Back to the blog
smtp relaymicrosoft 365smtp authapparaten
New

Microsoft 365 with SMTP AUTH disabled: what about your printer, scanner and applications?

When SMTP AUTH is switched off in Microsoft 365, devices and applications that send through a mailbox with a username and password — multifunction printers, scanners, alarm systems, NAS units, monitoring, older business software — suddenly stop sending. You can re-enable them one by one, with all the limitations of a mailbox, or move all automated mail to an SMTP relay with a separate login per application. The latter is usually the durable solution: your staff keep working in Microsoft 365, the devices send through the relay.

What exactly happens

Microsoft is phasing out classic sign-in with username and password, because it does not support two-step verification and is therefore a favourite target. In new environments, sign-in for outgoing mail via SMTP is disabled by default, and Microsoft has announced that the remaining exceptions will eventually go too. The symptom is always the same: a device that has emailed scanned documents for years suddenly reports an authentication error. Or a business application that sent invoices logs "authentication unsuccessful" and stops. Nobody changed anything; the setting on Microsoft's side changed.

Why it hits devices

A printer or scanner knows only one way to send mail: a server name, a port, a login and a password. The same goes for most alarm systems, camera systems, backup software and older ERP packages. They do not support modern token-based sign-in, and the manufacturer is not going to add it. The device is not broken; it simply speaks a language Microsoft 365 no longer wants to hear.

The options

Option 1: re-enable SMTP AUTH per mailbox

This works, as long as Microsoft allows it. You create a separate mailbox per device, enable the setting there and hope it keeps working. The drawbacks: the sending limits of a mailbox apply to the device too, every mailbox costs a licence or needs an exception, and you are building on a feature whose retirement has been announced. For one scanner it is a stopgap; for ten applications it is maintenance.

Option 2: deliver directly without sign-in

Microsoft offers ways to send to your own organisation without a login, from a fixed IP address. Handy for internal notifications, but limited: it works from a fixed address, often only to your own mailboxes or with strict limits outward, and it requires configuration in the admin centre that not everyone is familiar with.

Option 3: a relay for all automated mail

You give every device and every application its own login on a relay. The scanner, the alarm system and the invoicing package send through port 587 with STARTTLS, exactly as they always did, just to a different server name. The relay sends with SPF and DKIM for your domain, keeps a log per message, and has no mailbox limits. Microsoft 365 stays what it is: the environment where your people email and meet. Why that separation makes sense regardless of SMTP AUTH is on the transactional email page.

How to switch

  1. List everything that sends through Microsoft 365 without a person behind it. Ask the IT partner, the alarm supplier and the accountant; the list is always longer than expected.
  2. Create a login per application on the relay. One per device, so you can revoke one without touching the rest.
  3. Add the relay to your SPF record and enable DKIM for your domain. Your existing records for Microsoft 365 stay; you add, you do not replace.
  4. Change the server name, port and login on each device. Send a test message to an external address, not to yourself.
  5. For the first week, check in the relay's log that everything arrives.

What not to do

Put an employee's password in the scanner. That works until the employee changes their password or leaves, and it gives a device in the corridor access to a full mailbox. A relay login can only send, and only what you allow.

Frequently asked questions

Does anything change for my staff?

No. Outlook, Teams and webmail keep working as always. Only devices and applications get a different outgoing server.

What about applications that do support modern sign-in?

They can stay on Microsoft 365. But the sending limits of a mailbox still apply; for larger volumes a relay is the better route anyway.

Can I keep the sender address?

Yes. The scanner still sends from scanner@yourcompany.be; only the path the message takes changes.

#microsoft 365 smtp auth#smtp auth disabled#scanner to email office 365#printer smtp microsoft 365#office 365 smtp relay
Call us
Send an email