[{"data":1,"prerenderedAt":200},["ShallowReactive",2],{"blog-smtp-auth-basic-authentication-retirement-timeline":3},{"id":4,"title":5,"author":6,"body":8,"cta":184,"date":185,"description":186,"eventid":184,"extension":187,"hideInRecent":188,"layout":184,"meta":189,"moment":184,"navigation":190,"outro":191,"path":194,"seo":195,"stem":198,"tags":184,"webcast":188,"__hash__":199},"content_en/blog/smtp-auth-basic-authentication-retirement-timeline.md","Basic Auth for SMTP Didn't End in April",[7],"Sendman Team",{"type":9,"value":10,"toc":175},"minimal",[11,15,18,22,27,30,33,37,56,60,68,71,74,77,86,90,93,96,100],[12,13,14],"p",{},"If you've read that Microsoft switched off Basic Authentication for SMTP AUTH on April 30, you're in good company. Plenty of printer dealers and IT service providers still say so on their websites, and for a few months it was even true, in the sense that it was the plan. In January Microsoft threw that plan out. The date that replaced it is later and a good deal softer, which is good news right up to the point where someone reads it as permission to stop working on it.",[12,16,17],{},"The back and forth explains a lot, so here's the short version. When Microsoft turned off Basic Auth for POP, IMAP, EWS and the rest of Exchange Online in October 2022, SMTP AUTH was the one protocol it left alone, with the memorable line \"We are not touching SMTP AUTH and are done turning it off for now.\" In April 2024 it set a date anyway, September 2025, which later became a gradual rejection starting on March 1, 2026 and reaching every submission on April 30. On January 27 came the post that replaced all of it, and Microsoft's reasoning is worth quoting: \"many customers continue to face real challenges modernizing legacy email workflows\". Anyone who has asked a copier vendor about OAuth knows exactly what that sentence means.",[19,20],"at-a-glance",{":items":21},"[{\"label\":\"Until December\",\"value\":\"Nothing changes, Basic Auth for SMTP AUTH works as it does today\"},{\"label\":\"End of December 2026\",\"value\":\"Disabled by default for existing tenants, and admins can turn it back on\"},{\"label\":\"New tenants\",\"value\":\"Tenants created after December 2026 don't get it at all; OAuth is the supported method\"},{\"label\":\"Second half of 2027\",\"value\":\"Microsoft announces the date it goes away for good\"}]",[23,24,26],"h2",{"id":25},"what-disabled-by-default-means-for-you","What \"Disabled by Default\" Means for You",[12,28,29],{},"For existing tenants there's still a way back. At the end of December Microsoft turns Basic Auth for SMTP AUTH off, and an admin can turn it on again. The announcement doesn't say which switch that will be, so the honest expectation is this: one morning around New Year the scanners stop sending, and someone who knows where to look fixes it in a few minutes. That sounds harmless until you picture the last week of December, with half the IT team on holiday and accounting trying to get the year-end statements out of the ERP.",[12,31,32],{},"And turning it back on only buys time until Microsoft names the final date, which it plans to do in the second half of 2027. After that there's nothing left to switch. Tenants created after December never get Basic Auth for SMTP in the first place, which matters more than it sounds if a tenant migration or a carve-out is on next year's list: the new tenant will refuse logins the old one accepted without complaint.",[23,34,36],{"id":35},"find-out-who-still-uses-it","Find Out Who Still Uses It",[12,38,39,40,44,45,44,48,51,52,55],{},"You probably have a rough idea, and it's probably incomplete. The Exchange admin center has a report for exactly this, under ",[41,42,43],"strong",{},"Reports"," > ",[41,46,47],{},"Mail flow",[41,49,50],{},"SMTP AUTH clients",". It lists every sender address that submits mail over SMTP AUTH, shows whether it signs in with Basic Auth or OAuth and which TLS version it speaks, and goes back up to 90 days. The sign-in logs in Microsoft Entra ID, filtered to the client app ",[41,53,54],{},"Authenticated SMTP",", tell the same story from the identity side, including the IP addresses the logins come from. Between the two you'll usually find the copier on the third floor, a monitoring server that predates everyone on the team, and one application nobody admits to owning.",[23,57,59],{"id":58},"where-each-device-can-go","Where Each Device Can Go",[12,61,62,63,67],{},"Scripts and your own applications are the easy part. Microsoft Graph and cmdlets like ",[64,65,66],"code",{},"Send-MgUserMail"," send mail with modern authentication, and rewriting a script is an afternoon's work.",[12,69,70],{},"Devices whose vendor has shipped OAuth support need a firmware update and a bit of Entra configuration, and then they're done. Everything else is where it gets slow. Tony Redmond put it politely: \"I hear of many blank looks when customers ask vendors about their plans to upgrade devices to support OAuth for client submissions.