Simple Mail Transfer Protocol Authentication SHALL Be Disabled
Last updated
Last updated
Modern email clients that connect to Exchange Online mailboxes—including Outlook, Outlook on the web, iOS Mail, and Outlook for iOS and Android—do not use Simple Mail Transfer Protocol Authentication (SMTP AUTH) to send email messages. SMTP AUTH is only needed for applications outside of Outlook that send email message.
SMTP AUTH SHALL be disabled in Exchange Online
SMTP AUTH MAY be enabled on a per-mailbox basis
This setting can be configured in any Microsoft tenant.
SMTP AUTH can only be disabled tenant-wide using Exchange Online PowerShell. To do so, follow the instructions listed at
To enable SMTP AUTH on a per-mailbox basis, follow the instructions listed at
This will vary depending on the organization and what existing mail infrastructure looks like. This can be impactful if you have scanners, printers, or Line-of-business (LOB) applications leveraging SMTP auth for message relay. To avoid any issues here,
Use the following for configuring SMTP relay for printers, scanners, etc:
Changing Modern Auth Settings:
Basic Auth Reporting: