Transition to service principal authentication in Cayosoft Administrator
Overview
Following the best practices of Microsoft, Cayosoft begins the transition towards service principal authentication in Cayosoft Administrator. In v13.2.1, service principal authentication in the Microsoft 365 extension becomes the target authentication method. Existing environments upgrading to Cayosoft Administrator v13.2.1 will retain the original connection method until you manually configure service principal authentication. This article covers the background and roadmap for the transition.
IMPORTANT: Upgrading EXO PS module to the latest version without first upgrading Cayosoft Administrator to v13.2 and transitioning to service principal will result in loss of functionality starting July 2026. For additional information, refer to the following article: Deprecation of the -Credential Parameter in Exchange Online PowerShell | Microsoft.
Big picture
Microsoft continues a shift from service accounts and user-based authentication to modern authentication methods, Microsoft Graph, and app-only access. Microsoft ends support for dated identity and administration methods, including Azure AD Graph, AzureAD and MSOnline PowerShell modules. To align with the direction of Microsoft, Cayosoft Administrator v13.2 introduces service principal authentication as the target Microsoft 365 access model while preserving upgrade continuity.
Starting v13.2, Cayosoft Administrator transitions towards the service principal authentication in the Microsoft 365 extension. The service principal authentication brings the following benefits to your environment:
When you configure service principal authentication, the Microsoft 365 extension no longer depends on the stored connection account.
Disruption caused by the connection account password changes, MFA requirements, and Conditional Access policies for user accounts are reduced.
The process of granting tenant consent and application access boundaries is clear.
Service principal authentication aligns with Microsoft’s move toward Microsoft Graph, app-only access, and modern authentication patterns.
The Microsoft 365 extension will require a self-signed or trusted certificate to set up app authentication and migrate from a connection account.
IMPORTANT: Cayosoft Administrator v13.1.1 and earlier will continue using a connection-account-based authentication method in the Microsoft 365 extension and will not support the new authentication method.
Prepare for transition
Upgrade to Cayosoft Administrator v13.2 to migrate to the new Microsoft 365 authentication model on your own schedule. Upgrading early gives your team time to configure and validate service principal authentication. Perform the following steps before upgrading:
Identify an Entra ID administration stakeholder to grant Microsoft 365 application consent and prepare for the migration.
Decide whether to use a self-signed certificate or certificated issued by a trusted authority in your environment.
Schedule a maintenance window to upgrade Cayosoft Administrator. For additional information on the upgrade procedure, refer to the following article: Cayosoft Administrator upgrade guide.
Steps to configure service principal authentication will become available in documentation for Cayosoft Administrator v13.2 as soon as it will become available later in July.
Comments
0 comments
Please sign in to leave a comment.