts.

Message ID: MC1490911
Published: Oct 7, 2026
Service: Microsoft 365 suite
Tag: Major change, User impact, Admin impact, Retirement

Microsoft Message

Microsoft Edge is retiring its legacy direct-WAM sign-in implementation on Windows starting with Microsoft Edge version 157, completing the consolidation onto the OneAuth authentication library.

This change standardizes authentication flows across Microsoft 365 client applications, simplifies platform supportability, eliminates dual-stack authentication code paths, and provides improved diagnostic and recovery mechanisms. Windows Web Account Manager (WAM) itself is not being deprecated; OneAuth continues to use Windows WAM.

Rollout Schedule

General Availability (Worldwide, GCC): Rollout begins in early November 2026 and is expected to complete in early November 2026.

Impact on Your Organization

Who is affected

  • Organizations using Microsoft Edge on Windows.
  • Users with Edge profiles that have not yet automatically migrated to OneAuth.
  • Organizations that explicitly disabled OneAuth WAM using –disable-features=msOneAuthWAM.

Platforms/Services

  • Microsoft Edge on Windows
  • Browser sign-in, identity, token fetch, Single Sign-On, and account synchronization experiences

What will happen

  • Starting with Microsoft Edge version 157, all remaining profiles will transition directly to OneAuth authentication.
  • The fallback legacy WAM path will default off under all circumstances.
  • Most users will transition transparently.
  • In rare cases, users may need to sign in to Microsoft Edge again.

Action Required/Recommendations

We recommend that admins identify unmigrated profiles and test the transition before Microsoft Edge version 157 reaches their environment.

  • Navigate to edge://signin-internals in Microsoft Edge.
  • Under Edge Auth Library Information > Library, confirm whether the profile shows OneAuth or WAM.
  • If OneAuth is displayed, the profile is already using the modern path and no action is required.
  • If WAM is displayed, the profile is still using the legacy path.

On pilot test devices running Microsoft Edge version 155 or later, admins can test the transition before version 157 by launching Edge with this force flag:

msedge.exe --enable-features=msForceOneAuthWAM

Verify that edge://signin-internals reflects OneAuth, and confirm that browser sign-in, Single Sign-On, and account synchronization work as expected.

Inform support teams that a small number of users might see a sign-in action on the profile menu after updating to Edge version 157. If users experience sign-in issues, collect OneAuth logs with:

msedge.exe --enable-features=msForceOneAuthWAM --enable-logging -v=1 --oneauth-log-level=5

Default log location: %LOCALAPPDATA%\Microsoft\Edge\User Data\chrome_debug.log

Compliance considerations

Does the change include an admin control, and can it be controlled through Entra ID group membership?

Admins can validate and manage the transition through Microsoft Edge configuration and feature flags. Review your Microsoft Edge deployment and policy management practices for group-based rollout controls.