Fix Authenticated SMTP Settings Not Saving in Exchange Online
Question details
The user is unable to save Authenticated SMTP settings in Exchange Online, causing an ERP application to return error 535 because basic authentication is disabled.

- Product
- Exchange Online
- Device & OS
- not provided
- Scenario
- Configuring email integration for an ERP application or line-of-business software to send emails through Microsoft 365.
- Observed behavior
- Exchange Online fails to save the Authenticated SMTP settings in the admin center, and the connected ERP application throws an error 535 authentication failure.
Before modifying authentication settings, ensure you have Exchange Administrator credentials and have installed the Exchange Online PowerShell module on your system.
Update Authentication Policies via Exchange Online PowerShell
Use PowerShell to override global blocks by creating and assigning a targeted authentication policy that permits SMTP authentication for specific accounts.
A globally assigned authentication policy or Microsoft's default security settings may block legacy authentication, even if individual mailbox settings in the Exchange admin center appear correct.
Creating a separate, dedicated policy allows you to enable SMTP basic authentication exclusively for the required account or device (like your ERP application) without compromising your entire tenant's security.
Open your PowerShell terminal as an administrator and connect to Exchange Online by running the appropriate connection cmdlets for your environment.
Run the command 'Get-AuthenticationPolicy' to identify if a global policy is actively blocking legacy authentication methods in your tenant.
Create a specific policy to allow basic SMTP authentication by executing: New-AuthenticationPolicy "Allow only BasicAuth SMTP" -AllowBasicAuthSMTP.
Apply this new policy to the specific email account used by your ERP application by running: Set-User -Identity <email address> -AuthenticationPolicy "Allow only BasicAuth SMTP".
Run 'Get-User -Identity <email address>' to verify the assignment. Allow approximately one hour for the policy changes to fully propagate across the Microsoft 365 servers.

Try WPS Office: A Lightweight and Powerful Productivity Suite
While resolving backend server configurations in Microsoft 365, you may also need a fast, reliable desktop application to view and edit your reports. WPS Office is a completely free, lightweight alternative that handles your documents seamlessly.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install the Suite: Run the installer package and follow the on-screen instructions to complete the setup in just a few minutes.
- 3. Open Your Documents: Launch WPS Office to immediately start creating, opening, and editing your Word, Excel, and PowerPoint files without formatting issues.

Frequently Asked Questions
Why does my ERP application return error 535 when connecting to Microsoft 365?
Error 535 usually indicates an authentication failure. In Exchange Online, this often happens because Basic Authentication is disabled globally via security defaults or authentication policies, blocking standard SMTP logins from third-party apps.
Can I enable Authenticated SMTP through the Microsoft 365 admin center interface?
Sometimes the Modern Authentication settings page malfunctions or global policies override the UI settings. In these cases, even if you check the box to enable Authenticated SMTP in the admin center, it will not save or apply correctly, making PowerShell the only reliable method.
Is it safe to allow basic authentication for SMTP?
While modern authentication (OAuth) is significantly more secure and recommended by Microsoft, legacy devices like older printers, scanners, or certain line-of-business applications may only support basic authentication. To minimize risk, you should restrict basic authentication strictly to the individual accounts that require it.
How do I check if my new authentication policy was successfully applied?
You can verify the policy assignment by running 'Get-User -Identity <email address>' in Exchange Online PowerShell and checking the AuthenticationPolicy property in the command output.




