{"id":10233,"date":"2026-01-29T10:04:26","date_gmt":"2026-01-29T10:04:26","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/29\/microsoft-exchange-online-to-deprecate-smtp-auth-basic-authentication-for-tenants\/"},"modified":"2026-01-29T10:04:26","modified_gmt":"2026-01-29T10:04:26","slug":"microsoft-exchange-online-to-deprecate-smtp-auth-basic-authentication-for-tenants","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/29\/microsoft-exchange-online-to-deprecate-smtp-auth-basic-authentication-for-tenants\/","title":{"rendered":"Microsoft Exchange Online to Deprecate SMTP AUTH Basic Authentication for Tenants"},"content":{"rendered":"<p>    Microsoft Exchange Online to Deprecate SMTP AUTH Basic Authentication for Tenants<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Microsoft is preparing a major security shift for cloud email customers as Exchange Online moves toward deprecating SMTP AUTH Basic Authentication for all tenants. <\/p>\n<p>The change targets one of the oldest and weakest ways to sign in to email systems, where usernames and passwords are sent in clear form that attackers can easily steal if traffic is intercepted or credentials are reused. <\/p>\n<p>For years, threat actors have abused SMTP AUTH with basic auth to brute-force passwords, run password-spraying campaigns, and hijack accounts to send phishing and spam at scale.<\/p>\n<p>In response to this ongoing abuse, Microsoft researchers identified basic authentication for SMTP as a persistent weak point in many tenants, especially where legacy applications, devices, and scripts still rely on old protocols that do not support modern security controls. <\/p>\n<p>Once attackers gain valid credentials for SMTP AUTH, they can send email as a trusted user, bypassing many security filters and damaging an organization\u2019s reputation and email deliverability. <\/p>\n<p>This makes deprecating basic auth not just a protocol cleanup, but a critical step in hardening cloud email.<\/p>\n<p>Microsoft analysts further <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/exchange\/updated-exchange-online-smtp-auth-basic-authentication-deprecation-timeline\/4489835\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that SMTP AUTH basic sign-ins often lack strong safeguards such as multi-factor authentication (MFA) and conditional access, leaving organizations exposed even when other parts of their environment are locked down. <\/p>\n<p>Because SMTP AUTH basic auth is frequently enabled \u201cjust to keep things working\u201d for printers, line-of-business systems, and third-party tools, it has become a favorite target for attackers looking for the weakest link. <\/p>\n<p>By forcing a move away from basic <a href=\"https:\/\/cybersecuritynews.com\/esphome-web-server-authentication-bypass\/\" target=\"_blank\" rel=\"noreferrer noopener\">auth<\/a>, Microsoft aims to close this long-standing security gap before more tenants suffer account takeover and downstream compromise.<\/p>\n<p>Under the updated timeline, SMTP AUTH Basic Authentication will remain unchanged until December 2026, giving organizations time to discover and modernize all workflows that still depend on it. <\/p>\n<p>At the end of December 2026, it will be disabled by default for existing tenants, though administrators will still be able to re-enable it temporarily while migrations complete. <\/p>\n<p>For new tenants created after December 2026, SMTP AUTH Basic Authentication will be unavailable by default, with <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploit-microsoft-365-oauth-workflows\/\" target=\"_blank\" rel=\"noreferrer noopener\">OAuth<\/a>-based modern authentication as the supported method.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-how-attackers-abuse-smtp-auth-basic\"><strong>Infection Mechanism: How Attackers Abuse SMTP AUTH Basic<\/strong><\/h2>\n<p>In practice, attackers treat SMTP AUTH basic auth as an easy entry point rather than a traditional malware infection path. <\/p>\n<p>They commonly use automated tools to perform password spraying and <a href=\"https:\/\/cybersecuritynews.com\/cybersecurity-experts-report-surge-in-credential-stuffing-attacks-targeting-online-casino-accounts\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential stuffing<\/a> against SMTP endpoints, trying large sets of weak or reused passwords across many accounts until one succeeds. <\/p>\n<p>Once valid credentials are found, they authenticate via SMTP with basic auth and begin sending high-volume phishing or business email compromise (BEC) messages that appear to come from inside the victim\u2019s organization. <\/p>\n<p>From there, malicious mail can carry links to payloads, steal more credentials, or trick users into fraudulent payments, turning a single weak protocol into a broad compromise channel.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/microsoft-exchange-online-to-deprecate-smtp-auth\/\">Microsoft Exchange Online to Deprecate SMTP AUTH Basic Authentication for Tenants<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/microsoft-exchange-online-to-deprecate-smtp-auth\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Exchange Online to Deprecate SMTP AUTH Basic Authentication for Tenants Microsoft is preparing a major security shift for cloud email customers as Exchange Online moves toward deprecating SMTP AUTH Basic Authentication for all tenants. The change targets one of the oldest and weakest ways to sign in to email systems, where usernames and passwords [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10233","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10233"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10233"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10233\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10233"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}