ARO: Legacy Authentication Protocol Detected

History has introduced many methods of authenticating to a service and many are now not only outdated but also increasingly easy to exploit.


Protocols such as BAV2ROPC (Business Apps v2 Resource Owner Password Credentials) is a legacy authentication protocol frequently used to bypass MFA and should be disabled.


Microsoft have produced several resources on how to manage this legacy protocol


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article