Microsoft is retiring Basic Authentication for Exchange Online on October 1, 2022. The retirement impacts the availability of the Lightning Sync service account connection method for Microsoft Office 365 customers who use Exchange Online. Keep reading to learn whether Basic Authentication retirement affects you, and get our recommendations about syncing contacts and events with Salesforce for existing and prospective sync users.
Updated June 2022:
Updated February 2021:
Updated October 2020:
Updated April 2020:
Determine whether Basic Authentication retirement affects you, and if so, what you must do to continue syncing contacts and events.
Check with your company’s Microsoft admin or IT professional, or contact Microsoft directly.
If your Lightning Sync users’ email accounts are hosted on Exchange Online, check to see if your Lightning Sync connection method is service account.
If your settings indicate that you're connecting using the OAuth 2.0 connection method, the Basic Authentication retirement doesn’t affect you and no further action is necessary. OAuth 2.0 doesn’t require Basic Authentication, so you can continue to sync contacts and events using that connection method.
If your settings indicate that you're connecting with a service account, then the Basic Authentication retirement does affect you. To learn about next steps and when to take them, go to the next step.
Microsoft is blocking Basic Authentication for all tenants starting October 1, 2022. When Basic Auth is blocked, contacts and events stop syncing for your Lightning Sync users. To avoid sync interruption, skip to the last section in this article, Alternative Connection Methods for Syncing Between Exchange Online and Salesforce.
We recommend that you update your connection method before October 1, 2022. To learn more about the Basic Authentication retirement, see the Microsoft article, Deprecation of Basic authentication in Exchange Online.
Microsoft is blocking Basic Authentication for all tenants starting October 1, 2022. We recommend that at initial setup you use one of the recommended alternative connection methods given in the next section of this article.
When selecting an alternative connection method, keep in mind that Lightning Sync isn't available to new customers. Einstein Activity Capture is our long-term solution for syncing contacts and events between Microsoft® or Google applications and Salesforce. With Einstein Activity Capture, you benefit from productivity-boosting features beyond sync. We recommend that you first explore one of the Einstein Activity Capture connection methods available to Exchange Online customers.
These options let you continue to sync contacts and events between Exchange Online and Salesforce after Basic Authentication retirement. We suggest that you make one of these moves before October 1, 2022. We're here to help you and your sales reps prepare for a smooth transition to Einstein Activity Capture. See Move from Lightning Sync to Einstein Activity Capture.
You can continue to authenticate your email service to Salesforce user by user instead of authenticating all users in your tenant at the same time. During setup, you can connect your company's email service to Salesforce. Then each user connects their email and calendar account to Salesforce. For setup instructions, see Connect to Einstein Activity Capture with User-Level OAuth 2.0.
You can scope authentication to a set of users on your email service and deploy Einstein Activity Capture to all users at the same time. Plus, OAuth 2.0 is considered one of the leading methods for secure authentication. The Lightning Sync migration assistant can make the move quick and easy for you. For setup instructions, see Connect to Einstein Activity Capture with a Service Account OAuth 2.0.
You can continue to sync contacts and events with Lightning Sync with the OAuth 2.0 connection method. The OAuth 2.0 connection method is different than the service account because it provides authentication access to Salesforce for all Office 365 users in one setup step. OAuth 2.0 is considered one of the leading methods for secure authentication. For more information, see OAuth 2.0 Connection for Microsoft Users and Connect Salesforce and Microsoft® Exchange Using OAuth 2.0.
Keep in mind that for right now:
000388783

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.