Skip to content
TrustList
News

Exchange Online PowerShell: upgrade the ExchangeOnlineManagement module to 3.10.1 before strict logon enforcement on 31 March 2027

Editorial

By TrustList Editorial

Microsoft says ExchangeOnlineManagement versions before 3.10.1 may fail interactive sign-in once strict logon enforcement begins on 31 March 2027 (rollout to late April), especially PowerShell 7 with WAM disabled. Upgrade and test scripts first.

About Exchange Online PowerShell: upgrade the ExchangeOnlineManagement module to 3.10.1 before strict logon enforcement on 31 March 2027

Exchange Online PowerShell: upgrade the ExchangeOnlineManagement module to 3.10.1 before strict logon enforcement on 31 March 2027

1 October 2026 — Microsoft has told Exchange Online administrators to upgrade the ExchangeOnlineManagement PowerShell module to version 3.10.1 or later. A Message Center post published on 30 September 2026 (MC1483974), tagged as a major change, says enforcement of stricter logon requirements is scheduled to begin on 31 March 2027, with the rollout running from late March to late April 2027. The post's "act by" date is 26 March 2027.

Not yet independently verified. This rests only on Microsoft’s own Message Center post, read through a public archive because the admin centre requires sign-in. No independent report was found. We will update this when it can be confirmed, and remove this note.

What changes

Microsoft says version 3.10.1 of the module brings security enhancements to the Exchange Online PowerShell authentication flow. After enforcement starts, versions earlier than 3.10.1 may fail to authenticate in certain interactive scenarios. Microsoft singles out one combination: PowerShell 7 with Web Account Manager (WAM) disabled.

You may not be affected if you use:

  • ExchangeOnlineManagement 3.10.1 or later;
  • certificate-based authentication;
  • WAM-based authentication;
  • Windows PowerShell 5.x.

Where it will bite

The admin who runs Connect-ExchangeOnline by hand on a laptop will notice at once and upgrade. The problem is the module copies nobody looks at: scheduled scripts on a management server, jump boxes, runbooks, scripts in a managed service provider's tooling, and containers built from an image with a pinned module version. If one of those uses interactive sign-in on PowerShell 7, it can start failing in April 2027 with an authentication error that looks unrelated to a module version.

What to do

  • Inventory installed versions on every machine and image that runs Exchange Online PowerShell: Get-Module ExchangeOnlineManagement -ListAvailable.
  • Upgrade to 3.10.1 or later from the PowerShell Gallery, and update any pinned version in build images and automation accounts.
  • Prefer non-interactive authentication for automation: certificate-based authentication is listed as not affected.
  • Test scripts and runbooks after the upgrade, well before 26 March 2027.
  • Ask managed service providers who administer your tenant which module versions their tooling uses.

Sources

Categories & features