Jump to content

Recommended Posts

Posted
Hopefully now the end date is announced they will get moving. Any solution that relies upon basic auth in 2024 needs to get back in the sea.
Posted
Just curious how this will work with printer/photocopier manufacturers who have 1990's web interfaces - there are quite a few out there!
You can use direct send as long as you only need to send internally. No authentication required for that so shouldn't be affected by this if I understand it right.
Posted

I'm not sure, what I'm unclear about (as quoted off Microsoft's website) SMTP Auth now supports OAuth, but most devices haven't been patched to support this. Only SMTP Auth with Basic Authentication, which I presume what 99% of Admins are implementing, even if you're using a software layer such as Papercut.

 

I believe Papercut supports OAuth, but like I say, in smaller environments using the MFPs own 1990's interface I can only see this working after a firmware patch.

Posted
It's super easy to put an MTA on the network for older devices to connect to and relay to exchange via oauth. This change shouldn't affect anyone.
Posted
It's super easy to put an MTA on the network for older devices to connect to and relay to exchange via oauth. This change shouldn't affect anyone.

 

Raspberry Pi's time to shine. Again.

Posted

I think the suitable alternative will be a Microsoft High Volume account, which is currently in preview.

 

This allows -

 

- Emails to be sent internally to your tenancy

- Supports third party applications

- Uses Port 587

- Requires TLS

 

So almost identical to what we're doing now, so I suspect Admins would just need to enroll existing O365 accounts as Microsoft High Volume. I believe we'll be able to specify 20 accounts per tenancy which is plenty.

 

This is far more straight forward than OAuth2, such as Papercut's guidance which just made my head hurt.

Posted

And uses smtp-hve.office365.com instead of smtp.office365.com

 

I'm not entirely clear why or how this is any more secure than an existing account, given the parameters are pretty much identical.

  • 3 months later...
Posted

We are a new Tenant with "security defaults" enabled and this disabled all legacy SMTP auth including via HVE. Is there more granular setting somewhere in m365 as we still want to enforce MFA for most users. Account for scan to email from MFD can be exempt.

 

Links

 

Security Defaults

https://learn.microsoft.com/en-gb/entra/fundamentals/security-defaults

 

Basic Auth Retirement

https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-online-to-retire-basic-auth-for-client-submission-smtp/ba-p/4114750

 

HVE

https://learn.microsoft.com/en-gb/Exchange/mail-flow-best-practices/high-volume-mails-m365

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...