MC1158911 Low
Microsoft Exchange Online | SMTP onboarding to App RBAC
Summary AI-generated
Admins can assign SMTP.SendAsApp role to apps via RBAC for group-based mailbox access, streamlining onboarding and eliminating per-mailbox permissions in Exchange Online.
Suggested actions AI-generated
- Prepare security or distribution groups for mailbox access
- Plan migration to group-based RBAC assignments
- Communicate changes to support teams
- Update internal documentation
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1469960 (Updated) Microsoft Exchange Online: Review and configure EWSAllowedAppIDs before Exchange Web Services access changes
- MC1447678 (Updated) Microsoft Exchange Online: Prepare for Exchange Web Services retirement with EWSAllowedAppIDs
- MC1163922 Upcoming Secure by Default Settings Changes for Exchange and Teams APIs
- MC786329 (Updated) Exchange Online to retire Basic Auth for Client Submission (SMTP AUTH)
- MC1326502 (Updated) Shared and delegate mailbox scheduling for events
- MC1215071 (Updated) Microsoft Teams admin center: New Teams External Collaboration Administrator role
Original post from Microsoft
[Introduction]
We're simplifying how organizations grant applications permission to send email on behalf of mailboxes. Today, customers must manually assign permissions to each individual mailbox using PowerShell, which is time-consuming and inefficient. With this new capability, admins can assign the SMTP.SendAsApp role to an app through App Role-Based Access Control (RBAC), enabling group-based or scoped access to mailboxes. This simplifies onboarding for SMTP clients using OAuth and provides a scalable, secure, and modern approach to managing mailbox access.
This message is associated with Microsoft 365 Roadmap ID 498356.
[When this will happen:]
- General Availability (Worldwide): We will begin rolling out early November 2025 and expect to complete by late November 2025.
[How this affects your organization:]
Who is affected:
- Admins managing SMTP AUTH clients using OAuth in Exchange Online.
What will happen:
- Admins can assign the SMTP.SendAsApp role to applications via App RBAC.
- This enables group-based or scoped access to mailboxes.
- Eliminates the need for per-mailbox permission assignments.
- Streamlines onboarding for SMTP clients using OAuth.
- No changes to end-user experience.
[What you can do to prepare:]
- Prepare to create security or distribution groups for mailboxes requiring access.
- Plan for migration from per-mailbox permissions to group-based RBAC assignments.
- Communicate this change to your helpdesk or support teams.
- Update internal documentation if you currently detail mailbox permission onboarding.
- Review onboarding documentation: Authenticate an IMAP, POP or SMTP connection using OAuth | Microsoft Exchange | Microsoft Learn (https://learn.microsoft.com/exchange/client-developer/legacy-protocols/how-to-authenticate-an-imap-pop-smtp-application-by-using-oauth)
- Documentation will be updated November 1st
Additional details from Microsoft
- RoadmapIds
- 498356
- Summary
- Microsoft Exchange Online will enable admins to assign the SMTP.SendAsApp role to applications via App RBAC, allowing group-based or scoped mailbox access. This replaces manual per-mailbox permissions, simplifying OAuth SMTP client onboarding. Rollout begins November 2025, with no end-user impact. Prepare by planning group-based access and updating documentation.
- Platforms
- Desktop, Mac, Web