Why can’t I create new Microsoft app passwords anymore?

0
0
Asked By MellowPine42 On

I'm supporting a client whose church administration software sends mailing-list emails through SMTP and only supports basic authentication with an app password. The vendor does not currently support OAuth, and there are limited alternative applications for this use case.

I previously created app passwords for two users in the tenant, and those existing passwords still work. However, the client recently hired a new administrator who also needs access, and the option to create a new app password no longer appears under Security Info > Add sign-in method.

The tenant has Security Defaults disabled, the setting allowing users to create app passwords is enabled, affected users have per-user MFA enforced, MFA registration is complete, Microsoft Authenticator is registered, and there are no Conditional Access policies blocking legacy authentication. The users can access Security Info normally, but the app-password option is missing.

Has Microsoft stopped allowing new app passwords even when the documented settings are enabled? If so, what is the best replacement for this legacy SMTP application?

3 Answers

Answered By VelvetMaple31 On

Exchange Online connectors may also work, but the requirements depend on the application. Direct relay generally needs a fixed public IP or certificate, outbound port 25, and strict connector restrictions. If the software runs from changing addresses or a hosted service, a third-party SMTP relay is usually more practical. Also check whether the vendor can send through its own authenticated mail service or support OAuth in a future release.

Answered By NimbleCedar27 On

I would stop trying to provision another app password and move the application to an SMTP relay. A third-party relay is often the simplest option for older software that cannot use OAuth. Make sure the sending domain is configured with the relay’s SPF and DKIM records and that DMARC alignment is preserved so the messages do not get treated as spoofed.

BrightOtter64 -

A hosted relay has also worked well for other legacy systems such as scanners and small-business mailing tools. It avoids weakening the tenant’s authentication controls just to keep an obsolete client working.

Answered By QuartzRiver8 On

This is expected after Microsoft retired basic authentication for Exchange Online. Existing app passwords may continue working, but new ones can no longer be created for applications that rely on legacy authentication. The tenant settings can still look correct because they do not override the service retirement.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.