Office 365 SMTP authentication failing, even with correct account information

Anonymous
2020-02-10T16:38:43+00:00

On my Wordpress site I've run into a problem in the last day or so, where emails simply fail to send. Before today it was running flawlessly for two months. The account information/password/username etc have not changed in that two months.

I'm using a Wordpress plugin called WP Mail SMTP to facilitate the sending of all outgoing emails. The error log I'm getting from the email test on that is as follows:

Versions:

WordPress: 5.3.2

WordPress MS: No

PHP: 7.3.14-5+0~20200202.52+debian9~1.gbpa71879

WP Mail SMTP: 1.8.1

Params:

Mailer: smtp

Constants: No

ErrorInfo: SMTP Error: Could not authenticate.

Host: smtp.office365.com

Port: 587

SMTPSecure: tls

SMTPAutoTLS: bool(true)

SMTPAuth: bool(true)

Server:

OpenSSL: OpenSSL 1.1.1d 10 Sep 2019

SMTP Debug:

2020-02-10 16:36:56 Connection: opening to smtp.office365.com:587, timeout=300, options=array ()

2020-02-10 16:36:56 Connection: opened

2020-02-10 16:36:56 SERVER -> CLIENT: 220 LNXP123CA0008.outlook.office365.com Microsoft ESMTP MAIL Service ready at Mon, 10 Feb 2020 16:36:55 +0000

2020-02-10 16:36:56 CLIENT -> SERVER: EHLO www.*****.com

2020-02-10 16:36:56 SERVER -> CLIENT: 250-LNXP123CA0008.outlook.office365.com Hello [***]250-SIZE 157286400250-PIPELINING250-DSN250-ENHANCEDSTATUSCODES250-STARTTLS250-8BITMIME250-BINARYMIME250-CHUNKING250 SMTPUTF8

2020-02-10 16:36:56 CLIENT -> SERVER: STARTTLS

2020-02-10 16:36:56 SERVER -> CLIENT: 220 2.0.0 SMTP server ready

2020-02-10 16:36:56 CLIENT -> SERVER: EHLO www.zestpromotional.com

2020-02-10 16:36:56 SERVER -> CLIENT: 250-LNXP123CA0008.outlook.office365.com Hello [***]250-SIZE 157286400250-PIPELINING250-DSN250-ENHANCEDSTATUSCODES250-AUTH LOGIN XOAUTH2250-8BITMIME250-BINARYMIME250-CHUNKING250 SMTPUTF8

2020-02-10 16:36:56 CLIENT -> SERVER: AUTH LOGIN

2020-02-10 16:36:56 SERVER -> CLIENT: 334 VXNlcm5hbWU6

2020-02-10 16:36:56 CLIENT -> SERVER: c2FsZXNAemVzdHByb21vdGlvbmFsLmNvbQ==

2020-02-10 16:36:56 SERVER -> CLIENT: 334 UGFzc3dvcmQ6

2020-02-10 16:36:56 CLIENT -> SERVER: QmFkMzM4MzA=

2020-02-10 16:37:02 SERVER -> CLIENT: 535 5.7.3 Authentication unsuccessful [LNXP123CA0008.GBRP123.PROD.OUTLOOK.COM]

2020-02-10 16:37:02 SMTP ERROR: Password command failed: 535 5.7.3 Authentication unsuccessful [LNXP123CA0008.GBRP123.PROD.OUTLOOK.COM]

SMTP Error: Could not authenticate.

2020-02-10 16:37:02 CLIENT -> SERVER: QUIT

2020-02-10 16:37:02 SERVER -> CLIENT: 221 2.0.0 Service closing transmission channel

2020-02-10 16:37:02 Connection: closed

SMTP Error: Could not authenticate.

Does anyone have any ideas at all? I'm completely at a loss here.

Microsoft 365 and Office | Subscription, account, billing | For home | Windows

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

48 answers

Sort by: Oldest
  1. Anonymous
    2020-06-26T09:09:44+00:00

    @all i think this ist the solution:

    I had the same Problems, old offic365 accounts work, new accounts did not work. After searching for 5 hours i get a solution:

    In the old accounts SmtpClientAuthenticationDisabled is false by default on online Exchange, in the new accounts it is True by default.

