Migration guide

Inventory devices and applications that send email

Create an actionable dependency inventory before changing Microsoft 365 SMTP authentication.

Search beyond the obvious mailboxes

Mailbox sign-in reports are useful but not a complete inventory. Ask infrastructure, facilities, finance, ecommerce, development, and application owners which systems generate scans, alerts, forms, invoices, reports, and scheduled messages.

Capture decision-making fields

An inventory should be detailed enough to select a replacement and contact an owner during cutover.

  • System, version, physical or network location, and business owner
  • Current SMTP host, port, TLS mode, and authentication type
  • Mailbox and exact envelope sender
  • Internal or external recipients and approximate volume
  • Message and attachment sizes
  • Static public IP or certificate availability
  • OAuth, Graph, or custom SMTP capabilities
  • Test procedure, criticality, maintenance window, and rollback owner

Prioritize by risk

Migrate non-critical and easily observed clients first. Treat password resets, orders, backup failures, security alerts, and regulated workflows as separate higher-risk groups with explicit acceptance tests.

Primary sources

Microsoft Learn: Basic authentication deprecation in Exchange Online ↗Microsoft Learn: Set up devices and applications to send using Microsoft 365 ↗Microsoft Learn: Microsoft Graph user sendMail ↗