Call Us

Scan to Email Stopped Working on Microsoft 365

Frequently asked questions

Why has my printer stopped sending scans to email?

In a Microsoft 365 environment the usual cause is authentication rather than the device. The copier signs in to Exchange Online with a username and password, and that method is being withdrawn. It also breaks when the password on the mailbox it uses is changed or expires, when multi-factor authentication is applied to that account, or when security defaults are switched on in Microsoft Entra ID, because SMTP basic authentication is not compatible with security defaults.

When is Microsoft turning off SMTP AUTH basic authentication?

Behaviour is unchanged until December 2026. At the end of December 2026 SMTP AUTH basic authentication is disabled by default on existing tenants, although an administrator can still turn it back on. Tenants created after that date cannot use it at all. Microsoft has said it will announce the final removal date during the second half of 2027, and after that it cannot be re-enabled by anyone.

Will my scanner stop working at the end of December 2026?

Not permanently, and not without a way back. The end of December 2026 change flips the default, so a device using basic authentication stops sending until an administrator re-enables SMTP AUTH on the tenant. That is a reprieve rather than a fix, because the setting disappears entirely once Microsoft announces the final removal date. Treat December 2026 as the date you find out which devices are affected, not the date you solve it.

How do I find out which devices are using SMTP AUTH?

Three places. The SMTP AUTH clients report in the Exchange admin center lists the accounts and IP addresses that have submitted mail recently. Message trace shows what each device has actually sent. And the devices themselves hold the answer in their send settings: anything configured with smtp.office365.com on port 587 or 25 with a username and password is using the method being withdrawn. Walking the fleet is usually faster than inferring it from logs, because a device that only scans occasionally may not appear in a short reporting window.

What does it mean if my device only offers port 465?

It means the device almost certainly cannot do what Microsoft now requires. Microsoft states that a device recommending or defaulting to TCP port 465 does not support the versions of TLS needed for client SMTP submission, which are TLS 1.2 or TLS 1.3. A device in that position needs either a firmware update that adds modern TLS, or a different sending method such as an SMTP relay connector, or replacement.

What is the difference between SMTP relay and Direct Send?

An SMTP relay connector authenticates the device to Microsoft 365 using a TLS certificate or a static public IP address, and it can send to recipients outside your organisation. Direct Send authenticates nothing and can only deliver to recipients inside your own tenant, so a scan emailed to a client or a solicitor is rejected. Direct Send is also the method Microsoft has said it is working on disabling by default, so it is the weakest of the options to build on.

Does the mailbox a scanner sends from need a licence?

For client SMTP submission, yes. Microsoft requires a licensed Microsoft 365 mailbox for the device to send from, and the address of that mailbox appears as the sender. An SMTP relay connector does not need a licensed mailbox and can send from an address that has no mailbox at all, such as a no-reply address, which is usually the cheaper arrangement where several devices are involved.

Is scan to folder a safer option than scan to email?

It avoids this particular problem, because scanning to a network folder or to a document management system does not involve Exchange Online at all. It brings its own requirements around permissions, SMB versions and retention, so it is a change of approach rather than a workaround. Where scans are being emailed to the person who then files them, scanning straight into the filing system is usually the better answer regardless of what Microsoft does to authentication.

Paul Benson, Technology Director at Mastercopy
Written by
Paul Benson
Technology Director, Mastercopy

Paul is Technology Director at Mastercopy, where he heads the company's technology direction, manages its relationship with HP and leads the development of DocFlow, Mastercopy's document management platform. He has 18+ years across enterprise technology, infrastructure and systems architecture.

Find out which of your devices go quiet in January

We will inventory everything on your network that sends email, record how each one authenticates, and give you a written list of what needs firmware, a relay connector or replacing before the end of December 2026. We maintain the devices and we run the tenant, so it is one visit, not two suppliers.

ISO 27001 and ISO 9001 certified · Cyber Essentials · Same-day on-site engineer cover nationwide · Family owned since 1989