    I had to set it to false by exchange online powershell and also hat do go to e-mail-apps and set the hook to authenticated smtp

    after that it worked. Here you can read what is to do by exchange powershell:

    https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/authenticated-client-smtp-submission

    Steps in Powershell:

    $UserCredential = Get-Credential

    $Session = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri https://outlook.office365.com/powershell-liveid/ -Credential $UserCredential -Authentication Basic -AllowRedirection

    Import-PSSession $Session -DisableNameChecking

    Take a look if it is True: Get-TransportConfig  (if there is True set to false)

    Set-TransportConfig -SmtpClientAuthenticationDisabled $false

    Take a look again if it works: Get-TransportConfig

    Remove-PSSession $Session

    In Admin Center --> acitve Users --> click the user --> email-apps --> click the hook --> authenticated smtp

    With this combination it worked for me. Hope this can help you all

    Was this answer helpful?

    50+ people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2020-07-06T11:57:19+00:00

    Thanks for digging into this.

    It is frustrating as on the application development side, to get announcements like these https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-oauth-2-0-support-for-imap-and-smtp-auth-protocols-in/ba-p/1330432

    And then to move forward with implementation and getting customers through any friction with admin consent and then to discover that old accounts will respect the OAuth SMTP scope grant, but new ones won't because of this setting.

    From a consumer perspective, they've authorized it and in many cases an admin has granted approval for the application only to still have it not work for some hard to know reason (this setting).

    The OAuth grant should allow for SMTP, and at the least have a clear spot in azure admin to toggle SmtpClientAuthenticationDisable .

    As an application developer, I must say that the experience with conflicting, unclear documentation and the UX/UI of the admin portals have been the biggest challenge in interfacing with OAuth setup.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2020-07-06T16:16:02+00:00

    "...and at the least have a clear spot in azure admin to toggle SmtpClientAuthenticationDisable "

    Dead right Anthony Gentile_FUB.

    When I read that new tenants - and probably tenants that up until now have not used it - were to have Basic Authentication disabled for SMTP, I assumed that MSFT would at least make it relatively simple to re-enable it.

    Timme B81 has done us all a great favour in demonstrating how to do it. Many thanks.

    Perhaps MSFT do not realise the scale and disruption of forcing a conversion from SMTP Basic Authentication to Oauth2 in this way. And they haven't - and probably won't - produce a PHP version of MSAL, and that screws up the large number of apps (from the simple Contact form upwards) that email out of PHP on an Apache or similar back-end.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2020-07-24T21:56:29+00:00

    Hi all,

    As mentioned above, the SMTP AUTH protocol is now disabled by default for new organisations onboarding to Microsoft 365/Office 365/Exchange Online. This was announced here: 

    https://techcommunity.microsoft.com/t5/exchange-team-blog/securing-authenticated-smtp-in-exchange-online/ba-p/1293154

    The change uses two settings, an organisation setting (SmtpClientAuthenticationDisabled) , and per-mailbox settings (Under Manage Email Apps or the ) to allow admins to finetune what mailboxes have this protocol enabled. with the per-mailbox settings overriding the organsation setting such that you only need to enable mailboxes that need to use the protocol and allow the others to remain secured and disabled. 

    You can learn who to change these in the document shared above: 

    https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/authenticated-client-smtp-submission 

    For reference, the main support document that offers advice on how to configure devices and clients like Wordpress sites to send emails can be found here: 

    https://docs.microsoft.com/en-us/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365

    We added a note warning about SMTP AUTH being disabled to it as part of this change in behaviour. 

    Regarding basic authentication, just to be clear, this is a protocol-based setting and it disables SMTP AUTH, regardless of whether basic auth or OAuth is being used.

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2020-07-25T11:05:09+00:00

    The 17th July 2020 doc Option 1 (recommended): “Authenticate your device or application directly with a Microsoft 365 or Office 365 mailbox, and send mail using SMTP AUTH client submission” confused me, and I think the confusion comes from my being unable to distinguish when the doc is referring to SMTP AUTH with Basic Authentication or SMTP AUTH with Oauth2 (or both!).

    Your comment “Regarding basic authentication … this is a protocol-based setting and it disables SMTP AUTH, regardless of whether basic auth or OAuth is being used” is a minor bombshell and confuses me further. MSFT’s original announcement was that Basic Authentication was deprecated and would be discontinued early this year, with the discontinue date then being moved to later in 2021. We were guided to replace Basic Authentication by Modern Authentication (aka Oauth2). Your comment above implies that EITHER form of authentication* is deprecated – that SMTP itself will be blocked! If so, what is the recommended replacement?

    * to be pedantic: for ‘Oauth2’ read openid authentication with Oauth2 authorisation

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments