What the Basic Auth shutdown means for the sites you look after
At the end of December 2026 a default changes in every customer tenant, and every estate has devices hanging off it. This page has the dates, the devices a survey turns up, and the five ways out of each one. Four of them do not lead to us.
What happens, and when
Microsoft disables Basic Authentication for SMTP AUTH by default in existing Microsoft 365 tenants at the end of December 2026. In tenants created after that date, this authentication method is unavailable by default. What follows is less dramatic than it is made out to be in a lot of places. We are writing it out here so you can check it.
End of December 2026
Basic Auth for SMTP AUTH is disabled by default in existing tenants. Devices that sign in to smtp.office365.com with a username and password get an error instead of a delivery from that point on.
After that, if needed
Administrators can switch SMTP AUTH back on themselves. For now this is a changed default, not a removal of the feature.
Second half of 2027
Microsoft will announce the final removal date. That date is not known today and falls after the announcement.
The hard deadline is therefore later than the tone of most articles on the subject suggests. If your scanner stops in January 2027, you can buy yourself room instead of rebuilding everything on a Friday afternoon. You will still have to rebuild it, and converting devices across several branches is not an afternoon's work.
What turns up when you go through a customer base
The printer is the hook. The work is in everything else that will never get OAuth-capable firmware, and it is rarely on an inventory list, because nobody bought it as an email client. So do not start at the devices: start in the Exchange admin centre under Reports > Mail flow > SMTP AUTH Clients. That report lists the senders across the whole tenant, separates TlsAuthLogin (Basic) from XOAUTH2 in its Authentication Protocol column, and exports to CSV. Change the date range before you read anything into it: it opens on the last seven days and can be widened to ninety, and the machine in the warehouse that scans one delivery note a month is not in seven. Which device sits behind a sender is then a question for that mailbox's Sent Items folder, where Microsoft 365 keeps a copy of every message sent over SMTP AUTH.
Multifunction printers and scanners
Scan-to-email is the classic case: the device knows exactly one SMTP server, one username and one password, and all three live in its own web interface rather than in your documentation. They are rarely counted in full - the machine in the warehouse that scans one delivery note a month never shows up in a ticket. For large scans, Mailwerk Relay switches to an upload session automatically from around 3 MB, and the device never notices the difference.
ERP and merchandise management
Invoices, delivery notes and order confirmations go out straight from the application. Mail sending sits in a configuration file on the application server, or in a dialog three levels deep that nobody has touched in years, and there is no OAuth update for the version in use. Do not ask the customer's IT about this one; ask whoever writes the invoices, because that is where it shows first.
Monitoring and alerting
Monitoring that can no longer get its mail out also stops reporting the outage it was bought for. The fault usually only surfaces when something else goes wrong on top of it. Going through an estate, this is the class most likely to be yours rather than the customer's: your own tool, sending through one of their mailboxes. Nobody has pressed the test button on that notification channel since the day it was set up.
NAS and backup
A backup report that never arrives looks exactly like a backup that ran. That is precisely why mail from NAS and backup systems is the place where a silent shutdown gets genuinely expensive. Look twice here: the NAS has SMTP settings of its own, the backup software on top of it has another set, and both of them send.
Point of sale and alarm panels
End-of-day reports, fault messages, door contacts. These devices are certified or sealed, and their firmware does not get reissued over an authentication method. Most of the time they are not on your inventory at all: another trade installed them, and the credentials sit with the installer. This is the class where the first job is a phone call, not a settings change.
Time tracking and old line-of-business software
Software that has run for years, usually on a VM nobody touches, precisely because it runs. The vendor no longer exists, or no longer maintains the version in use; there will be no update that retrofits OAuth here, and you do not need to go looking for one. It keeps working as soon as it can get its mail out again.
Five ways out, and when each one is right
For each device you find there are five routes worth considering. Four of them do not lead to us: two cost nothing, one costs cents, and one costs a new device. Which one is right is decided by the line, the recipients and the device, not by anyone selling you something.
Microsoft's inbound connector
Right when the site has a static public IP address it shares with no other organisation.
It costs nothing, it comes from Microsoft, and you do not need us for it. You set it up in that customer's own Exchange admin centre, once per tenant. The alternative to a static address is a certificate on every device, which almost nothing in the list above can hold. Microsoft does not support dynamic lines for this route, and dynamic is what branch offices and small businesses mostly have.
A firmware update to OAuth
Right wherever the manufacturer still ships one for that exact model.
It costs nothing but your time, and it settles that device for good, because afterwards it authenticates over OAuth on its own. Check per model rather than per range: with printers and scanners the cut-off often runs through the middle of a series, and a 2019 unit gets what its identical-looking 2016 sibling does not. Ask support about OAuth 2.0 or modern authentication for Microsoft 365, not about TLS.
Microsoft High Volume Email
Right when the device only sends to recipients inside the customer's own tenant, stays under 10 MB, and the customer has an Azure subscription with pay-as-you-go billing.
Microsoft has a second route for devices, and the December change does not touch it: an HVE account signs in at an endpoint of its own (smtp.hve.mx.microsoft, port 587, TLS) and, in Microsoft's own words, still authenticates when SMTP AUTH is switched off for the tenant. No static address, no certificate, no licence, and you pay for what you send: $0.000042 per delivered recipient, which is $42 per million. A scanner sending receipts to the customer's own finance team is settled by this, and you do not need us for it. The limits above are hard ones, though: without a billing policy assigned, an HVE account cannot send at all; it never delivers to an external recipient; and 10 MB is the ceiling. HVE itself takes either, OAuth or a username and password. Only the second needs Security Defaults switched off in Entra ID, and a device that cannot do OAuth leaves you exactly that one - which is what such a device costs you here.
Replacing the device
Right when it is at the end of its life anyway. Expensive when it is not.
A multifunction device coming out of its service contract gets replaced regardless, and the shutdown is only the occasion. Replacing a sealed alarm panel over an authentication method is another matter: the work costs many times what a relay on the same network costs, and the fault message is no better afterwards. Do that arithmetic per device, not per site.
A relay on the customer's network
Right for what is left: changing addresses, mail going outside the tenant, large attachments, no Azure subscription, Security Defaults you want to keep on, and firmware that will never be reissued.
A program on a machine on the customer's network accepts SMTP with a username and password and delivers through that same customer's Microsoft 365 tenant over OAuth2. On the device you change the server address and the credentials, and nothing else. That is Mailwerk, and the only one of the five you pay us for; for a single site on a static address it is the wrong choice.
Across one site this is a decision. Across thirty customers it is a list, and the four routes ahead of ours take a good part of it off that list before we come into it at all.
Get started
Two sites free of charge, no payment details
Create a customer, roll the agent out, repoint the device. Two sites are free of charge: one for your own office, one to try at a customer. From the third one on it is billed, for every site, monthly and cancellable monthly.