How to Fix Python SMTP Error 535 After Basic Authentication Is Disabled
Question details
The user needs to resolve an SMTP Error 535 in their Python script because Microsoft Exchange has deprecated basic authentication.

- Product
- Microsoft Exchange / Python
- Device & OS
- not provided
- Scenario
- Attempting to send automated emails via a Python script using Microsoft 365 or Exchange Online.
- Observed behavior
- The email script fails to execute and returns SMTP Error 535 Authentication Failed, blocking the outbound messages.
Ensure you have administrative access to your Microsoft Azure Active Directory (Entra ID) portal to register applications and configure OAuth 2.0 API permissions.
Migrate Python Script to OAuth 2.0 Authentication
Update your Python email script to authenticate using OAuth 2.0 tokens rather than relying on standard username and password credentials.
Microsoft has permanently disabled Basic Authentication for Exchange Online to improve data security. To restore email sending functionality, developers must transition their automated scripts to Modern Authentication (OAuth 2.0). This process involves registering an application in Azure and generating a secure access token.
Log in to the Microsoft Entra ID (Azure AD) admin center. Go to 'App registrations', click 'New registration', and configure the application name and supported account types.
Navigate to 'API permissions' within your new app. Add a permission for Microsoft Graph, select 'Application permissions', and check 'Mail.Send'. Grant admin consent for your organization.
Go to 'Certificates & secrets' and create a new client secret. Copy the secret value immediately, as it will be hidden after you leave the page.
Install the Microsoft Authentication Library (MSAL) for Python via pip. Modify your script to request an access token using your Client ID, Tenant ID, and Client Secret.
Use the retrieved access token to construct an XOAUTH2 encoded string. Pass this string into your smtplib connection using the 'docmd("AUTH", "XOAUTH2 " + auth_string)' command to securely authenticate.

Use an App Password as a Temporary Workaround
If OAuth 2.0 implementation is currently blocked, generate a dedicated App Password if your organization's security policies still permit it.
Try WPS Office for Your Document Management Needs
While resolving complex Exchange connection errors and backend scripting issues, you can simplify your daily document workflow with WPS Office. As a lightweight, highly compatible alternative to Microsoft Office, it handles Word, Excel, and PowerPoint files effortlessly.
- 1. Download the Installer: Visit the official WPS Office website and click on the 'Download' button for your operating system.
- 2. Install WPS Office: Run the downloaded installation file and follow the simple on-screen instructions to set up the software.
- 3. Open and Edit Documents: Launch WPS Office to instantly open, edit, and save your existing Microsoft Office format documents with perfect formatting.

Frequently Asked Questions
Why did Microsoft disable Basic Authentication for SMTP?
Microsoft disabled Basic Authentication across Exchange Online to enhance security. Basic Authentication passes credentials in plain text or simple encoding, making it highly vulnerable to brute-force attacks and credential stuffing. Modern Authentication (OAuth 2.0) uses token-based verification, which is significantly more secure.
Does Python's smtplib support OAuth 2.0?
Yes, Python's built-in smtplib library can handle OAuth 2.0. However, instead of passing a regular password, you must generate an XOAUTH2 encoded string containing the user's email address and the OAuth 2.0 access token, then send it using the SMTP AUTH command.
Can I still use SMTP port 587 with OAuth 2.0?
Yes. The transition to OAuth 2.0 changes how the authentication string is processed, but the connection protocol remains the same. You should still connect to smtp.office365.com on port 587 and initiate TLS encryption using the starttls() method.
What if my Python script is running on a server without a UI?
If your script runs on a headless server, you should configure the Azure AD application to use 'Client Credentials Grant' or a background service daemon approach, allowing the script to authenticate autonomously without requiring interactive user login prompts.




