logo
search
Conditional Access Problems

Fix PHPMailer SMTP Error 535 Authentication Unsuccessful in Microsoft 365

Partner EditorPartner Editor Sep 28, 2026 869 views

Question details

The user needs to resolve an SMTP authentication failure when sending emails via PHPMailer through Microsoft 365.

Fix PHPMailer SMTP Error 535 Authentication Unsuccessful in Microsoft 365
Product
Microsoft 365
Device & OS
not provided
Scenario
Attempting to send an email using PHPMailer configured with smtp.office365.com.
Observed behavior
PHPMailer connects and completes STARTTLS but fails authentication with error 535 5.7.139 because the organization's security policy blocks the sign-in method.
Before you start

Ensure you have administrative access to the Microsoft 365 tenant or can contact your IT administrator, as resolving this issue requires modifying server-side security policies and mailbox settings.

Solution 1Recommended

Verify Mailbox Settings and Administrator Policies

Check if authenticated SMTP is enabled for the specific mailbox and ensure Conditional Access policies allow the connection.

Microsoft 365 disables Basic Authentication by default for most tenants to improve security. If your PHPMailer script relies on a standard username and password, it will be blocked unless explicitly permitted by the administrator.

1
Check Account Status

Verify that the Microsoft 365 account being used is active, the password is correct, and it is not locked.

2
Enable Authenticated SMTP

Have your Microsoft 365 administrator log into the Microsoft 365 Admin Center, navigate to Active Users, select the specific user account, go to the Mail tab, click 'Manage email apps', and ensure that 'Authenticated SMTP' is checked.

3
Review Security Policies

Ask the administrator to check the Azure portal for Security Defaults or Conditional Access policies that might be blocking legacy authentication (Basic Authentication) for the account.

Verify Mailbox Settings and Administrator Policies
Basic Authentication Deprecation: Microsoft is actively deprecating Basic Authentication. Even if you enable Authenticated SMTP temporarily, it is highly recommended to migrate to Modern Authentication.
Free Microsoft Office alternative

Looking for a Reliable Office Suite? Try WPS Office

While you are troubleshooting Microsoft 365 email integrations and server policies, if you need a lightweight, free, and highly compatible office suite for your daily document tasks, WPS Office is an excellent alternative. It seamlessly handles Microsoft Office formats without the heavy subscription fees or complex administrative configurations.

Free to use for daily document editingFully compatible with Microsoft Word, Excel, and PowerPoint formatsLightweight and runs smoothly on Windows, Mac, and LinuxFamiliar user interface for a seamless transition
QA img-9

Frequently Asked Questions

Why am I getting error 535 5.7.139 in Microsoft 365?

This error occurs when your organization's security policies, such as Security Defaults or Conditional Access, block the legacy sign-in method (Basic Authentication) used by your application to send emails.

Can I use an App Password to bypass this SMTP error?

App passwords might work if Multi-Factor Authentication (MFA) is enforced but basic authentication is still permitted by the tenant. However, relying on app passwords is not recommended as Microsoft continues to phase out legacy authentication in favor of OAuth 2.0.

How do I know if Authenticated SMTP is disabled for my account?

Your Microsoft 365 administrator can check this in the Microsoft 365 Admin Center by selecting your user profile, navigating to the Mail tab, and checking the 'Manage email apps' section to see if Authenticated SMTP is checked.