If you’ve got a copier that scans to email, an alarm system that sends alerts, or a business application that emails invoices and order confirmations, this one’s for you.

Microsoft has been winding down Basic Authentication for years. In January they published an updated timeline for the last piece still standing — the method your devices and applications use to send mail through Microsoft 365. The dates moved. The direction didn’t.

One thing this isn’t about: how your people log in. Microsoft is retiring text-message and phone-call verification on its own separate track — we covered that in The Text Message Code Is Going Away. Same vendor, same year, two different projects. This one is about the machines that send mail, not the people who read it.

The dates

Now through December 2026. Nothing changes.

End of December 2026. Microsoft switches it off by default on existing tenants. Your IT team can still turn it back on.

New tenants after December 2026. Not available at all.

Second half of 2027. Microsoft announces the final shut-off date. That one has no override.

So you have runway. What you don’t have is a reason to wait.

What’s probably affected

Most businesses have more of these than they think:

  • Copiers and scanners with scan-to-email
  • Alarm, access control, and camera systems sending alerts
  • Accounting, ERP, and practice management systems sending invoices and statements
  • Web forms that email submissions to a shared inbox
  • Old scripts nobody has looked at in years

These rarely live in one place — some on a server in your closet, some hosted by a vendor, some baked into hardware. There’s no dashboard that lists them all.

Why “we’ll just turn it back on” isn’t a plan

The December change is a default, not a deadline. Plenty of businesses will flip it back on and move on.

That doesn’t solve anything. It schedules the same fire drill for a date Microsoft hasn’t announced yet, and next time there’s no switch. It also leaves in place what Microsoft is retiring for a reason: a username and password sitting in a copier’s settings is one of the easiest ways into your environment. Those credentials don’t prompt for MFA, they usually don’t expire, and nobody notices when they get used at 2 a.m.

We see it constantly: a service account set up for a scanner in 2019, password never changed, whoever configured it gone two jobs ago, still sending mail as your company.

Microsoft’s replacements don’t cover everyone

Microsoft’s answer is modern authentication, or one of their purpose-built sending options. Right instinct — narrower than it sounds.

Modern authentication is the clean fix when your application supports it. Plenty don’t — your copier probably doesn’t, and neither does much of the industry-specific software small businesses run. If the vendor never built it, there’s nothing to configure.

The alternatives mostly share one catch: they only deliver inside your own organization. High Volume Email, Microsoft’s newest option, went live this spring and started billing June 1 — and it won’t send to anyone outside your company. Neither will Direct Send. The one option that does reach outside needs a dedicated static internet address and won’t work for cloud-hosted applications. Past that you’re into an Azure project to make a copier send a scan.

So the moment something needs to email someone outside your company — a customer, a vendor, a patient — the easy options fall away. This was never just a security setting. Microsoft is getting out of the business of relaying mail for whatever you point at it.

What to do now

Find out what you actually have. Guessing won’t cut it — the list has to come from the logs. Your IT provider can pull every device and application sending mail through your tenant, and it almost always turns up something nobody remembered.

Split that list into internal-only and external. That one split decides most of your path.

Ask your vendors about modern authentication. Supported, on the roadmap, or never coming. “Never coming” just means the fix lives somewhere else.

Clean house while you’re in there. Every old service account is a mailbox you may be paying for and a credential you’re carrying risk on.

Then pick your path. Once you know what has to send externally, the right setup gets obvious — for most businesses that means consolidating that traffic somewhere built for it, so you configure it once instead of rebuilding every time Microsoft changes a default.

The bottom line

The direction is set. The businesses that handle this well will take inventory now and move on their own schedule — not on a holiday weekend when the invoices stop going out.

K&J clients: we’re already pulling this inventory across the environments we manage, and we’ll bring you your list along with what it means for your setup.

Not a client? The inventory is worth doing regardless, and it isn’t a big lift. Reach out and we’ll tell you what’s actually sending mail through your tenant.

Thanks,

Kyle

Sources