● Microsoft Exchange Online · Deadline December 2026

Microsoft is ending SMTP Basic Auth.
Prepare now, not later.

Last updated: 29 September 2026 (timeline as per Microsoft's announcement of 27 January 2026)

Microsoft has officially announced that SMTP authentication via username and password (Basic Auth) in Exchange Online will be disabled by default at the end of 2026. Printers, scanners, ERP systems and other legacy applications still sending via SMTP with a password will stop working with nobody having changed a thing. Administrators can switch the authentication back on once more, but that only moves the date: Microsoft intends to announce the final shutdown date in the second half of 2027. There is time for an orderly migration if you start today.

Background

What is happening?

Microsoft has been phasing out legacy authentication methods in Exchange Online for several years. After other protocols such as IMAP, POP and EWS were affected by this change in 2022, SMTP AUTH now follows on its own, later timeline.

With SMTP Basic Auth, an application sends its username and password with every connection, only Base64-encoded, which offers no real protection. An attacker who obtains these credentials can silently send emails on behalf of the organisation. OAuth2 (Modern Authentication) solves this with short-lived tokens issued specifically for a single application.

Common confusion: In October 2022, Microsoft disabled Basic Auth for IMAP, POP, EWS and other protocols. SMTP AUTH ran on a separate, later schedule. If you are already experiencing issues today, it is most likely because SMTP AUTH was manually disabled in your tenant's security settings, or a Conditional Access policy is blocking legacy auth.

Multifunction printer · Send log
08:14:02Connecting to smtp.office365.com:587
08:14:02220 Microsoft ESMTP MAIL Service ready
08:14:02STARTTLS, TLS 1.2
08:14:03AUTH LOGIN scanner@example.com
08:14:03535 5.7.139 Authentication unsuccessful, basic authentication is disabled.
08:14:03Scan to email failed (error 535)
With SMTPly: the device sends to the local relay, no password at all.

The timeline

Microsoft has split the deprecation of SMTP AUTH Basic Auth into several phases:

  1. Todayto Dec 2026
    You are here

    Nothing changes yet

    In existing Exchange Online tenants, SMTP AUTH with Basic Auth keeps working as before, as long as it is enabled in the tenant settings and no Conditional Access policy blocks it.

  2. End of Dec2026

    Disabled by default

    In existing tenants, SMTP AUTH with Basic Auth is disabled by default. Administrators can still turn it back on for now. That only postpones the problem until Microsoft sets the final end date.

  3. From Jan2027

    New tenants get OAuth2 only

    Tenants created after December 2026 no longer get SMTP AUTH with Basic Auth at all. Anyone setting up a new tenant from then on needs OAuth2 from day one.

  4. H22027

    Microsoft names the final date

    In the second half of 2027, Microsoft plans to announce when Basic Auth for SMTP disappears for good. From then on it can no longer be switched back on, and OAuth2 is the only way left.

Source: Microsoft Exchange Team Blog, Jan 27, 2026 · Last reviewed: Sep 27, 2026

Which error does your device show?

535 5.7.139 Authentication unsuccessful, basic authentication is disabled: SMTP AUTH is turned off for the tenant or the mailbox, or a Conditional Access policy blocks the sign-in. This can already happen today.

550 5.7.30 Basic authentication is not supported for Client Submission: Exchange Online no longer offers Basic Auth for SMTP AUTH. Expect this message once the shutdown applies to your tenant.

Either way, the fix is a route without password sign-in at Microsoft, for example a local relay.

Why act now anyway? The deadline sounds comfortable, but in practice the switch takes longer than expected: app registration, internal approvals, testing with every device and application, maybe delivery times for new hardware. Those who start early switch over in an orderly way. Those who wait until November 2026 switch over under pressure.

Which systems are affected?

Any application or device that sends email through Exchange Online via SMTP with a username and password is affected:

Printers & scanners

Multifunction devices with scan-to-email from Kyocera, Ricoh, Canon, Konica Minolta, HP and Xerox, typically without OAuth2 support in firmware.

ERP & business software

Sage, Lexware, Infor, older SAP installations, Microsoft Dynamics NAV (older versions), and many other systems sending invoices and order confirmations via SMTP.

Hotel software & PMS

Oracle Fidelio Suite 8, Opera, Protel, Sihot and other property management systems sending booking confirmations and invoices via SMTP.

Monitoring & backup

PRTG, Zabbix, Check_MK, Veeam, Backup Exec and similar tools that send alerts and reports via SMTP.

CRM & DMS

Document management systems and CRM software that send notifications, workflow emails and reports via SMTP.

Custom applications

In-house .NET, Python, PHP and PowerShell scripts and automations that use SMTP for email delivery.

What are the options?

Upgrade the device or software to OAuth2

If your device or software supports OAuth2 or a firmware update is available, you can switch directly to Modern Authentication without needing a relay.

Challenge: Many devices will never receive an update. Configuration is required per device. Often not possible for older multifunction printers.

IP-based SMTP relay via Exchange Online connector

Microsoft allows email delivery without authentication if the sender's IP address is whitelisted in an Exchange connector. No OAuth2 required.

Challenge: Requires a static, public IP address, access to the Exchange Admin Center, and careful configuration. Not suitable for dynamic IP addresses.

Cloud-based SMTP relay service

Third-party providers such as SendGrid or Mailjet accept emails via SMTP and forward them on. No server infrastructure required.

Challenge: Email content (invoices, contracts, patient data) passes through external servers. Monthly costs. Potentially problematic for privacy-sensitive industries.

