Migration guide

Microsoft 365 Basic-auth SMTP migration guide

Move SMTP-only devices and applications away from reusable Microsoft mailbox passwords without rushing the cutover.

Confirm the current Microsoft position

Microsoft guidance and timelines change. Start with the current Exchange Online documentation rather than a date copied from an old article, device manual, or internal ticket. Basic authentication is already disabled for many Exchange Online protocols, while Microsoft publishes separate current guidance for SMTP AUTH.

Inventory every sender

Record the client, owner, location, software or firmware version, mailbox, envelope sender, internal/external recipient need, volume, attachment size, network path, and current authentication method.

  • Printers and scanners
  • Websites and ecommerce plugins
  • NAS, backup, monitoring, and hypervisor alerts
  • Line-of-business and scheduled applications
  • Scripts and unattended jobs

Select a replacement method

Prefer native OAuth or direct Graph for maintained software. Consider Microsoft 365 SMTP relay when connector administration and network identity fit. Use a compatibility bridge for fixed SMTP interfaces that support STARTTLS and credentials but cannot complete OAuth.

Pilot and cut over

Choose a low-risk client, preserve rollback details, create separate credentials, test a real workflow, monitor the first days, then migrate in controlled groups. Revoke old credentials and document the new owner and recovery path.

Primary sources

Microsoft Learn: Basic authentication deprecation in Exchange Online ↗Microsoft Learn: Set up devices and applications to send using Microsoft 365 ↗Microsoft Learn: Microsoft Graph user sendMail ↗