Post-Basic-Auth Cleanup Checklist: SMTP AUTH, Service Accounts and Scripts
Retrospective: this article looks back at events from October 2022, written in 2026 with the benefit of hindsight.
After Basic Authentication was turned off in Exchange Online, many organizations found lingering dependencies. Use this checklist to clean up.
SMTP AUTH
- Organization-level SMTP AUTH disabled.
- Mailboxes with SMTP AUTH enabled listed and justified.
- Devices and apps using SMTP AUTH migrated to OAuth, direct send or a relay connector.
- Plan in place for Microsoft's announced Basic Auth retirement for SMTP AUTH.
Service accounts
- Service accounts used by scripts and apps inventoried.
- Passwords for those accounts rotated after migration.
- Interactive sign-in disabled for service accounts where possible.
- Accounts no longer needed disabled and removed.
Scripts
- Exchange Online PowerShell scripts use the EXO V3 module with modern authentication or certificate-based app-only authentication.
- No scripts store passwords in plain text.
- Scripts reviewed for hardcoded credentials and moved to Key Vault or managed identity where possible.
Applications
- Applications reading mailboxes migrated to Microsoft Graph with app registrations.
- Application mailbox access restricted to specific mailboxes (RBAC for Applications).
- Old app registrations and secrets removed.
Monitoring
- Conditional Access policy blocking legacy authentication is on.
- Alerts for any successful legacy authentication.
Documentation
- A list of remaining exceptions with owners and retirement dates.
- Exchange Online Basic Auth Turned Off (Oct 2022): The End of an Era Platform Changes
- How to Verify Legacy Authentication Is Fully Blocked in Your Tenant How-To & Hardening
- CIO Brief: What Broke When Basic Auth Died — and What Got Safer CIO Briefings