Open the device mail settings

Connect a printer or scanner without storing your Microsoft password. Look for E-mail, Scan to E-mail, SMTP server, or outgoing mail in the administrator interface.

Device details that matter

Choose STARTTLS or Explicit TLS, not implicit SSL on port 465. Set the printer clock and DNS correctly: certificate validation often fails when the clock is wrong or the device uses a hard-coded IP.

Use the connected mailbox for both authentication and sender. Start with one recipient and a small PDF, then test address-book and multi-page scans after basic delivery works.

Plan for older firmware

Older devices may advertise TLS while supporting only obsolete cipher suites. Update firmware first. If STARTTLS negotiation still fails, inspect the device event log rather than weakening transport security.

Limit access to the printer administration page and avoid exporting its configuration with credentials included. Name the connection after the physical device so it can be identified and revoked quickly when the printer is replaced.

Before you save

Use the connected Microsoft 365 address as the sender. Store the generated password securely; it cannot be displayed again.

Send a small test message to an address you control. Confirm delivery before enabling production notifications.

If the test fails

Check that port 587 is permitted by the network, STARTTLS is enabled, and no spaces were copied into the credentials.

Never share passwords or message content. Revoke and recreate the connection if the password is lost.