Knowledge CenterAPI ReferencesDalil MCPClaude Skills

Enable SMTP AUTH in Microsoft 365

Turn on Authenticated SMTP for a Microsoft 365 mailbox so it can send your Dalil sequences: admin center steps, PowerShell fallback, and the usual blockers.

Updated September 16, 20265 min read

Microsoft disables Authenticated SMTP (SMTP AUTH) by default on most Microsoft 365 tenants. Until an admin turns it on for a mailbox, anything sending through that mailbox over SMTP is refused at authentication, so your sequence emails never leave. Enabling it takes about two minutes per mailbox in the Microsoft 365 admin center.

This is a setting on Microsoft's side, not in Dalil. You only need to do it once per sending mailbox.

Before you start

  • You need Global Administrator or Exchange Administrator rights on the tenant. A regular user cannot change this setting on their own mailbox.
  • The mailbox has to be hosted in Exchange Online. On-premises and hybrid mailboxes are governed by your own Exchange server instead.
  • The setting is per mailbox, not per domain. Repeat it for every mailbox you plan to send from.

Enable Authenticated SMTP for a mailbox

  1. Sign in to the Microsoft 365 admin center as an admin
  2. Go to Users β†’ Active users
  3. Select the user whose mailbox will send your sequences
  4. Open the Mail tab in the panel that opens
  5. Under Email apps, click Manage email apps
  6. Tick Authenticated SMTP
  7. Click Save changes

The change usually applies within a few minutes, though Microsoft can take up to an hour to propagate it across the tenant. If the mailbox is already connected to Dalil, reconnect it afterwards so the new permission is picked up.

πŸ’‘

Sending from several mailboxes is the right way to run volume safely, and each one needs this box ticked. If you are enabling more than a handful, use the PowerShell method below and do them in one pass.

If Authenticated SMTP is greyed out or will not stay on

Three tenant-level settings override the per-mailbox toggle. Check them in this order.

Security defaults are enabled. Security defaults block legacy authentication across the whole tenant, and SMTP AUTH is covered by that block. You will find the switch in the Microsoft Entra admin center under Properties β†’ Manage security defaults.

⚠️

Turning security defaults off removes baseline MFA enforcement for every account in the tenant. Only do this if you have Conditional Access policies that cover the same ground, and keep SMTP AUTH enabled on sending mailboxes only.

SMTP AUTH is disabled organization-wide. In the Exchange admin center, go to Settings β†’ Mail flow and check Turn off SMTP AUTH protocol for your organization. The per-mailbox setting takes precedence over the organization setting, so a mailbox you explicitly enabled will still work, but leaving the org-wide block in place is what causes mailboxes to "lose" the setting later.

An authentication policy blocks basic authentication for SMTP. If your tenant has an authentication policy that disables basic auth for SMTP, clients cannot use the protocol even with everything above enabled. SMTP AUTH itself supports OAuth as well as basic authentication, so the fix is usually to allow the mailbox in the policy rather than to weaken it tenant-wide.

Doing it in PowerShell

Connect to Exchange Online PowerShell, then enable a single mailbox:

Set-CASMailbox -Identity "sales@yourdomain.com" -SmtpClientAuthenticationDisabled $false

Check that it worked. False means SMTP AUTH is enabled, True means disabled, and blank means the mailbox follows the organization setting:

Get-CASMailbox -Identity "sales@yourdomain.com" | Format-List SmtpClientAuthenticationDisabled

Enable a list of mailboxes at once, one address per line in the text file:

$Allow = Get-Content "C:\mailboxes.txt"
$Allow | foreach {Set-CASMailbox -Identity $_ -SmtpClientAuthenticationDisabled $false}

To lift an organization-wide block:

Set-TransportConfig -SmtpClientAuthenticationDisabled $false

Microsoft 365 SMTP settings

If you are asked for server details, these are Microsoft's:

  • Server: smtp.office365.com
  • Port: 587
  • Encryption: STARTTLS
  • Username: the full email address of the mailbox

Connect the mailbox to Dalil

With Authenticated SMTP on, connect the mailbox under Settings β†’ Core Integrations β†’ Add Email, choose Microsoft, and complete the sign-in. The full walkthrough, including calendar sync and visibility settings, is in Integrate your Email & calendar.

Two things to do before the mailbox carries real outbound:

ℹ️

If you bought your Microsoft 365 mailboxes through a reseller such as GoDaddy, some of these controls live in the reseller's own email dashboard and the Microsoft admin center may not expose them. Enable Authenticated SMTP there, or move the tenant to direct Microsoft billing.

FAQ

Do I have to do this for every mailbox? Yes. Authenticated SMTP is a per-mailbox setting, so each sender you add needs it. The PowerShell list method handles a batch in one command.

Does enabling SMTP AUTH weaken our security? It re-opens one authentication path on the mailboxes you choose. Keep it limited to sending mailboxes, leave MFA and Conditional Access in place for everyone, and prefer OAuth over basic authentication where your tooling supports it.

I enabled it and sending still fails. What now? Work through the three tenant-level blockers above, in order: security defaults, the organization-wide SMTP AUTH toggle, then authentication policies. Also allow up to an hour for the change to propagate before retesting.

Does this affect the mailbox's normal Outlook use? No. Outlook, Outlook on the web and the mobile apps do not use SMTP AUTH to send, so the person using the mailbox will not notice any difference.

Key outcome

Authenticated SMTP is the switch that decides whether a Microsoft 365 mailbox can send programmatically at all. Turn it on for each sending mailbox, confirm no tenant-level policy is overriding it, then warm the mailbox up before pointing sequences at it.

Was this article helpful?

Your feedback helps us improve our documentation.