Microsoft 365: SMTP onboarding to App Role Based Access Control
Why it matters: Breaking change — admin action may be required
From Microsoft's description: “Today, customers must manually assign permissions to each individual mailbox using PowerShell, which is time-consuming and inefficient.”
⏰ Act before November CY2025 · overdue
We're simplifying how organizations grant applications permission to send email on behalf of mailboxes. Today, customers must manually assign permissions to each individual mailbox using PowerShell, which is time-consuming and inefficient. With this new capability, admins can assign the SMTP.SendAsApp role to an app through App Role-Based Access Control (RBAC), enabling group-based or scoped access to mailboxes. This eliminates the need for per-mailbox configuration and streamlines onboarding for SMTP clients using OAuth. It’s a scalable, secure, and modern approach to managing mailbox access for applications.
How this was classified (derived by the tracker — not Microsoft's label)
- breaking · 80% confidence · matched action-required
Today, customers must manually assign permissions to each individual mailbox using PowerShell, which is time-consuming and inefficient.
Affected: Exchange, Microsoft 365