logo
search
Exchange Connection Problems

Fix TLS 1.2 Access Denied When Sending Email Through Microsoft 365 SMTP

Natalie TaylorNatalie Taylor Sep 30, 2026 868 views

Question details

A line-of-business application fails to send emails through Microsoft 365 SMTP, displaying a TLS 1.2 access denied error despite using valid credentials.

How to Fix TLS 1.2 Access Denied When Sending Email Through Microsoft 365 SMTP
Product
Microsoft 365 Exchange Online
Device & OS
not provided
Scenario
Sending automated emails from a third-party application using smtp.office365.com on port 587 with SSL.
Observed behavior
Network traces show a TLS 1.2 access denied error and the application cannot send emails, even though standard PowerShell commands like Send-MailMessage work successfully with the same credentials.
Before you start

Verify that your Microsoft 365 global administrator account is accessible and ensure your line-of-business application is updated to its latest version to natively support modern security protocols.

Solution 1Recommended

Verify Application Support for TLS 1.2

Ensure your third-party application natively supports TLS 1.2, as Microsoft 365 actively rejects connections using older deprecated protocols like TLS 1.0 and 1.1.

Microsoft has deprecated TLS 1.0 and 1.1 in Microsoft 365 to ensure data security. If your application hardcodes older TLS versions or relies on outdated frameworks, the connection to smtp.office365.com will be immediately denied, regardless of whether the credentials are correct.

1
Check Vendor Documentation

Review the official documentation or contact the vendor of your line-of-business application to explicitly confirm it supports TLS 1.2 or higher for SMTP connections.

2
Apply Software Updates

Update the application to its latest release or apply any necessary security patches provided by the developer.

3
Update the Underlying Framework

If the application relies on the .NET framework, ensure it is running on .NET 4.6.2 or later. If it runs on an older version, you may need to update the registry to force strong cryptography on the host server.

Verify Application Support for TLS 1.2
Free Microsoft Office alternative

Looking for a Lightweight Alternative to Microsoft Office?

While resolving backend Exchange server and SMTP connection issues, consider WPS Office for your everyday document tasks. It is a completely free, lightweight, and highly compatible alternative to Microsoft Office that ensures seamless workflow continuity without heavy resource requirements.

  1. 1. Download the Installer: Visit the official WPS Office website and click the free download button.
  2. 2. Install the Software: Run the lightweight installer and follow the simple on-screen prompts to set up the suite on your device.
  3. 3. Start Creating: Open WPS Office and seamlessly continue working with your existing Microsoft Office files.
100% free and extremely lightweight on system resourcesFully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx)Familiar user interface requiring no learning curve or retrainingIncludes built-in advanced PDF editing and conversion tools
microsoft office alternative - wps office

Frequently Asked Questions

Why is Microsoft 365 denying access despite correct SMTP credentials?

Microsoft 365 strictly enforces TLS 1.2 or higher for security purposes. Even with valid credentials, if your application attempts to connect using deprecated protocols like TLS 1.0 or 1.1, the SMTP relay server will automatically deny access.

Why does Send-MailMessage work while my specific app fails?

The PowerShell command 'Send-MailMessage' utilizes your operating system's default security protocols, which generally default to modern TLS 1.2. However, third-party applications may be hardcoded to use older TLS versions internally, causing them to fail on the same machine.

How can I check if my line-of-business application supports TLS 1.2?

You should review the official documentation provided by the application's vendor, check for recent software updates, or consult their technical support team. Applications built on outdated frameworks may require manual patching or framework updates to enable modern TLS.