How to Troubleshoot Legacy SMTP AUTH on Port 587 with TLS
Question details
Users need to resolve sign-in failures that occur when configuring legacy applications to send email via SMTP AUTH over port 587 with TLS.
- Product
- Microsoft Entra ID
- Device & OS
- not provided
- Scenario
- Connecting a legacy application or service to an email server using SMTP AUTH on port 587 for outbound communications.
- Observed behavior
- Sign-ins over port 587 with TLS fail and are flagged by the system as risky sign-ins due to authentication policy blocks.
Ensure you have global administrator or security administrator privileges in the Microsoft Entra ID portal to view sign-in logs and modify Conditional Access policies.
Review Microsoft Entra ID Risk Controls and Authentication Logs
Identify the root cause of the risky sign-in blocks by analyzing Entra ID logs and adjusting trusted IP configurations.
Legacy authentication protocols like SMTP AUTH do not support modern Multi-Factor Authentication (MFA), causing Microsoft Entra ID to flag them as risky sign-ins by default.
To resolve this, you must configure Conditional Access to trust the source IP, which requires an appropriate Microsoft Entra ID Premium license.
Log in to the Microsoft Entra ID admin center, navigate to 'Monitoring', and select 'Sign-in logs' to identify the specific blocked legacy SMTP sign-in attempts.
If you hold a Premium license, navigate to 'Security' > 'Conditional Access' > 'Named locations' to add the application's static IP address as a trusted location.
Create a new Conditional Access policy that excludes your newly created trusted IP location from the strict MFA requirements for that specific application account.
Because this involves complex Microsoft Defender configurations, post your specific error details in the Microsoft Defender for Cloud section on Microsoft Q&A, or open an official Microsoft Support request via your portal.
Verify Mailbox-Level SMTP AUTH Status
Ensure that the specific Exchange Online mailbox used by the application is explicitly allowed to use SMTP authentication.
Switch to WPS Office for a Hassle-Free Experience
Troubleshooting advanced Microsoft Exchange and Entra ID network configurations can be highly complex and time-consuming. If you are looking for a reliable, lightweight, and completely free alternative to Microsoft Office for your daily document workflows, try WPS Office. It provides a full suite of robust editing tools without the overhead of complex enterprise network setups.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install the Software: Run the downloaded installer and follow the quick on-screen instructions to set up the suite.
- 3. Open Existing Documents: Launch WPS Office and directly open your existing Microsoft Office files without needing any format conversion.

Frequently Asked Questions
Why are my SMTP AUTH sign-ins flagged as risky?
Microsoft Entra ID uses advanced security defaults that often flag legacy authentication protocols, such as SMTP AUTH over port 587, as risky. This happens because legacy protocols generally do not support modern Multi-Factor Authentication (MFA) prompts.
Do I need a special license to whitelist IP addresses for SMTP?
Yes, utilizing Trusted IP locations and creating targeted Conditional Access policies to bypass MFA requirements typically requires a Microsoft Entra ID Premium P1 or P2 license.
How do I get expert help for Microsoft Defender network security configurations?
You can escalate the issue by posting your specific configuration details in the Microsoft Defender for Cloud section on Microsoft Q&A, or by opening a direct technical support ticket from your Azure or Microsoft 365 admin portal.