\"",[12,72,73],{},"If a device only ever mails people inside the company, High Volume Email is worth a look. It has been generally available since the end of March, costs $42 per million recipients and, somewhat against the direction of everything else in this post, keeps accepting Basic Auth on its own endpoint until September 2028. The limits are real, though: internal recipients only, at most 50 recipients and 10 MB per message, and nothing ever reaches a supplier or a customer.",[12,75,76],{},"For mail that has to leave the company, Microsoft points to Azure Communication Services. It speaks SMTP, but the password is the client secret of an Entra app registration, and client secrets expire. Somebody will have to change the scanner's password on a schedule, which is exactly the kind of task that gets remembered the day after it was due.",[12,78,79,80,85],{},"And then there are the devices that can't do any of that, which in most buildings is more of them than anyone would like. They need a relay that accepts the login they already have. An on-premises Exchange server does that job, as long as Exchange Online still takes its mail, and that has turned into ",[81,82,84],"a",{"href":83},"/blog/exchange-online-blocks-outdated-exchange-servers","a story of its own this month",".",[23,87,89],{"id":88},"dont-wait-for-the-switch","Don't Wait for the Switch",[12,91,92],{},"The new timeline gives you more than a year until the final date, but it doesn't give you a quiet December. If you open the report this month, you can move the easy cases in October, sort out the difficult ones in November, and spend the last week of the year the way it was meant to be spent.",[12,94,95],{},"We built Sendman for that last group, the devices that will never learn OAuth.",[23,97,99],{"id":98},"sources","Sources",[101,102,103,114,122,130,137,144,152,159,166],"ul",{},[104,105,106,107,113],"li",{},"Microsoft Exchange Team: ",[81,108,112],{"href":109,"rel":110},"https://techcommunity.microsoft.com/blog/exchange/updated-exchange-online-smtp-auth-basic-authentication-deprecation-timeline/4489835",[111],"nofollow","Updated Exchange Online SMTP AUTH Basic Authentication Deprecation Timeline",", January 27, 2026",[104,115,106,116,121],{},[81,117,120],{"href":118,"rel":119},"https://techcommunity.microsoft.com/blog/exchange/exchange-online-to-retire-basic-auth-for-client-submission-smtp-auth/4114750",[111],"Exchange Online to retire Basic auth for Client Submission (SMTP AUTH)",", April 15, 2024, with later updates",[104,123,124,125],{},"Microsoft Learn: ",[81,126,129],{"href":127,"rel":128},"https://learn.microsoft.com/en-us/exchange/monitoring/mail-flow-reports/mfr-smtp-auth-clients-report",[111],"SMTP AUTH clients report in the new EAC in Exchange Online",[104,131,124,132],{},[81,133,136],{"href":134,"rel":135},"https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/authenticated-client-smtp-submission",[111],"Enable or disable SMTP AUTH in Exchange Online",[104,138,124,139],{},[81,140,143],{"href":141,"rel":142},"https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365",[111],"How to set up a multifunction device or application to send email using Microsoft 365",[104,145,106,146,151],{},[81,147,150],{"href":148,"rel":149},"https://techcommunity.microsoft.com/blog/exchange/high-volume-email-continued-support-for-basic-authentication--other-important-up/4411197",[111],"High Volume Email: Continued support for Basic Authentication & other important updates",", May 6, 2025",[104,153,124,154],{},[81,155,158],{"href":156,"rel":157},"https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/high-volume-mails-m365",[111],"Manage High Volume Email for Microsoft 365",[104,160,124,161],{},[81,162,165],{"href":163,"rel":164},"https://learn.microsoft.com/en-us/azure/communication-services/quickstarts/email/send-email-smtp/smtp-authentication",[111],"Set up SMTP authentication for sending emails with Azure Communication Services",[104,167,168,169,174],{},"Office 365 for IT Pros: ",[81,170,173],{"href":171,"rel":172},"https://office365itpros.com/2026/01/29/smtp-auth-basic-retirement/",[111],"SMTP AUTH Client Submission Retirement Delayed",", January 29, 2026",{"title":176,"searchDepth":177,"depth":177,"links":178},"",2,[179,180,181,182,183],{"id":25,"depth":177,"text":26},{"id":35,"depth":177,"text":36},{"id":58,"depth":177,"text":59},{"id":88,"depth":177,"text":89},{"id":98,"depth":177,"text":99},null,"2026-09-12T09:20:00+02:00","If you've read that Microsoft switched off Basic Authentication for SMTP AUTH this spring, you read a plan Microsoft scrapped in January. The real date is the end of December, and it's a softer one than the old, for now.","md",false,{},true,{"headline":192,"copy":193},"Keep the Logins, Lose the Deadline","Sendman is the SMTP relay for Microsoft 365, built for the devices that will never learn OAuth. They keep the logins they have, validated against Microsoft Entra ID – no app registration, no consent, nothing to change in your tenant – and their mail goes into Exchange Online without SMTP AUTH, unaffected by Microsoft's Basic Authentication retirement.","/blog/smtp-auth-basic-authentication-retirement-timeline",{"title":196,"description":197},"SMTP AUTH Basic Auth Retirement: The Real Timeline","Microsoft scrapped the April 2026 cut-off. SMTP AUTH Basic Authentication is disabled by default at the end of December 2026. What changes, and what to do.","blog/smtp-auth-basic-authentication-retirement-timeline","YhasNFKlRj3K_zEFjApVp-xS0Iaiq5nF55Qs6dXVkaM",1789226271722]