Microsoft High Volume Email (HVE)

A separate Microsoft sending service for Exchange Online (smtp-hve.office365.com). According to Microsoft it accepts SMTP with username and password until September 2028, OAuth2 only after that.

Challenge: delivers to recipients inside your own organization only. Not suitable for invoices, orders or scans sent to customers and suppliers, and Basic Auth ends here too.

Azure Communication Services Email

Microsoft's sending service in Azure. It offers SMTP access where a device signs in with the credentials of an Entra app, and it delivers to external recipients as well.

Challenge: Azure subscription billed per message, your domain has to be verified in Azure, devices need SMTP sign-in with TLS. Mail bypasses the Microsoft 365 mailbox, so there is no copy in Sent Items.

Frequently asked questions.

What is SMTP Basic Auth and why is Microsoft removing it?

SMTP Basic Auth is the method of authenticating with an SMTP server using a username and password. With every connection, the credentials are transmitted only Base64-encoded — which offers no real protection and can easily be intercepted.

Microsoft is removing this method because it does not support multi-factor authentication (MFA) and is vulnerable to password spraying and credential stuffing attacks. OAuth2 uses short-lived tokens issued for a specific application instead of transmitting the actual password.

When exactly is Microsoft disabling SMTP Basic Auth?

Microsoft is planning the shutdown in two phases:

  • End of 2026: SMTP AUTH with Basic Auth will be disabled by default for existing tenants. Administrators can still re-enable it manually after that point.
  • Second half of 2027: Microsoft will announce the final shutdown date. With that date, manual re-enabling goes away too.

Tenants created after December 2026 will not get SMTP AUTH with Basic Auth at all. In many recent tenants SMTP AUTH is already turned off by default today, but it can still be turned on until the end of 2026.

Why is my printer or ERP system already unable to send emails?

There are several possible causes, even though the final shutdown has not yet taken place:

  • Tenant settings: Your administrator has manually disabled SMTP AUTH with Basic Auth for the tenant or the specific mailbox.
  • Conditional Access: Security policies block legacy authentication without explicitly exempting SMTP AUTH.
  • New tenant: In more recent Microsoft 365 tenants, SMTP AUTH is turned off by default and has to be enabled first.
  • Confusion with 2022: The shutdown of other protocols (IMAP, POP, EWS) in October 2022 is sometimes incorrectly applied to SMTP AUTH.
Do I need to replace my printers, scanners or ERP software?

In most cases, no. Your devices and applications can continue sending via classic SMTP — just not with a password directly to Microsoft 365. With a local SMTP relay like SMTPly on your Windows server, almost nothing changes in your devices' configuration: you simply enter the Windows server's IP address as the SMTP host.

I have many devices from different manufacturers. Do I need to reconfigure each one?

With a central SMTP relay you configure the Windows server once. All devices and applications then connect to this single server — regardless of manufacturer or model. The change per device is limited to entering the new server IP address as the SMTP host, which typically takes a few minutes.

Does SMTPly work with my ERP, hotel system or industry-specific software?

Yes — SMTPly works with any software that can send email via SMTP. This includes Sage, Lexware, Infor, older SAP versions, Oracle Fidelio Suite 8, Opera, Protel, PRTG, Veeam and custom applications in .NET, Python, PHP or PowerShell.

Requirement: the software must support SMTP on port 25 or 587. No password authentication is required by SMTPly — it simply accepts open connections from your server's IP.

Is my email content safe when it goes through SMTPly?

Yes. SMTPly runs exclusively on your own Windows server. Email content travels directly from your server to Microsoft 365 — no third-party server is in between. OAuth2 credentials are stored DPAPI-encrypted. A message stays in the protected queue on your server only until Microsoft 365 has accepted it and is deleted afterwards. Messages that fail permanently are kept for 14 days for troubleshooting. The log only records details such as sender, recipient and subject, never the body or attachments.

For industries with strict data protection requirements (healthcare, law firms, public authorities, hospitality) this is a significant advantage over cloud relay services.

How complex is the SMTPly setup?

The server is usually set up in under ten minutes:

  1. Connect to Microsoft 365: The wizard signs you in with Microsoft and you consent to the Mail.Send permission as an administrator. No manual app registration is required; if you prefer to create it yourself in the Entra admin center, you still can.
  2. Reconfigure devices (approx. 1–2 min. per device): Change the SMTP server address to the Windows server's IP.
  3. Send a test mail: Result immediately visible in the dashboard.
What does SMTPly cost?

SMTPly starts at €149 one-time per Windows server — no subscription, no recurring costs. Starter (€149) covers one Microsoft 365 tenant, Business (€249) up to 5 tenants, Enterprise (€499) up to 25 tenants including syslog, REST API and sandbox mode. A 14-day fully functional trial is available at no cost. Compare editions →

What happens if I do nothing until end of 2026?

From end of 2026, SMTP AUTH with Basic Auth will be disabled by default for your tenant. All printers, scanners and applications that have been sending via SMTP with a password will stop sending, without anyone having changed a thing. As an administrator you can switch it back on once more, which buys time but is not a fix: Microsoft intends to announce the final shutdown date in the second half of 2027, and new tenants no longer get the authentication at all.

Prepare now, not in December 2026

SMTPly is usually up and running in under ten minutes and makes your entire SMTP infrastructure future-proof: no hardware replacement, no cloud, no monthly costs.

from €149 one-time · 1 license per server · unlimited number of devices · Business €249 · Enterprise €499