๐ Secure Bits ๐ก
๐ฆ๐ ๐ง๐ฃ ๐๐จ๐ง๐ ๐ถ๐ป ๐๐
๐ฐ๐ต๐ฎ๐ป๐ด๐ฒ ๐ข๐ป๐น๐ถ๐ป๐ฒ ๐ถ๐ ๐ผ๐ณ๐ณ๐ถ๐ฐ๐ถ๐ฎ๐น๐น๐ ๐ด๐ผ๐ถ๐ป๐ด ๐ฎ๐๐ฎ๐ โ ๐๐ต๐ฒ ๐๐ถ๐บ๐ฒ๐น๐ถ๐ป๐ฒ ๐ถ๐ ๐ป๐ผ๐ ๐๐ฝ๐ฑ๐ฎ๐๐ฒ๐ฑ.
Microsoft has published an ๐๐ฝ๐ฑ๐ฎ๐๐ฒ๐ฑ ๐ฑ๐ฒ๐ฝ๐ฟ๐ฒ๐ฐ๐ฎ๐๐ถ๐ผ๐ป ๐๐ถ๐บ๐ฒ๐น๐ถ๐ป๐ฒ ๐ณ๐ผ๐ฟ ๐ฆ๐ ๐ง๐ฃ ๐๐จ๐ง๐ ๐๐๐ถ๐ป๐ด ๐๐ฎ๐๐ถ๐ฐ ๐๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป in Exchange Online – and it will end fairly soon.
If you still rely on SMTP AUTH for:
– Applications and scripts
– Printers and scanners
– Legacy systems or monitoring tools
โฆ those systems ๐๐ถ๐น๐น ๐๐๐ผ๐ฝ ๐๐ฒ๐ป๐ฑ๐ถ๐ป๐ด emails once deprecation is enforced.
โฐ ๐ช๐ต๐ฎ๐ ๐ถ๐ ๐๐ต๐ฒ ๐๐ถ๐บ๐ฒ๐น๐ถ๐ป๐ฒ?
– ๐๐ป๐ฑ ๐ผ๐ณ ๐๐ฒ๐ฐ๐ฒ๐บ๐ฏ๐ฒ๐ฟ ๐ฎ๐ฌ๐ฎ๐ฒ: SMTP AUTH Basic Authentication will be disabled for existing tenants. Administrators will still be able to enable it if needed.
– ๐๐ฎ๐ป๐๐ฎ๐ฟ๐ ๐ฎ๐ฌ๐ฎ๐ณ: SMTP AUTH Basic Authentication will be unavailable for newly created tenants. OAuth will be the supported authentication method.
– ๐ฆ๐ฒ๐ฐ๐ผ๐ป๐ฑ ๐ต๐ฎ๐น๐ณ ๐ผ๐ณ ๐ฎ๐ฌ๐ฎ๐ณ: Microsoft will announce the final removal date for SMTP AUTH Basic Authentication.
๐ค ๐ช๐ต๐ ๐๐ต๐ถ๐ ๐บ๐ฎ๐๐๐ฒ๐ฟ๐
SMTP AUTH is one of those things that often runs in the background. More often the not, critical service or system relies on it. When it breaks, the impact is very visible โ invoices not sent, alerts not delivered, workflows failing โ but the root cause is often not obvious.
Fixing it usually isnโt a checkbox. It often requires ๐ฐ๐ต๐ฎ๐ป๐ด๐ถ๐ป๐ด ๐ต๐ผ๐ ๐ฎ๐ฝ๐ฝ๐น๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป๐ ๐๐ฒ๐ป๐ฑ ๐บ๐ฎ๐ถ๐น, not just tweaking a setting.
๐ก๏ธ ๐ช๐ต๐ฎ๐ ๐ ๐๐ผ๐๐น๐ฑ ๐ฑ๐ผ
– If you are using SMTP AUTH to send emails to ๐ถ๐ป๐๐ฒ๐ฟ๐ป๐ฎ๐น ๐ฟ๐ฒ๐ฐ๐ถ๐ฝ๐ถ๐ฒ๐ป๐๐, you can use High Volume Email for Microsoft 365
– If sending to ๐ถ๐ป๐๐ฒ๐ฟ๐ป๐ฎ๐น ๐ฎ๐ป๐ฑ ๐ฒ๐
๐๐ฒ๐ฟ๐ป๐ฎ๐น ๐ฟ๐ฒ๐ฐ๐ถ๐ฝ๐ถ๐ฒ๐ป๐๐, use Azure Communication Services Email.
– If you have an ๐๐
๐ฐ๐ต๐ฎ๐ป๐ด๐ฒ ๐ฆ๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ถ๐ป ๐ต๐๐ฏ๐ฟ๐ถ๐ฑ ๐ฐ๐ผ๐ป๐ณ๐ถ๐ด, you can use Basic auth against the Exchange Server
– If you are done changing your systems, I would advise to disable the SMTP AUTH beforehand.
โ๏ธ ๐๐ถ๐๐ฎ๐ฏ๐น๐ฒ ๐ฆ๐ ๐ง๐ฃ ๐๐จ๐ง๐ ๐ถ๐ป ๐๐ผ๐๐ฟ ๐ผ๐ฟ๐ด
1. Sign in to the Exchange admin center.
2. Click Settings > Mail Flow.
3. Toggle the setting labeled “Turn off SMTP AUTH protocol for your organization”.
4. Click Save.
Even after SMTP AUTH is disabled tenant-wide, it can still be enabled for individual users. Make sure that you run a PowerShell script to retrieve all the mailboxes where SMTP AUTH is enabled and disable it.
โ ๏ธ ๐๐บ๐ฝ๐ผ๐ฟ๐๐ฎ๐ป๐
First, identify if itโs still used via sign-in logs in Entra ID, then change your systems to use modern counterparts ๐ป๐ผ๐, while you still have time to test and redesign them.
๐ฌ Do you know exactly which apps or devices in your tenant are still using SMTP AUTH?
๐๐ถ๐ต๐ฉ๐ฐ๐ณ ๐ฐ๐ง ๐ต๐ฉ๐ฆ ๐ฑ๐ฐ๐ด๐ต:
Martin Strnad
