To enable or disable authenticated client SMTP submission in Exchange Online, use the organization-wide setting for the default and a mailbox-level override for exceptions. Microsoft recommends disabling SMTP AUTH for the organization and enabling it only for mailboxes that still need it. Enabling the setting does not restore Basic authentication or bypass other authentication restrictions.
Choose the right scope
SMTP AUTH is used by some POP/IMAP clients, applications, reporting systems, and multifunction devices to send mail. Many modern email clients do not use it. Exchange Online provides two controls:
- Organization setting: sets the default for mailboxes without an explicit mailbox value.
- Mailbox setting: overrides the organization setting for that mailbox.
Microsoft recommends disabling SMTP AUTH organization-wide and enabling it only for accounts that require it. See Microsoft’s SMTP AUTH guidance.
Enable or disable SMTP AUTH for the organization
Use the Exchange admin center
- Open the Exchange admin center and go to Settings > Mail Flow.
- To disable SMTP AUTH organization-wide, turn on Turn off SMTP AUTH protocol for your organization. To enable it, turn that option off.
Use Exchange Online PowerShell
Set the organization default with Set-TransportConfig:
#1 Best Overall
- Fortinet FortiMail-VM virtual appliance for all supported platforms. 8 x vCPU cores
- Fortinet SW FML-VM08
- Manufacturer Part: FML-VM08
- Disable SMTP AUTH:
Set-TransportConfig -SmtpClientAuthenticationDisabled $true - Enable SMTP AUTH:
Set-TransportConfig -SmtpClientAuthenticationDisabled $false
Check the saved organization setting with:
Get-TransportConfig | Format-List SmtpClientAuthenticationDisabled
Enable or disable SMTP AUTH for one mailbox
Use the Microsoft 365 admin center
- Go to Users > Active users and select the user.
- Select Mail > Manage email apps.
- Check Authenticated SMTP to enable it, or clear the box to disable it, then save.
Use Exchange Online PowerShell
Set the mailbox value with Set-CASMailbox, replacing <MailboxIdentity> with the mailbox identity:
- Disable:
Set-CASMailbox -Identity <MailboxIdentity> -SmtpClientAuthenticationDisabled $true - Enable:
Set-CASMailbox -Identity <MailboxIdentity> -SmtpClientAuthenticationDisabled $false - Follow the organization default:
Set-CASMailbox -Identity <MailboxIdentity> -SmtpClientAuthenticationDisabled $null
Use $null when you want the mailbox to inherit the organization setting rather than keep an exception. The mailbox value takes precedence when it is explicitly set. See the Set-CASMailbox parameter reference.
Verify a mailbox setting
Run:
Get-CASMailbox -Identity <MailboxIdentity> | Format-List SmtpClientAuthenticationDisabled
Rank #3
- Model: RHTx-IoT1; SMS(4G/LTE Version) + Email + Cloud hosting to User End | Measuring Parameters: Temperature, Relative Humidity | Temperature Range: 0 to 50°C; Accuracy: ± 0.5°C; Resolution: 0.1°C | Relative Humidity: 0 to 100% RH; Accuracy: ± 2% RH; Resolution: 0.1 %RH |
- Display: 128 X 64 Dot Matrix Graphical Large LCD Display with White Backlight | Operating Temperature: Safe operating temperature of instrument is 0°C to 70°C | Cable Length: Connecting Cable, pre-wired 3 mtrs. Extension between display monitor & sensor.
- Buzzer: Standard In-Built Buzzer for Alarm (External Buzzer also available - Contact Store) | Alarm Type: In built buzzer for Low & High Limit upon temperature set point violation, approx. 50 Decibel | Alarm Limit: User Configurable, freely programmable from 4 front keypad |
- Acknowledgement Key: Provided for user to acknowledge the alarm manually, thus avoiding continuous buzzer alarm sound & user attention | Sensor Type: 1. Polymer sensing for Temperature 2. Capacity polymer sensing for Relative humidity 3. Option of Extending Audio Visual Buzzer to 24/7 Surveillance/Security Rooms | Power Supply: 12 VDC Input with minimum of 2-amp current rating. Adaptor provided alongwith | Enclosure: Wall mounting type ABS
- Supply Scope: 1 Unit of RHTx-IoT Temperature Humidity Monitor, Antenna, Power Adaptor, Instruction Manual and Factory Calibration Certificate | Applications: Server Rooms, Datacenters, Cold Chains, Pharmaceuticals, Bio-Medical, Warehouse, Hospitals, Seed Storages.
Truemeans SMTP AUTH is disabled for the mailbox.Falsemeans it is enabled for the mailbox.- A blank or null value means the mailbox follows the organization setting.
