Can I use "app passwords" with POP/SMTP on outlook365.com for a different email client

Anonymous
2024-11-08T18:06:42+00:00

Hi,

I have 2FA enabled on my outlook365 work account. With the admin, i made sure POP3 access is on, and I have created an "app password" for my account (which was a whole bunch of hoops to jump through thanks to this issue). But the information on using app passwords and pop3 is very contradictory across forum posts and official Microsoft articles.

For once and for all for everyone:

  1. is it possible to use pop3 with a third party email client with any authentication method other then OAuth2?
  2. If only OAuth2is supported, what is the use-case for app passwords? I see no use-case for them other than allow specific apps that don't support OAuth2 to have a dedicated traditional password.

Currently, when i use a POP3 client without OAuth2 and using the dedicated App Password that i created in

https://mysignins.microsoft.com/security-info, and using the details for the pop/image server listed in https://admin.exchange.microsoft.com/#/account/:/popimapaccess, I get an authentication error that the username/password are wrong.

Regards,

Dolf

Outlook | Web | Outlook on the web for business | Security

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Anonymous
    2024-11-08T21:05:30+00:00

    Dear Dolf Andringa

    Good day! Thank you for posting in the Microsoft Community. We will be happy to help you.

    I'm sorry to hear you are having the conflicting information on the use of "app passwords" with POP/SMTP on outlook365.com for a different email client. To clarify this:

    ♦POP3 Authentication Methods

    1. OAuth2: This is the preferred and more secure method for authentication. Microsoft has been moving towards OAuth2 for all its services, including POP3 and IMAP, due to its enhanced security features.
    2. App Passwords: These are intended for apps that do not support OAuth2. However, for Outlook 365, using app passwords with POP3 is not supported. This means that even if you create an app password, it won't work with POP3 if the client does not support OAuth2.

    ♦Use-Case for App Passwords

    App passwords are primarily used for older applications or devices that do not support modern authentication methods like OAuth2. They provide a way to still use these applications securely by generating a unique password that can be revoked if needed.

    Given that Microsoft is deprecating basic authentication methods, including for POP3 and IMAP, your third-party email client must support OAuth2 to connect to Outlook 365. If it doesn't, you will encounter authentication errors, as you've described.

    1. To ensure your email client supports OAuth2 for POP3. Clients like Mozilla Thunderbird and newer versions of Outlook support this.
    2. If possible, consider switching to IMAP, which also supports OAuth2 and provides better synchronization features.
    3. If you continue to face issues, contacting Microsoft Support might provide additional insights specific to your setup. You can contact Microsoft support through the Teams help center or the Office 365 admin portal by going to Office 365 Admin Center (Admin permission is needed) > Support > New Service Request. The support engineers there have the correct escalation channel, and this is the most efficient way to report such issue.

    References

    1. Modern Authentication Methods now needed to continue syncing Outlook ...
    2. POP3 and IMAP4 in Exchange Online | Microsoft Learn

    I hope this helps clear things up! Let me know if you have any more questions or need further assistance. Please note that our initial response does not always resolve the issue immediately. However, with your help and more detailed information, we can find a solution together. Thank you for your help.

    Was this answer helpful?

    0 comments No comments