Microsoft is continuing to enhance security and will be removing one of the last remaining outdated login methods in Exchange Online in the coming months: Basic Authentication for SMTP AUTH Client Submission. Many companies still use this method for automated processes – often unknowingly and deeply integrated into business processes.
By phasing out Basic Authentication for client submission (SMTP AUTH), Microsoft is continuing its multi-year plan to improve cloud security. The timeline has since been adjusted: SMTP AUTH Basic Authentication will remain available for existing Exchange Online tenants until the end of December 2026. After that, the feature will be disabled by default—with complete removal to follow at a later date.
What may sound at first glance like a minor technical change can have a direct impact on business processes—for example, if invoices, alerts, or status notifications can no longer be sent via email. For companies, now is therefore the right time to identify affected systems and plan the transition in a structured manner.
Basic Authentication is now a fundamental security risk. Usernames and passwords are only transmitted in Base64-encoded form for each connection – an open gateway for phishing, brute force attacks and credential stuffing.
Even more critically, Basic Auth undermines modern security concepts because it does not support multi-factor authentication (MFA). As long as a tenant accepts Basic Auth, a backdoor remains open – even if strong security mechanisms have already been implemented elsewhere.
Microsoft is therefore following a clear line: away from password-based logins, towards zero trust and modern, token-based authentication using OAuth 2.0. OAuth 2.0 significantly reduces the risk of stolen passwords, can be controlled granularly and forms the basis for stable security controls. Basic Authentication has already been disabled for other protocols; with SMTP AUTH, one of the last remaining exceptions is now being removed.
Imagine checking into a hotel. Instead of receiving the master key for the building (password/basic authentication), you are given a key card (token). This card only opens your room and perhaps the fitness area – and only for the duration of your stay. If the card is stolen, the vault remains secure.
This is exactly how OAuth 2.0 works: an application (e.g. a scanner) does not receive your password, but a time-limited access token. This token only allows clearly defined actions (e.g. ‘send email’) and can be revoked at any time without having to change the main password. This significantly increases security, keeps the login process compatible with modern methods such as MFA, and noticeably reduces the risk of compromised access data.
To ensure that the transition does not take place without adequate preparation, Microsoft is already providing administrators with tools to identify affected systems. An updated report for SMTP AUTH Client Submission has been available in the Exchange Admin Centre since October 2024. This report shows which devices and applications are still using Basic Authentication. For administrators, this serves as a starting point for gaining visibility and compiling a complete list of all affected systems.
Microsoft has since adjusted the originally communicated shutdown date. Until the end of December 2026, the behaviour of SMTP AUTH Basic Authentication will remain unchanged for existing Exchange Online tenants. Systems that currently still send emails via Microsoft 365 using Basic Authentication will therefore continue to function for the time being. However, this additional time should not be seen as a green light, but rather as an opportunity to thoroughly identify affected applications, multifunction devices, scanners or scripts and to plan suitable alternatives.
At the end of December 2026, SMTP AUTH Basic Authentication will be disabled by default for existing tenants. Administrators can re-enable the feature for the time being if necessary. For tenants created after December 2026, Basic Authentication will no longer be available by default; OAuth will then be the supported authentication method. In the second half of 2027, Microsoft intends to announce the final date for the complete removal of SMTP AUTH Basic Authentication.
In theory, switching to OAuth 2.0 is easy. In practice, however, it often fails due to the existing infrastructure in the background. While laptops and smartphones have long been modernised, printers, scanners, older ERP systems and scripts continue to stubbornly communicate using usernames and passwords.
Typical examples include a scanner that sends delivery notes to a central mailbox address, an ERP system that automatically sends order confirmations by email, or a monitoring tool that sends alerts to the on-call service in the event of malfunctions. For many of these devices, there are no longer any current firmware updates available. A complete hardware or system replacement would be technically possible, but often disproportionate in economic terms.
That is why a systematic analysis of existing connections is the most important first step. If you know early on where basic authentication is still in use, you can carry out the changeover in a planned, risk-aware manner and without time pressure.
Companies should proceed in a structured manner:
The strategy should be two-pronged.
It is tempting to put off dealing with this issue. However, those who delay the transition risk automated email delivery failures: invoices will remain stuck in the ERP, scan-to-mail functions will fail, and alerts from monitoring systems will no longer reach anyone. Individual disruptions can quickly become a business risk – with consequences for efficiency, customer satisfaction and, in some circumstances, compliance. This means that the changeover is not just a technical detail, but a business-critical project.
As a bridging technology, MTF offers an SMTP mail relay service from the MTF Business Cloud. The service is specially designed for scenarios in which systems that do not support modern authentication must continue to operate but still need to send emails reliably.
The relay service runs in our highly available Swiss cloud environment, is optimised for sending from applications and devices, and can be integrated into existing security and compliance requirements in a controlled manner. Companies retain control over senders, routing and policies, while the technical complexity of connecting to Exchange Online is reduced.
The advantages of this solution are obvious:
The decision to disable Basic Authentication for SMTP AUTH has been made. Companies have until End of 2026 to adapt their environment – but this time should be used actively. The next steps include a structured inventory, evaluation of affected systems and a decision on modernisation or a relay solution.
MTF supports you in making this transition predictable and secure. We analyse your Exchange Online environment, identify all relevant connections and work with you to develop a migration plan – from direct conversion to OAuth 2.0 to integration of the SMTP Mail Relay Service from the MTF Business Cloud.
If you want to ensure that your email communication continues to function smoothly after April 2026, it is worth discussing this with us at an early stage. Contact us for a no-obligation consultation – we will guide you step by step through the transition.