Microsoft 365How-To & HardeningRetrospectives

Post-Basic-Auth Cleanup Checklist: SMTP AUTH, Service Accounts and Scripts

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from October 2022, written in 2026 with the benefit of hindsight.

After Basic Authentication was turned off in Exchange Online, many organizations found lingering dependencies. Use this checklist to clean up.

SMTP AUTH

  • Organization-level SMTP AUTH disabled.
  • Mailboxes with SMTP AUTH enabled listed and justified.
  • Devices and apps using SMTP AUTH migrated to OAuth, direct send or a relay connector.
  • Plan in place for Microsoft's announced Basic Auth retirement for SMTP AUTH.

Service accounts

  • Service accounts used by scripts and apps inventoried.
  • Passwords for those accounts rotated after migration.
  • Interactive sign-in disabled for service accounts where possible.
  • Accounts no longer needed disabled and removed.

Scripts

  • Exchange Online PowerShell scripts use the EXO V3 module with modern authentication or certificate-based app-only authentication.
  • No scripts store passwords in plain text.
  • Scripts reviewed for hardcoded credentials and moved to Key Vault or managed identity where possible.

Applications

  • Applications reading mailboxes migrated to Microsoft Graph with app registrations.
  • Application mailbox access restricted to specific mailboxes (RBAC for Applications).
  • Old app registrations and secrets removed.

Monitoring

  • Conditional Access policy blocking legacy authentication is on.
  • Alerts for any successful legacy authentication.

Documentation

  • A list of remaining exceptions with owners and retirement dates.
smtp auth cleanup checklistBasic auth turned off2022

More on this story