-> Legacy Exchange tokens are deprecated. Legacy Exchange [user identity](../outlook/authentication.md#exchange-user-identity-token) and [callback](../outlook/authentication.md#callback-tokens) tokens have been turned off for most Exchange Online tenants. Administrators can reenable legacy tokens for tenants and add-ins until June 2025. In October 2025, legacy tokens will be completely turned off for all tenants. For the timeline and details, see our [FAQ page](../outlook/faq-nested-app-auth-outlook-legacy-tokens.md). This is part of [Microsoft's Secure Future Initiative](https://blogs.microsoft.com/on-the-issues/2023/11/02/secure-future-initiative-sfi-cybersecurity-cyberattacks/), which gives organizations the tools needed to respond to the current threat landscape. Exchange user identity tokens will still work for Exchange on-premises. Nested app authentication is the recommended approach for tokens going forward.
0 commit comments