SMTP AUTH allows applications, devices, and users to send email through Exchange Online using SMTP authentication. However, if you don’t need SMTP AUTH, there is no reason to keep it enabled. Microsoft recommends disabling SMTP AUTH to reduce the attack surface of your Microsoft 365 environment. In this article, you will learn how to disable SMTP AUTH in Exchange Online.
SMTP AUTH in Exchange Online
SMTP AUTH is an authentication method that allows clients and applications to submit email through Exchange Online. Although some applications, scanners, and devices still use SMTP AUTH, it should be disabled when it is no longer required.
Keeping SMTP AUTH enabled when it is not needed increases the available attack surface. For that reason, it is recommended to disable SMTP AUTH at the organization level and verify the setting on every mailbox.
There are two settings to check:
- Organization setting: Controls SMTP AUTH for the Exchange Online organization.
- Mailbox setting: Controls SMTP AUTH for an individual mailbox.
Note: An important part of this configuration is checking both the organization-wide setting and the individual mailboxes. Disabling SMTP AUTH at the organization level does not mean that SMTP AUTH is disabled on every mailbox. You should therefore check the SMTP AUTH setting on each mailbox and disable it or set it to follow the organization value where necessary.
SMTP AUTH options
Before disabling SMTP AUTH, make sure you understand how applications and devices currently send email. If SMTP AUTH is still required, there are several alternatives you can use depending on the application, device, and email flow.
| Option | Description |
|---|---|
| SMTP AUTH + OAuth 2.0 | Keep SMTP AUTH and replace Basic Authentication with OAuth 2.0. |
| High Volume Email (HVE) | For application and device-generated email to internal recipients. |
| Microsoft Graph | Modern API-based approach that moves away from SMTP. |
| Exchange Online SMTP relay | Use an Exchange Online connector for applications and devices that cannot use the other options, especially on-premises sources. |
| On-premises SMTP server | Use an existing on-premises SMTP server to relay email. |
| Third-party email service | Use an external email delivery service instead of Microsoft 365. This moves email delivery to another provider. Not recommended. |
Disable SMTP AUTH in Exchange admin center
To disable SMTP AUTH for the entire organization from the Exchange admin center, follow these steps:
- Sign in to Exchange admin center.
- Go to Settings > Mail flow.
- Enable Turn off SMTP AUTH protocol for your organization.
- Select Save.


- Sign in to Microsoft 365 admin center.
- Go to Users > Active users.
- Select a User.
- Select Mail.
- Select Manage email apps.


- Uncheck Authenticated SMTP.
- Click Save changes.


Note: You must check whether Authenticated SMTP is unchecked for every mailbox. This is why we recommend to use PowerShell.
Disable SMTP AUTH with PowerShell
To disable SMTP AUTH for the entire organization using Exchange Online PowerShell, follow these steps:
- Install the Exchange Online PowerShell module.
Install-Module -Name ExchangeOnlineManagement -Force
- Connect to Exchange Online PowerShell.
Connect-ExchangeOnline
- Disable the SMTP AUTH protocol for the entire organization.
Set-TransportConfig -SmtpClientAuthenticationDisabled $true
- Get configuration status.
Get-TransportConfig | Format-Table SmtpClientAuthenticationDisabled
The output appears as True, which means it’s disabled for the entire organization.
SmtpClientAuthenticationDisabled
--------------------------------
True
5. There might be mailboxes that have SMTP AUTH enabled, so you must check that and disable it too.
There are three values:
- True (disabled)
- False (enabled)
- Null (inherit, which means it follows the organization value).
Note: We recommend setting this to True (disabled) for every mailbox.
Check all mailboxes that have SMTP AUTH set to Null or False.
Get-CASMailbox -ResultSize Unlimited | Where-Object { $_.SmtpClientAuthenticationDisabled -ne $true } | Select-Object DisplayName, PrimarySmtpAddress, SmtpClientAuthenticationDisabled
- Set all the mailboxes that are not set to disabled to the True value.
$mailboxes = Get-CASMailbox -ResultSize Unlimited | Where-Object { $_.SmtpClientAuthenticationDisabled -ne $true }
foreach ($mailbox in $mailboxes) {
Set-CASMailbox -Identity $mailbox.Identity -SmtpClientAuthenticationDisabled $true
}
That’s it!
Read more: Change alias address to primary SMTP address with PowerShell »
Conclusion
You learned how to disable SMTP AUTH in Exchange Online. Remember, disabling SMTP AUTH at the organization level does not necessarily mean that every mailbox will inherit the setting. Check each mailbox and make sure SMTP AUTH is set to True (disabled) or $null, which means the mailbox follows the organization-level setting.
If you still have applications or devices that require SMTP AUTH, enable it only for the specific mailboxes that need it and plan to move away from Basic Authentication to OAuth or another suitable alternative.
Did you enjoy this article? You may also like How to Block Legacy Authentication with Conditional Access. Don’t forget to follow us and share this article.

