Share via


Upgrade Transport Layer Security to TLS 1.3

Enabled for Public preview General availability
Admins, makers, marketers, or analysts, automatically - Dec 6, 2024

Business value

To comply with standard security protocols, Dynamics 365 Customer Engagement (on-premises) servers must meet the standard Transport Layer Security (TLS) and current cipher suite requirements. This requirement includes any on-premises server that communicates server-to-server with online Dynamics 365 or Power Apps services. Examples of these servers are Exchange Server (on-premises) and web servers that host clients or services. Deprecated cipher suites include non-supported cipher suites such as TLS_RSA. For improved security, faster handshakes, enhanced privacy, and simplified cipher suites, use the TLS 1.3 protocol.

Feature details

Use on-premises servers for the following services:

  1. Server-side sync for Exchange emails.
  2. Outbound plug-ins.
  3. Web server-to-server integration.
  4. Environment discovery with the regional discovery service.

Upgrade the TLS protocol on Dynamics 365 Customer Engagement (on-premises) computers and network from TLS 1.2 to TLS 1.3 to secure communications over the internet.

TLS 1.3 simplifies and enhances security by using only three cipher suites with perfect forward secrecy (PFS) and authenticated encryption with additional data (AEAD). This version streamlines the protocol and ensures robust security. Key improvements include:

  • Privacy enhancements: Minimal cleartext protocol bits prevent protocol ossification and hide content length. This feature reduces visible user information on the network.
  • Confidential client authentication: TLS 1.3 ensures client authentication is always confidential. This version of TLS removes the need for renegotiation and reduces round trips and CPU costs.

TLS 1.3 provides better security, privacy, and efficiency than TLS 1.2.

Geographic areas

Visit the Explore Feature Geography report for Microsoft Azure areas where this feature is planned or available.

Language availability

Visit the Explore Feature Language report for information on this feature's availability.

Additional resources

Server cipher suites and TLS requirements (docs)