Printers, applications and websites often send mail in different ways, even when teams call all of them SMTP. Map each sender, verify its authentication method and plan a safe transition.
Distinguish SMTP protocol from Basic Authentication. Changing support for password login does not mean the end of SMTP across the board or the same impact on all connectors and devices.
Current terms differ from older articles
Microsoft in updated exchange team announcement states that the behavior of SMTP AUTH Basic Authentication will remain unchanged until December 2026. At the end of December, it should be disabled by default for existing tenants with the option to enable it again. For new tenants after December, OAuth should be the default supported path. Microsoft plans to announce the final removal date in the second half of 2027.
Therefore, do not use the older March or April 2026 date as the current definitive date. Before making a drastic change, also check the notice for your own tenant.
The postponement does not change the need for inventory. It is a space for a supported solution and its test, not a reason to further expand the dependency on passwords.
Four different shipping ways
| Way | Typical use | Key control |
|---|---|---|
| SMTP submission with modern authentication | Applications with OAuth support | Client Support, Permissions and Token Operations |
| SMTP relay via connector | Appropriate corporate infrastructure | Certificate or public IP and network conditions |
| Direct Send | Limited internal delivery in appropriate scenario | Do not assume relay to the Internet |
| Standalone email service or API | Applications and specialized submissions | Domain authentication, limits, costs and administration |
Microsoft compares supported scenarios in how to set up a multifunction device and application. Choose the method according to the actual location of the application and recipients.
Take inventory by sender
For each system, record the owner, SMTP endpoint or API, port, authentication, sender address, and recipient. Add device location, manufacturer support and access to logos.
In particular, ask whether the system sends only within the organization or also to customers. The scan test to your own address does not demonstrate functional external delivery of invoices.
Also distinguish between an in-office device and a third-party hosted application. The same connector configuration may not be a supported solution for both locations.
What to expect from a printer supplier
Ask about the specific model, firmware and OAuth method supported. A general confirmation that "we can do Microsoft 365" is not enough. You need a registration procedure, access recovery and error behavior.
Request a trial scenario with a real tenant and a supported management method. See if the sending continues after changing the password, changing the administrator or restarting the device.
If the device does not support modern authentication, select the corresponding supported alternative. We wouldn't suggest turning off protection for the entire tenant as a common way to get a single scanner up and running.
The connector has its own network prerequisites
SMTP relay via connector is not a general public SMTP server for every application. Verify the sender's ID, public IP or certificate, and the availability of the required port.
In particular, check branches and internet connection changes. If the solution depends on a public address, switching to another provider may break sending without changing the printer.
A firewall or DNS entry should have an owner and a documented reason. Don't rely on a historical configuration that no one can explain.
Direct Send and external recipient
Direct Send is not a substitute for any customer mailing. If the accounting system needs to send to other domains, verify the method corresponding to this requirement.
The terms "direct send" and "SMTP relay" are often confused on forums. Diagnose by endpoint, connector, and actual authentication, not the name in the email from the previous vendor.
For a simple printer, the chosen path should be manageable in the long term. A solution requiring complex infrastructure due to multiple scans per week may be operationally inconvenient, even if technically possible.

Model example: printer, ERP and web
A hypothetical company has a printer in the office, an ERP on a company server and a website with an external provider. All three devices have different conditions and may need a different path.
The printer only sends to employees. ERP also delivers invoices to customers and needs logs and replays. The website sends a confirmation from the hosted environment. Choosing one SMTP password for all systems ignores their differences.
The administrator prepares a separate test and owner for each route. Finance confirms the delivery of the invoice, the operations team scans and the site manager the delivery of the form confirmation. The success of one method does not automatically transfer to others.
Also test non-delivery
Before deployment, send the message internally and externally, verify the representative attachment and check the result in the log. Then try the error: unavailable network or invalid recipient in the safe test.
Determine whether the application is repeating the request and whether there is a risk of duplication. For invoices, it is important to check the business result, not just the "SMTP accepted" record.
Include in the submission where the rejected message is being looked for and who is responding. Without this step, you can upgrade authentication and still have the same problem with invisible errors.
Migration plan
- Map all sending systems.
- Specify today's method and dependencies.
- Check with vendors for supported alternatives.
- Choose a solution for each location and traffic type.
- Test delivery and error behavior.
- Deploy the change on a system-by-system basis.
- Remove unnecessary old accesses and update records.
Prepare a specific approved procedure for the return. Restoring the old mechanism is not a long-term result of the migration and should not be done without the knowledge of the responsible administrator.
Frequently asked questions
Will all SMTP stop working in 2026?
No. The notice is for a specific authentication method with SMTP AUTH, not for every send path.
Just change the password?
If the system uses Basic Authentication, another password will not change the authentication mechanism.
Does every printer need a licensed mailbox?
It depends on the chosen method. Some supported relay scenarios do not need a clipboard; verify the entire configuration.
Can we use the corporate connector for a third-party site?
Don't assume it. Microsoft has specific restrictions on hosted applications and SMTP relay.
The result of a well-executed change
The company knows where it sends mail from, how systems are verified and who handles errors. The new authentication will also bring a better operational overview, which will help the next time you change equipment or supplier.