To list mailbox values across the tenant, Microsoft documents querying all CAS mailboxes and filtering by the relevant value:
Get-CASMailbox -ResultSize unlimited | Where-Object {$_.SmtpClientAuthenticationDisabled -eq $true}lists mailboxes explicitly disabled.Get-CASMailbox -ResultSize unlimited | Where-Object {$_.SmtpClientAuthenticationDisabled -eq $false}lists mailboxes explicitly enabled.Get-CASMailbox -ResultSize unlimited | Where-Object {$null -eq $_.SmtpClientAuthenticationDisabled}lists mailboxes inheriting the organization setting.
Understand what the setting does not enable
SMTP AUTH supports OAuth as well as Basic authentication, but Microsoft says Basic authentication is disabled in all Exchange Online tenants. Switching on SMTP AUTH therefore does not make a legacy Basic-authentication-only client work. An application that uses SMTP AUTH with OAuth needs an application registration in Microsoft Entra, an access token with the appropriate SMTP scope, and SASL XOAUTH2 authentication. Follow Microsoft’s OAuth guidance for IMAP, POP, and SMTP.
Other identity controls can also block SMTP AUTH even when the mailbox setting is enabled. Microsoft says security defaults disable SMTP AUTH; an authentication policy that blocks Basic authentication for SMTP can also prevent a client from connecting. The current Basic authentication documentation links to Exchange Team guidance on the SMTP AUTH retirement timeline. Check that announcement for the latest milestone rather than relying on an undated or outdated date.
Troubleshoot an application or printer that cannot send
For Exchange Online client SMTP submission, Microsoft’s device setup guidance specifies smtp.office365.com, port 587 recommended (or port 25), and TLS/StartTLS. The setup article requires TLS 1.2 or later. Use the credentials of the designated mailbox; if the device sends from an address other than the sign-in mailbox, that account needs Send As permission. Consult Microsoft’s multifunction device and application setup guide.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBest Value
- 【Processor & OS】Firewall Mini PC with Intel J4105 CPU up to 2.5GHz, 4Cores4threads 4MB L2 Cache, TDP 10w, supports AES-NI. It tested with pf-sense linux ubuntu and other popular open source OS. ("DEL" key to enter BIOS)
- 【Interfaces】The firewall pc has 4 * Intel 2.5GbE I226 lan ports, 2 * USB3.0 ports, 1 * VGA port, 1 * HD port, 1 * DC port. Equipped with VESA mount, you can install the micro pc behind the monitor to save space.
- 【DDR4 RAM & mSATA SSD】The firewall router equipped with 8G DDR4 RAM, max support 16GB; 240GB mSATA SSD equipped, can be up to 512GB. Not support HDD.
- 【Fanless Design】The small firewall box is only small but powerful. Low power consumption, only 10W; fanless heat dissipation design, aluminum alloy shell, efficient and fast heat dissipation, support 24/7 hours working, no noise. Fanless mini PC, silent, with heat dissipation through the casing, which can withstand temperatures up to 60°C
- 【12 Months Service】You will get 1*mini pc,size:5.27 * 4.98 * 1.43 in weigh:500g. If you encounter any problems during the use, please contact us through Amazon, we have a professional and efficient team dedicated to serving you.
- Confirm the device supports TLS 1.2 or later and StartTLS.
- Check that the network permits the selected SMTP port.
- Verify the mailbox-level value and organization default, then check for security defaults or an authentication policy that blocks the method the client uses.
- Confirm the sign-in mailbox is the intended sender, or verify Send As permission for a different From address.
- Check whether the client supports OAuth if it relies on SMTP AUTH; enabling the protocol alone does not enable Basic authentication.
Choose the right mail-flow method for a device or application
SMTP client submission is one of several Microsoft-documented options. The right choice depends on recipient scope, authentication support, device capabilities, and tenant configuration. Microsoft distinguishes client SMTP submission, SMTP relay, Direct Send, and High Volume Email in its mail-flow method guidance.
- Client SMTP submission: uses SMTP AUTH and can send to internal and external recipients. Use it when the application can meet the tenant’s authentication and TLS requirements.
- SMTP relay: uses a connector rather than mailbox SMTP AUTH. Review Microsoft’s requirements for connector configuration and the sending environment.
- Direct Send: can send only to recipients in the organization, so it is not a fit when the device must send to external recipients.
- High Volume Email: is a distinct option intended for high-volume sending; check Microsoft’s current eligibility and setup guidance before choosing it.
These methods have different authentication, port, recipient, mailbox, connector, and volume requirements. Use Microsoft’s current setup guidance to compare those requirements against the device and tenant before changing SMTP AUTH solely to resolve a delivery problem.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

