Exchange OnlineSecurityMicrosoft Retirement

SMTP AUTH Basic Authentication Is Being Retired in Exchange Online

Regroove IT Consulting2 min read427 words

If an application, copier, scanner, or line of business system in your organization sends email through Exchange Online using SMTP AUTH with a plain username and password, that setup is on a real, published retirement timeline, and it is worth checking now rather than after something quietly stops sending mail.

What is actually changing

SMTP AUTH Client Submission using Basic Authentication, meaning a stored username and password rather than a modern, token based sign in, is being disabled by default across existing Microsoft 365 tenants at the end of December 2026. Administrators will still be able to re-enable it manually for a period after that if genuinely needed, but any tenant created after that date will not have the option available at all, with OAuth as the only supported method going forward. Microsoft has said it will announce a final, permanent removal date in the second half of 2027.

What breaks if you do nothing

Once Basic authentication is disabled on your tenant, anything still configured to send mail through SMTP AUTH with a stored password will start failing with a specific error, "550 5.7.30 Basic authentication is not supported for Client Submission," rather than failing silently. This most commonly affects scan to email on office copiers, older line of business applications with a hardcoded SMTP relay setting, monitoring systems, and scripts that send notification emails.

What to switch to instead

Microsoft's recommended paths depend on what you are actually sending and to whom. For internal only notification email at real volume, Microsoft's High Volume Email service is built for exactly that scenario. For mail going to both internal and external recipients, Azure Communication Services Email is the supported modern alternative. Devices and applications that support OAuth directly should be reconfigured to use it rather than a stored password, which is also the more secure option regardless of this deadline.

Why Microsoft is doing this

Basic authentication sends credentials in a form that is far easier to intercept, phish, or brute force than modern token based authentication, and it has been a disproportionately common entry point for account compromise. Retiring it tenant wide closes that off completely rather than relying on individual users and applications to be configured securely.

If you are not sure what in your environment is still relying on SMTP AUTH with a stored password, that is worth auditing before the default changes rather than after. Our Microsoft 365 and Modern Work team can help you find it and migrate it properly. Get in touch if you want a hand.

Regroove IT Consulting

Microsoft Solutions Partner specializing in Managed IT Services and Modern Work, covering Microsoft 365, Teams, SharePoint, Power Platform, and Azure. Helping organizations everywhere get lasting value from their Microsoft investment since 1993.

About Regroove →

Need help with your Microsoft environment?

We work with organizations everywhere. Tell us where you are and what you're trying to solve.

Talk to Regroove