Microsoft SMTP Basic Auth ends December 2026: what to do

At the end of December 2026, Microsoft is turning off a piece of technology most businesses have never heard of and quietly depend on.

It's called Basic Authentication, and it's the method that devices and applications use to sign in and send email through Microsoft 365. When it goes, anything still relying on it will stop sending email. Not with an error message anyone will notice. It just stops.

This is the last stage of something Microsoft has been working through since 2019, and it's the piece that affects the widest range of everyday equipment. Here's what's actually happening and what to do about it.

What Basic Authentication is, with no geek-speak

When a person signs into Microsoft 365 today, there's usually more to it than a password. A prompt on their phone, a code, an approval tap. That extra step is what stops a stolen password being enough on its own.

Devices and applications never got that treatment. A printer, a monitoring tool or a line of business application typically signs in with nothing but a username and password, exactly as people did in 2010. That's Basic Authentication.

The problem is obvious once you say it out loud. If those credentials are stolen, guessed or found in an old configuration file, whoever has them can send email that appears to come from your business. There's no second factor in the way and, in many cases, no alerting either.

Microsoft has been removing this method across its services for years. Older protocols went in 2022. Email submission from devices and applications was left as the final exception, because so much equipment depends on it. That exception is now ending.

The timeline

Microsoft has revised this several times, so it's worth being precise about where things stand.

End of December 2026. Basic Authentication is disabled by default for existing Microsoft 365 tenants. Administrators can temporarily switch it back on, but Microsoft is clear this is a migration aid rather than a long-term option.

New tenants created after December 2026. Basic Authentication will not be available by default at all.

Second half of 2027. Microsoft will announce the final, permanent removal date. At that point there is no re-enabling it.

If your business gets the re-enable treatment in January, treat it as buying a few months rather than solving the problem.

What this actually affects

This is where most businesses underestimate the scope. It isn't a printer problem, although printers are the most visible example.

It affects anything that sends email without a person clicking send:

  • Multi-function printers and photocopiers using scan to email

  • CCTV, alarm and intruder detection systems sending alerts

  • Door entry and access control systems

  • Building management, heating and refrigeration monitoring

  • Accounts, CRM, stock and ERP systems sending automated statements or reports

  • Backup and monitoring software reporting failures

  • Scheduled scripts and reporting jobs

  • Bespoke software written for your business, particularly anything more than a few years old

  • Third party services configured to send email on your behalf

The pattern is consistent. These are systems that were set up once, worked reliably, and have not been thought about since. In many businesses the person who configured them has left.

You might not be affected, and that's worth confirming first

This change is narrower than it sounds, and plenty of businesses will find nothing needs doing.

It applies specifically to devices signing in with a username and password to Microsoft's client submission endpoints, smtp.office365.com and smtp-legacy.office365.com.

If your devices send email through a connector that recognises your office IP address rather than a password, they're not affected. If they route through an on-premises mail server or gateway, they're not affected either.

So the first question isn't "what do we need to change". It's "does any of this apply to us". For a reasonable number of businesses, the honest answer is no.

How to find out

There are two ways to get an answer, depending on who looks after your IT.

If you're a 1-Fix client, we're already on it

You don't need to do anything.

We're running this check across every client we support. If nothing on your systems is affected, we'll email to tell you that and there'll be nothing further to do. If we find something, your account manager will be in touch with a list of exactly what's involved, whether each item can be reconfigured or needs replacing, and what it costs either way.

Either way, you'll hear from us. You won't need to chase it, and you won't be left wondering.

One thing that would help. If you've added any equipment recently that might send email, particularly printers, alarm systems or anything from a third party supplier, mention it when we get in touch. Kit installed by someone else is the most common thing to slip through.

If you want to check it yourself

Microsoft built reporting for this specifically.

In the Exchange admin centre, under Reports and then Mail flow, there's an SMTP AUTH clients report. It lists every mailbox or address submitting email this way, and since late 2024 it includes a column showing whether each one is using Basic Authentication or the modern method. It exports to a spreadsheet.

Two things to watch.

The date range. The report defaults to the last seven days. Plenty of systems only send email monthly or quarterly, so a short window can come back looking clean when it isn't. Pull at least 30 days, and 90 if you can. This is the single most common way businesses end up thinking they're fine when they aren't.

Identifying the actual device. The summary report tells you which mailbox is being used, not which piece of equipment. There's a detailed version that includes the source IP address for each submission, which is what you need to trace it back to a physical device. On larger environments it can take several hours to generate, so request it early.

If you run the report and can't work out what's behind some of the entries, that's normal. Tracing an IP address back to a specific device is the part that usually needs someone with access to the network. We're happy to help with that even if you're not a client.

Your options

There's rarely one answer for a whole business. Most organisations end up using two or three of these.

Move to modern authentication. Where the device or application supports it, this is the right answer. It's Microsoft's own solution, it's more secure, and once it's done there's nothing further to revisit. Some equipment needs a firmware update first, and occasionally the software vendor needs to be involved.

Replace the device. Equipment beyond about five to seven years old often cannot support modern authentication at all. Where that's the case, replacement usually works out cheaper across a couple of years than maintaining workarounds for it. Lead times on some equipment run to weeks, which is a strong argument for finding out early.

Route through an on-premises relay. If you still run a server on site, legacy devices can keep working with no changes to them at all. It buys time, but it keeps you tied to hardware you'll eventually want to retire, and it needs maintaining.

Microsoft High Volume Email. Designed for systems that only email people inside your own organisation. It runs on its own dedicated endpoint and supports the older sign-in method until September 2028, so it buys significant extra time for internal-only sending. It cannot send to customers or suppliers.

Azure Communication Services. Built for applications rather than hardware, and suited to software sending order confirmations, appointment reminders or notifications out to customers. There's a usage-based cost and your software supplier will usually need to make a change at their end.

The cost of leaving it

The obvious risk is the outage. Systems stop sending, and because there's no visible error, nobody finds out until something that should have arrived didn't. Backup failures go unreported. Invoices quietly stop going out. Alarm faults are never flagged.

The less obvious risk is what people do next.

When scan to email breaks, staff do not stop working. They photograph the document on a phone and send it from a personal email account. Contracts, HR files, invoices, all leaving the business through a route nobody is monitoring and nobody knows about. There's no report that surfaces this, and once it's been happening for a few weeks it's very difficult to establish where anything ended up.

Then there's the money. Handled through 2026, any replacements sit in a normal budget cycle and can be staged. Handled in January, it becomes emergency procurement at emergency prices, usually during a week when several other things have gone wrong at once.

And there's a genuine security gain sitting underneath all of this. Old-style logins are one of the more commonly exploited routes into a business email system. Removing them is the sort of thing cyber insurers, Cyber Essentials assessors and larger clients ask about during due diligence. Being able to answer confidently has value beyond this deadline.

What we'd suggest

Run the check in the next couple of months rather than the autumn. Not because December is close, but because if the answer involves replacing equipment, you want that decision made with time to spare.

Then work through it in order. Anything business critical first, anything cheap and easy second, anything requiring capital expenditure planned into the budget year. Most of it is straightforward once you know what you're dealing with.

The review itself takes very little of your time. The value is in knowing exactly where you stand well before the deadline, rather than finding out afterwards.

If you'd like us to run that check across your systems, get in touch and we'll get it booked in.