If you've implemented multi-factor authentication, you should disable the default basic authentication to make sure attackers can't exploit it. Attackers will go after weaker credentials and passwords ...
CISA has urged government agencies and private sector organizations using Microsoft's Exchange cloud email platform to expedite the switch from Basic Authentication legacy authentication methods ...