SMTP Basic Auth Retirement: Action Required for Scanners & Apps

SMTP Basic Auth Retirement: Action Required for Scanners & Apps

· by IDE Solutions · Updated

Short answer: Microsoft is retiring Basic Authentication for SMTP, so printers, ERP systems and website forms that send email through Microsoft 365 with a stored password will stop working. Microsoft has revised the timeline: nothing changes before December 2026, when SMTP AUTH Basic Authentication is switched off by default for existing tenants, and a final removal date is due to be announced in the second half of 2027. Check the Exchange Admin Center SMTP AUTH report, then move each sender to OAuth 2.0, direct send or a relay.

There is a printer in almost every German office that nobody thinks about until it stops working. It scans documents, sends them to a shared mailbox, and has been doing so without complaint for seven years. When Microsoft finally switches off Basic Authentication for SMTP, that printer will go silent, and the timing will feel like the worst possible moment.

This is not hypothetical. Microsoft began signalling this change in 2019. The timeline for tenants still using SMTP AUTH with Basic credentials was revised in January 2026: behaviour stays unchanged until December 2026, when the setting is disabled by default for existing tenants, while tenants created after that date will not have it available at all. If you have not acted yet, this guide tells you exactly what to check, what your options are, and what the consequences are of doing nothing. This is also one of the gaps our Microsoft 365 security assessments cover as standard.

Why basic auth for SMTP is a security problem

Basic Authentication sends your username and password with every email request, encoded in Base64. That is not encryption: Base64 can be decoded in seconds. Anyone intercepting the connection, or anyone who finds that password in a configuration file, can use your mail account without restriction.

The deeper problem is that Basic Auth cannot support Multi-Factor Authentication. A stolen password is enough. Microsoft's own data shows that over 99% of compromised accounts do not use MFA. Legacy authentication protocols are the direct enabler of most credential-based attacks the company investigates.

From a DSGVO perspective, this matters directly. Article 32 of the GDPR requires organisations to implement appropriate technical measures to protect personal data. Using an authentication method that is widely known to be exploitable, when modern alternatives exist, is difficult to defend in a breach investigation. German supervisory authorities (Datenschutzbehörden) have been increasingly specific about what "state of the art" means in security assessments. Basic Auth no longer qualifies. In practice, the risk is not primarily that your printer gets hacked: it is that a credential stored on that printer is also reused somewhere else, and that is where the real breach begins.

What gets affected, a practical checklist

Not everything that sends email through your Microsoft 365 tenant uses SMTP AUTH. The question is whether the sending application authenticates using a username and password combination rather than a certificate or OAuth token. Work through this list:

  • →Multifunction printers / copiers with Scan-to-Email: Kyocera, Ricoh, Canon, Konica Minolta, virtually all of them use stored credentials. Check the device's network settings for an SMTP username field.
  • →Line-of-business applications: ERP systems like SAP Business One, DATEV, Lexware, and many custom-built applications send order confirmations, reminders, and reports via SMTP. Each one is a potential failure point.
  • →Monitoring and alerting tools: Server monitoring software, UPS systems, and NAS devices often send alert emails. These are usually forgotten until something breaks.
  • →Older CRM and ticketing systems: On-premise installations of tools like SugarCRM or Redmine often have hardcoded SMTP credentials in configuration files.
  • →Website contact forms: PHP-based websites using PHPMailer or similar libraries connected to an Exchange Online mailbox via SMTP AUTH.

To find all SMTP AUTH usage in your tenant, go to Exchange Admin Center → Reports → Mail flow and filter for SMTP AUTH client submissions. The report shows you exactly which accounts have authenticated via legacy SMTP in the past 30 days.

SMTP AUTH is not the only legacy connection Microsoft is winding down on the same tenant. Many of those same backup jobs, CRM systems and scan-to-email printers also reach your mailbox through Exchange Web Services, which is being retired on its own schedule, so it is worth checking both at once rather than fixing one and getting caught by the other later.

Your three migration paths

There is no single right answer. The right path depends on whether the sending device or application can be updated to support modern authentication.

Option 1: OAuth 2.0 (Recommended for Applications)

Modern line-of-business applications and newer printer firmware versions support OAuth 2.0. The application registers as an app in Entra ID and exchanges a client secret for a short-lived token instead of storing a password. This is the most secure option and eliminates the risk of a stolen static credential. Implementation requires creating an app registration in Azure, granting it SMTP.Send permissions, and updating the application's mail configuration to use the token endpoint.

Option 2: Direct Send via Microsoft 365 (Good for Printers)

If the device only sends to recipients within your own domain, you can configure it to use the Microsoft 365 direct send endpoint (your tenant's MX record) without any authentication at all, provided you whitelist the device's IP address. No credentials are stored on the device. This works well for printers that send scans to internal mailboxes but cannot be used to send to external addresses like customers or suppliers.

Option 3: SMTP Relay via Azure or a Third-Party Service

For devices that need to send externally but cannot support OAuth 2.0, the cleanest solution is to route through an SMTP relay service. Azure Communication Services, SendGrid, or a dedicated on-premise relay server accepts the connection from the device using a static credential scoped to that relay only, not your main Microsoft 365 tenant. This keeps Exchange Online credentials out of legacy devices entirely.

Step by step: migrate a printer to direct send

This is the most common scenario and the fastest to implement. Here is what to do for a Ricoh, Kyocera, or similar MFP that only sends internally:

  1. Log into the device's web interface (usually at its local IP address).
  2. Navigate to Email / SMTP Settings.
  3. Change the SMTP server address from smtp.office365.com to your tenant's MX endpoint (visible in Microsoft 365 Admin Center → Domains → your domain → MX record).
  4. Set the port to 25 and disable authentication entirely.
  5. In Exchange Admin Center, navigate to Mail flow → Connectors and create an inbound connector that accepts mail from the printer's IP address.
  6. Send a test scan and verify delivery in the target mailbox.

The whole process takes about 20 minutes per device once you know what you are doing. The risk is forgetting a device, which is why the audit step matters so much.

What happens if you do nothing

At the end of December 2026 Microsoft will switch off SMTP AUTH Basic Authentication by default at the tenant level. Devices and applications still using it will start receiving authentication errors. Email flows stop. In a finance department, this means invoice PDFs stop reaching customers. In a logistics operation, dispatch notifications stop sending. Administrators will still be able to turn it back on after that date, but only until Microsoft names the final removal date, which is expected in the second half of 2027.

Beyond operational disruption, there is the security and compliance angle. If a breach occurs through a legacy SMTP account between now and the time you disable it, you will need to explain to your insurer and potentially to your Datenschutzbehörde why a known deprecated authentication method was still in use. That is not a comfortable position.

SMTP Migration & Microsoft 365 Support

We run a full SMTP AUTH audit across your tenant and every sending device or application we can identify. For each one, we recommend the right migration path and handle the technical implementation, whether that is configuring OAuth 2.0 app registrations in Entra ID, setting up direct send connectors, or deploying an SMTP relay for your legacy hardware.

Most projects are completed within one to two days of work. We document every change, test every flow, and leave you with a configuration record that satisfies both your IT team and any future compliance review.

This article was drafted with AI assistance and reviewed, edited and approved by IDE Solutions before publication. More in our Impressum.

More Articles