Overview
The copier scans fine to a folder or USB stick, but scan-to-email stops working — either silently, or with “Authentication failed”, “Cannot connect to SMTP server” or “Send error” on the panel.
Nine times out of ten, nothing changed on the printer. Microsoft 365 changed the rules on how devices are allowed to send mail.
Likely cause
- Basic authentication and SMTP AUTH are disabled by default in Microsoft 365 — the most common cause since 2023.
- The mailbox password used by the copier was changed or expired.
- MFA was enabled on the account the copier uses (devices can't answer an MFA prompt).
- Wrong port or encryption setting after a firmware update.
- A firewall blocking outbound port 587.
Before you begin
Never use a real staff member's mailbox and password on a copier.
Anyone with physical access to the device can read those credentials, and password changes silently break scanning. Use a dedicated, restricted account or direct send instead.
- The printer's IP address (print a config page).
- Admin access to the printer's web page.
- Microsoft 365 admin access, if settings need changing there.
Step-by-step
Step 1 — Read the exact error on the printer
Check the panel and the device's send log or job history. “Authentication failed” and “Cannot connect” point to completely different fixes.
Step 2 — Open the printer's web admin page
Enter the printer's IP address in a browser on the same network:
https://192.168.1.45Sign in as admin and go to the SMTP / Scan to Email settings.
Step 3 — Verify the SMTP settings
| Setting | Microsoft 365 value |
|---|---|
| SMTP server | smtp.office365.com |
| Port | 587 |
| Encryption | STARTTLS (not SSL, not None) |
| Authentication | Enabled, using the device mailbox address |
| From address | Must match the authenticated mailbox exactly |
Step 4 — Re-enter the password
Type the password again rather than trusting the saved dots, and use the printer's Test button. Many devices silently keep an old password after a firmware update.
Step 5 — Enable SMTP AUTH for the device mailbox
In the Microsoft 365 admin center, open Users → Active users → the device mailbox → Mail → Manage email apps, and tick Authenticated SMTP. Allow up to an hour to apply.
Enable SMTP AUTH per mailbox, never tenant-wide.
Turning it on for the whole organisation re-opens legacy authentication for every account and is a serious security risk.
Step 6 — Prefer direct send or a connector
The most reliable setup avoids passwords entirely. Point the copier at your tenant's MX endpoint on port 25 and allow your office public IP with a Microsoft 365 connector.
| Method | Password needed | Can email external recipients | Best for |
|---|---|---|---|
| SMTP AUTH client submission | Yes | Yes | A single device, quick setup |
| Direct send | No | Internal only | Most small offices — scan to yourself |
| Microsoft 365 connector | No | Yes | Multiple devices, permanent setup |
Step 7 — Confirm the network path
From a PC on the same network, check that outbound SMTP is not blocked:
Test-NetConnection smtp.office365.com -Port 587TcpTestSucceeded : True means the firewall is allowing the traffic.
Expected result
The printer's SMTP test reports success, and a scan arrives in the recipient's inbox within a minute.
Troubleshooting
Still stuck?
If you'd rather not work through this yourself, CYBER904 can take it from here. Reach the team directly during business hours and we'll get it sorted.