Directly blocking legacy authentication The easiest way to block legacy authentication across your entire organization is by configuring a Conditional Access policy that applies specifically to legacy authentication clients and blocks access. Conditional Access policies apply to all client apps by default Client apps. By default, all newly created Conditional Access policies will apply to all client app types even if the client apps condition is not configured. Reference: https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/block-legacy- authentication