Hi Roger,
Thanks for reaching out to Microsoft Q&A.
It can be a potential security risk if IMAP is not properly configured. It is essential to ensure that IMAP connections are encrypted using TLS (Transport Layer Security) to protect the data transmitted between the client and the server1.
Configuration Complexity: Enabling and configuring IMAP in Exchange Server requires several steps, this includes starting the IMAP4 services, configuring the services to start automatically, and setting up the IMAP4 settings for external clients.
It may be advisable to avoid enabling IMAP in Microsoft Exchange Server unless there is a specific need for it. If you decide to enable IMAP, make sure to follow best practices for configuration and security to minimize potential risks.
Reference documents- https://learn.microsoft.com/en-us/exchange/clients/mapi-mailbox-access?view=exchserver-2019
Please do not forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.