Exchange Online SMTP Basic Auth: Find What Still Sends Mail
Anything that signs in to a Microsoft 365 mailbox with a username and password to send mail relies on SMTP AUTH basic authentication. And the only reliable way to find all of it? A written inventory of every device, plugin and app that sends email. The first announced cut-off passed this spring without a shutdown, because Microsoft moved the deadline. The work hasn’t changed, though.
Table of Contents
What changed in the SMTP AUTH basic authentication timeline?
Short version: Microsoft postponed the retirement, and nothing changes until December 2026. The original plan in the Exchange Team retirement announcement was to start rejecting a small share of submissions on 1 March 2026 and reach 100% rejections on 30 April 2026. The same post gives the reason: Basic auth sends usernames and passwords in plain text, which exposes them to credential theft, phishing and brute force attacks.
Then, on 27 January 2026, the company published an updated deprecation timeline post. At the end of December 2026 the method is switched off by default for existing tenants, although administrators can still enable it. Extra runway, not a cancellation. Apps and devices will still need OAuth for SMTP or another supported route.
What still sends email with a mailbox password?
In a small company it’s usually the same suspects. Use these categories as the skeleton of your email sending inventory:
- printers and scanners with scan to email
- website form plugins
- invoicing and shop tools
- CRM or help desk notifications
- scripts and scheduled tasks
- monitoring or backup alerts
Scanner and app email sending is easy to miss. Note separately every shared mailbox password stored in an old device. Those credentials tend to outlive the hardware.
How to find Exchange Online SMTP AUTH senders in your tenant
You need two things here: Microsoft’s own report and a manual walk through devices and app settings. The SMTP AUTH Clients Submission Report in the Exchange admin center shows whether Basic auth or OAuth is used to submit email. But it only tells you which mailboxes send, not which machine or program sits behind them. So match each sending account to a real thing.
Then check by hand. Outgoing mail settings in printer panels, the website admin, invoicing and shop tools, plus saved credentials in scripts. And ask colleagues which tools send messages on their behalf. Marketing or support often set up Microsoft 365 email from apps without telling whoever looks after IT.
Build the inventory: one row and one owner per sender
Nothing fancy. A simple table with one line per sender and a named person responsible is enough. Record these columns:
- what sends
- which mailbox or account it uses
- what the messages are for
- who owns it
- vendor contact
- supported sending method
- test date
- status
An owner is a person, not a department. Without one, the row will not move before the deadline. Rank entries by business impact: invoices and customer notifications go ahead of scan to email. It also helps to tie the sheet to a quarterly user access review, so sending accounts get checked on the same rhythm as people’s access.
Ask every vendor about OAuth for SMTP or another supported method
Put the same four questions to every vendor, and ask for the answers in writing: does the product support OAuth for SMTP AUTH, from which version or firmware, what is the alternative if it does not, and what do you have to change on your side.
Business apps deserve the same scrutiny as hardware, because their failures are silent. Ticket notifications that stop arriving lead to a growing support ticket backlog before anyone notices. Broken sequences halt the automated lead nurturing emails that sales counts on. Running the EpicCRM help desk with tickets from email on the Business plan, or its Mailcraft integration? Send those questions to both providers as well.
For senders that must keep Basic auth, Microsoft names three options: High Volume Email for Microsoft 365, Azure Communication Services for Email, or Exchange Server on-premises in a hybrid configuration.
Test before December and remove old passwords
Switch and test each sender well ahead of the end of December 2026, then clean up the credentials left behind. Don’t count on an admin re-enabling the old method once the default changes: according to Microsoft’s revised SMTP AUTH schedule, that is a temporary option, and the final removal date is to be announced in the second half of 2027.
Work through one sender at a time and send a real message. Afterwards, remove shared mailbox passwords from retired or reconfigured devices and change any password that sat in an old printer or script. Update the status column after each test.
The SMTP AUTH basic authentication deadline moved, but the job did not shrink. The inventory, the owners, the vendor answers and the tests are what you should finish now, while a failed test is still an inconvenience and not an outage.
FAQ
Is Basic auth for SMTP already turned off in Exchange Online?
No. This spring the behaviour is unchanged, and senders using a mailbox password keep working. Under the revised timeline, the default changes at the end of the year for existing tenants.
Can an admin turn Basic auth back on after it is disabled by default?
Yes, for existing tenants under the revised timeline. But it is a stopgap before final removal, so use it to finish the migration.
What if my printer or scanner does not support OAuth?
Ask the vendor about a firmware update or another supported sending method. If neither exists, look at the alternatives Microsoft names for senders that must keep Basic auth. And where there is no path at all, plan to replace the device.

