Important Notice for Customers Using Exchange Online SMTP in Netwrix Password Secure

Important update for Exchange Online users – Changes to SMTP authentication

Microsoft has announced that Basic Authentication for SMTP client submission in Exchange Online will be retired in March 2026. This change affects all services that use SMTP AUTH with username/password, including our self-hosted password management solution if configured to send emails through Exchange Online.

:link: Microsoft Announcement – Retirement of Basic Auth for SMTP AUTH

Want the full details? Click the link below!


Why OAuth isn’t a practical alternative for our use case

While Microsoft recommends OAuth 2.0 for SMTP authentication, it unfortunately is not a feasible option for our product:

  • OAuth requires interactive user consent during the authentication flow.
  • Our SMTP implementation is headless and fully automated, running in the background on customer infrastructure.
  • Implementing and maintaining OAuth in this context would require secure storage and periodic refresh of access tokens, introducing complexity and potential points of failure for customers.

Because of this, we do not plan to support OAuth-based SMTP authentication in our product at this time.


Recommended alternatives for Microsoft 365 / Exchange Online users

To continue sending email notifications reliably, we recommend switching to one of Microsoft’s modern and supported options:

Microsoft Email Communication Service (ECS)

  • Designed for application-to-person (A2P) email delivery.
  • Fully managed, scalable and supports secure authentication.
  • Ideal for password reset emails, alerts, and other transactional messages.

Microsoft High Volume Email (HVE)

  • Suitable for sending large volumes of system-generated email.
  • Requires setting up a connector in Microsoft 365 and assigning a static IP.
  • More complex to set up, but powerful for larger installations.

We strongly recommend ECS for most customers due to its ease of integration and lower setup effort.


What you should do

If you’re currently using Exchange Online SMTP with Basic Auth in our product:

  1. Start planning your transition now.
  2. Evaluate ECS as the preferred alternative.
  3. Update your SMTP configuration accordingly before March 2026.

If you are using another SMTP provider (e.g. on-prem Exchange, Postfix, SendGrid, etc.), no action is required at this time. This change only applies to Exchange Online.

If you need assistance or have questions about how to reconfigure your setup within Netwrix Password Secure, please reach out via our support channel or community forum.


Need help?

There are many different ways to get help with our products!

Situation Action
If you feel the product is broken and not working as intended… Contact Support
If you have a question you’d like to ask other experts… Create a discussion in the community: Password Secure > Discussions & Questions
If you have a feature request… Let our product team know directly: Password Secure > Ideas
If you have something cool to show… Show everyone what you built: Password Secure > Show & Tell

What are your thoughts?

We are always happy to hear from our users on what you like, and what you hope to see in the future. Please, share your thoughts below!

8 Likes

Updated Exchange Online SMTP AUTH Basic Authentication Deprecation Timeline | Microsoft Community Hub

Updated Exchange Online SMTP AUTH Basic Authentication Deprecation Timeline

The_Exchange_Team

Platinum Contributor

Jan 27, 2026

We understand that many customers continue to face real challenges modernizing legacy email workflows and need sufficient time to adopt viable, secure alternatives. Based on customer feedback and visibility into adoption progress, we are refining the Exchange Online SMTP AUTH Basic Authentication Deprecation timeline to provide clearer milestones and additional runway.

  • Now to December 2026: SMTP AUTH Basic Authentication behavior remains unchanged.

  • End of December 2026: SMTP AUTH Basic Authentication will be disabled by default for existing tenants. Administrators will still be able to enable it if needed.

  • New tenants created after December 2026: SMTP AUTH Basic Authentication will be unavailable by default. OAuth will be the supported authentication method.

  • Second half of 2027: Microsoft will announce the final removal date for SMTP AUTH Basic Authentication.

These updates are intended to give customers with tenants in our service (all cloud environments) more time to plan, validate, and deploy modern authentication alternatives, while maintaining a clear path toward stronger default security.

OAuth setup is straightforward for most Microsoft 365 tenant. It is significantly simpler than the configuration approach you are currently advocating. It is also free with any paid version of O365. Several of our other vendors have already transitioned to OAuth, and their applications and email integrations continue to function.

Secure storage is essential for operating Netwrix products, and OAuth token renewal is a minimal operational overhead. Please reconsider adding OAuth support across the Netwrix product family to align with modern authentication standards and streamline deployment. Maybe you could create a plugin to allow for oAuth? Thanks for taking this into consideration. BB

1 Like