MC786329 - Exchange Online to retire Basic Auth for Client Submission (SMTP AUTH)

Primary Service: Exchange

Admin Impact
High
User Impact
Medium
Release Start
01 Mar 2026
Release End
30 Apr 2026

ChangePilot Summary:

  • Exchange Online is retiring Basic authentication for Client Submission (SMTP AUTH) in favor of more secure authentication methods.
  • Applications and devices will need to use OAuth for SMTP AUTH to send emails, as Basic auth will no longer be supported.
  • Administrators must update or replace systems currently using Basic authentication to prevent service disruptions.
  • Alternatives are provided for different use cases, including Microsoft 365 High Volume Email and Azure Communication Services Email.
  • The change aims to enhance security and protect customer data from vulnerabilities associated with Basic authentication.
Services
Exchange
Category
Unknown
Tags
User Adoption
Retirement

History

DateDescription
4/26/2024Item Added to Message Center
6/16/2025- The removal of Basic authentication from SMTP AUTH Client Submission has been delayed from September 2025 to between March 1st and April 30th, 2026. - Communication to tenants using Basic auth will now occur monthly starting July 2025, instead of a few times in the lead-up to the removal date. - The requirement to switch to OAuth or alternatives comes into effect at the new completion date of April 2026, instead of September 2025. - Clarification added that third-party solutions can also be used if Basic auth must be utilized beyond the transition.

Microsoft Message

Updated June 12, 2025: We have delayed the Basic Auth removal from SMTP AUTH Client Submission to begin March 1st 2026 and complete by April 30th 2026 in order to give customers more time to adopt alternatives. Expect no further delays beyond this date. Please review the information below for more details.

Updated October 18, 2024: We have updated the SMTP AUTH Clients Submission Report in the Exchange admin center, adding the Authentication Protocol column to show if Basic auth or OAuth is being used to submit email to Exchange Online. The data will build up over the next 90 days. Thank you for your patience.

Today, we are announcing that Exchange Online will permanently remove support for Basic authentication with Client Submission (SMTP AUTH) gradually beginning with a small percentage of submission rejections for all tenants on March 1st 2026 and reaching 100% rejections on April 30th 2026, (previously September 2025). After this time, applications and devices will no longer be able to use Basic auth as an authentication method and must use OAuth when using SMTP AUTH to send email.

Basic auth is a legacy authentication method that sends usernames and passwords in plain text over the network. This makes it vulnerable to credential theft, phishing, and brute force attacks. To improve the protection of our customers and their data, we are retiring Basic auth from Client Submission (SMTP AUTH) and encouraging customers to use modern authentication methods that are more secure.

When this will happen:

We will be making this change beginning March 1st, 2026, and completing April 30th, 2026 (previously September 2025).

How this will affect your organization:

The SMTP AUTH Clients Submission Report in the Exchange admin center has been updated to show if Basic auth or OAuth is being used to submit email to Exchange Online. Starting in July 2025, we will send monthly Message Center posts to tenants who are using Basic auth with Client Submission (SMTP AUTH) to alert them to the upcoming change.

Starting March 1st 2026 (previously September 2025) we will gradually start rejecting Basic Auth requests to the Client Submission (SMTP AUTH) endpoints, increasing to 100% rejection by the end of the April 2026.

The Client Submission (SMTP AUTH) endpoints in scope for this change are:

• smtp.office365.com

• smtp-legacy.office365.com

Once Basic auth is permanently disabled, any clients or apps connecting using Basic auth with Client Submission (SMTP AUTH) will receive this response:

• 550 5.7.30 Basic authentication is not supported for Client Submission.

What you need to do to prepare:

If your client supports OAuth, follow these steps: Authenticate an IMAP, POP or SMTP connection using OAuth

If your client doesn’t support OAuth and you must use Basic Auth with Client Submission (SMTP AUTH), you will need to switch to one of the following alternatives before April 2026, previously September 2025:

• If you are using basic authentication with Client Submission (SMTP AUTH) to send emails to recipients internal to your tenant, you can use Microsoft 365 High Volume Email. Please visit this site to learn more: Manage high volume emails for Microsoft 365 Public preview

• If you are using basic authentication with Client Submission (SMTP AUTH) to send emails to recipients internal and external to your tenant, you can use Azure Communication Services Email. Please visit this site to learn more: Overview of Azure Communication Services email

• If you have an Exchange Server on-premises in a hybrid configuration, you can use Basic auth to authenticate with the Exchange Server on-premises or configure the Exchange Server on-premises with a Receive connector that allows anonymous relay on Exchange servers. Please visit this site to learn more: Allow anonymous relay on Exchange servers

Regardless of the volume of email, if you must use Basic auth to send email with Exchange Online, then you must use one of the alternatives or a 3P solution.

We understand that this change requires some adjustments, but we believe that this is a necessary step to enhance the security and reliability of our email service and your data.