Quick troubleshooting view
An application using smtp.office365.com can no longer be authenticated and receives 535 5.7.119.
- SMTP AUTH disabled on the box
- SMTP AUTH deactivated at the organizational level
- inherited authentication blocked
- Check account.
- Control SMTP AUTH
- Validate TLS and port
- enable SMTP AUTH only for the box that needs it
- migrating to a modern method when the application allows
- correct the account and port used
Contextual technician plan
Ensure that the identifiers work and the box is active.
East-Transport Config, Format-List SmtpClientAuthent InformationDisabledThe command should complete without an unexpected error and return data consistent with the intended service.
If the result is normal, keep this layer lower in the hypothesis ranking and continue with the next discriminating check.
If the result is abnormal, preserve the output and investigate this layer before making broader changes.
Check the box and organization settings.
The result is that the user is not able to use the same format as the user.The command should complete without an unexpected error and return data consistent with the intended service.
If the result is normal, keep this layer lower in the hypothesis ranking and continue with the next discriminating check.
If the result is abnormal, preserve the output and investigate this layer before making broader changes.
Test 587 with ▼TLS.
“Validate TLS and port” should produce an observation that clearly confirms or rules out “inherited authentication blocked”.
If the observation is normal, lower “inherited authentication blocked” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “inherited authentication blocked” first. Related action: correct the account and port used.
Control SecurityBlots, Conditional Access and restrictions of authentication.
“Checking policies” should produce an observation that clearly confirms or rules out “poor identifiers or security policy”.
If the observation is normal, lower “poor identifiers or security policy” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “poor identifiers or security policy” first. Related action: document the safety exception.
Repeat the same validation test after the correction and confirm the original symptom is gone. Validate stability before closing the incident.
Before changing configuration, record the current value and a way back.
If the application does not support any modern method and the activation of SMTP AUTH is incompatible with security policy.
An application using smtp.office365.com can no longer be authenticated and receives 535 5.7.119.
Causes probables
- SMTP AUTH disabled on the box
- SMTP AUTH deactivated at the organizational level
- inherited authentication blocked
- poor identifiers or security policy
Diagnostic étape par étape
- 1
Check account.
Ensure that the identifiers work and the box is active.
- 2
Control SMTP AUTH
Check the box and organization settings.
- 3
Validate TLS and port
Test 587 with ▼TLS.
- 4
Checking policies
Control SecurityBlots, Conditional Access and restrictions of authentication.
Commands utiles
East-Transport Config, Format-List SmtpClientAuthent InformationDisabledThe result is that the user is not able to use the same format as the user.Solutions possibles
- enable SMTP AUTH only for the box that needs it
- migrating to a modern method when the application allows
- correct the account and port used
- document the safety exception
If the application does not support any modern method and the activation of SMTP AUTH is incompatible with security policy.