Fix TLS 1.2 Access Denied When Sending Email Through Microsoft 365 SMTP
Question details
A line-of-business application fails to send emails through Microsoft 365 SMTP, displaying a TLS 1.2 access denied error despite using valid credentials.

- Product
- Microsoft 365 Exchange Online
- Device & OS
- not provided
- Scenario
- Sending automated emails from a third-party application using smtp.office365.com on port 587 with SSL.
- Observed behavior
- Network traces show a TLS 1.2 access denied error and the application cannot send emails, even though standard PowerShell commands like Send-MailMessage work successfully with the same credentials.
Verify that your Microsoft 365 global administrator account is accessible and ensure your line-of-business application is updated to its latest version to natively support modern security protocols.
Verify Application Support for TLS 1.2
Ensure your third-party application natively supports TLS 1.2, as Microsoft 365 actively rejects connections using older deprecated protocols like TLS 1.0 and 1.1.
Microsoft has deprecated TLS 1.0 and 1.1 in Microsoft 365 to ensure data security. If your application hardcodes older TLS versions or relies on outdated frameworks, the connection to smtp.office365.com will be immediately denied, regardless of whether the credentials are correct.
Review the official documentation or contact the vendor of your line-of-business application to explicitly confirm it supports TLS 1.2 or higher for SMTP connections.
Update the application to its latest release or apply any necessary security patches provided by the developer.
If the application relies on the .NET framework, ensure it is running on .NET 4.6.2 or later. If it runs on an older version, you may need to update the registry to force strong cryptography on the host server.

Configure SMTP Client Submission Correctly
Double-check that your application is configured with the exact settings required for Microsoft 365 SMTP client submission.
Open a Support Request with Microsoft 365
If the application officially supports TLS 1.2 but still fails to connect, request advanced backend trace analysis from Microsoft Support.
Looking for a Lightweight Alternative to Microsoft Office?
While resolving backend Exchange server and SMTP connection issues, consider WPS Office for your everyday document tasks. It is a completely free, lightweight, and highly compatible alternative to Microsoft Office that ensures seamless workflow continuity without heavy resource requirements.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button.
- 2. Install the Software: Run the lightweight installer and follow the simple on-screen prompts to set up the suite on your device.
- 3. Start Creating: Open WPS Office and seamlessly continue working with your existing Microsoft Office files.

Frequently Asked Questions
Why is Microsoft 365 denying access despite correct SMTP credentials?
Microsoft 365 strictly enforces TLS 1.2 or higher for security purposes. Even with valid credentials, if your application attempts to connect using deprecated protocols like TLS 1.0 or 1.1, the SMTP relay server will automatically deny access.
Why does Send-MailMessage work while my specific app fails?
The PowerShell command 'Send-MailMessage' utilizes your operating system's default security protocols, which generally default to modern TLS 1.2. However, third-party applications may be hardcoded to use older TLS versions internally, causing them to fail on the same machine.
How can I check if my line-of-business application supports TLS 1.2?
You should review the official documentation provided by the application's vendor, check for recent software updates, or consult their technical support team. Applications built on outdated frameworks may require manual patching or framework updates to enable modern TLS.




