---
title: Warning 'mysql_native_password' authentication type is disabled by default in MySQL 8.4
url: https://calvin.my/posts/warning-mysql_native_password-authentication-type-is-disabled-by-default-in-mysql-8-4
published: 2026-03-26
updated: 2026-09-16
category: Operations
tags:
- MySQL
- AWS
- RDS
summary: Upgrading from MySQL 8.0 to 8.4 may warn that accounts still use the deprecated mysql_native_password authentication method, which is disabled by default in 8.4 and planned for removal. The post recommends first updating to the latest 8.0 release, identifying affected users, migrating them to caching_sha2_password, notifying users if passwords change, and testing each updated connection.
---

# Warning 'mysql_native_password' authentication type is disabled by default in MySQL 8.4

## The Issue

When upgrading from MySQL v8.0 to v8.4, you will get a warning message such as the following:

```bash
4) Check for deprecated or invalid user authentication methods.
	Some users are using authentication methods that may be deprecated or removed, please review the details below.
	username@% - The following users are using the 'mysql_native_password' authentication method which is deprecated as of MySQL 8.0.34 and will be removed in a future release.
Consider switching the users to a different authentication method (i.e. caching_sha2_password).
The 'mysql_native_password' authentication type is disabled by default in MySQL 8.4, but can still be enabled by setting loose_mysql_native_password=ON.
```

* * *

## The Fix

1. (Recommended) Upgrade to the latest minor version of 8.0.x first.

2. Then, obtain a list of impacted users by running this query.

   ```sql
   SELECT user, host, plugin FROM mysql.user;
   ```

3. Those users who have their plugin value equal to `mysql_native_password` require a change.

4. For each of these users, run the following query with their corresponding password to change the plugin. If you change the password here, make sure you also <u>inform the corresponding user</u> to update on the client side.

   ```sql
   ALTER USER 'the_username'@'%' IDENTIFIED WITH caching_sha2_password BY 'the_password';
   ```

5. Test the connection to the database with the username and password.
