Microsoft is deprecating Basic Authentication for Exchange Online SMTP. If your organisation uses Microsoft 365 (Exchange Online) to send emails, you must migrate to OAuth2 authentication. This section explains how to configure eFront to use Microsoft OAuth2 for SMTP.
| Note: This applies only if you are using a Microsoft 365 / Exchange Online SMTP server. If you are using Gmail, Sendmail, or any other non-Microsoft SMTP provider, Basic Authentication continues to work and no changes are required. |
Before starting, ensure you have:
- A Microsoft 365 account with Exchange Online
- Access to the Azure Portal (portal.azure.com) with permissions to create an App Registration
- Admin access to your eFront platform
Step 1 How to get the Microsoft Teams tenant ID and the Microsoft Teams client ID
- Sign in to the Microsoft Azure portal with your account.
-
Go to Manage Azure Active Directory (1).
-
Click App registrations (2) from the left menu bar and then on New registration (3) to create a new application.
-
Add a name (4) for the new app and set Who can use this application or access this API to Accounts in this organizational directory only (Default Directory only - Single tenant) (5). Add a Redirect URI, select "Web" and enter your eFront Redirect URI available in System Settings > Integrations > Mail > Microsoft OAuth2.
-
Click Overview (6) from the left menu bar. Copy the client ID (7) and the tenant ID (8). We will use them in Step 4.
Step 2 Configure API permissions
- Sign in to Microsoft Azure portal with your account.
-
Go to Manage Azure Active Directory (1).
-
Click App registrations (2) from the left menu bar and select the already created application (3).
-
Click API permissions (4) from the sidebar, then Add a permission (5). Select Microsoft Graph (6).
-
Click on Delegated permissions (7) and then add the permission SMTP.Send (8).
-
Click Grand admin consent for … (9) and make sure the status on the last column is set to Granted (10).
Step 3 Create a client secret
- Sign in to the Microsoft Azure portal with your account.
-
Go to Manage Azure Active Directory (1).
-
Click App registrations (2) from the left menu bar and select the already created application (3).
-
Click Certificates & secrets (4) from the left menu bar. Click New client secret (5), add a secret description (6) and then click on Add (7). This is your client secret.
-
Copy the newly created secret Value (8). We will use it in Step 4.
| Note: The Client secret has a specific expiration date and must be recreated and updated after expiration. |
Step 4 Configure eFront Mail Settings
- In eFront, go to System Settings (1) > Integrations (2) > Mail (3).
- Under Authentication type, select Microsoft OAuth2 (4).
- Fill in the required fields:
- Client ID (5): Your Azure Application (client) ID
- Client Secret (6): The secret value you copied in Step 3
- Tenant ID (7): Your Azure Directory (tenant) ID
- SMTP Host (8): smtp.office365.com
- Click Authenticate (9).
Authentication status and re-authentication
eFront will automatically refresh the OAuth2 token in the background. However, if the refresh fails (e.g. the client secret expires or consent is revoked), the status will change to Expired. In that case, an admin must return to the Mail settings and click Authenticate with Microsoft again.
| Note: Basic Authentication settings remain available for non-Microsoft SMTP providers and are unaffected by this change. |
| Note: Client IDs and Tenant IDs are both GUIDs (UUID format) and appear side-by-side on the Azure App Registration Overview screen. Make sure you copy the correct value for each field, the Application (client) ID and the Directory (tenant) ID are different values. |