Scan-to-email on office printers broke for a lot of businesses over the last couple of
years, and the reason is the same everywhere: mail providers turned off the insecure sign-in
method these machines relied on.

Why it stopped

Multifunction printers traditionally sent mail using basic authentication — a username and
password sent more or less as-is. Microsoft and Google have both disabled that, because it’s
the method attackers use most. Your printer hasn’t changed; what it’s allowed to do has.

There are two ways forward, and which you pick depends on how much control you have.

Option 1: an app password

The simplest approach if your provider allows it. You generate a separate password that
works only for this one purpose, and give that to the printer instead of the real account
password.

For a Microsoft 365 account, app passwords require multi-factor authentication to be on for
that account and the option to be permitted by your administrator. For Google, generate an app
password from the account’s security settings — also only available with two-step verification
enabled.

Then set the printer’s SMTP settings: server smtp.office365.com port
587 with STARTTLS for Microsoft 365, or smtp.gmail.com port
587 with STARTTLS for Gmail. Username is the full email address; password is the
app password you just generated.

Option 2: send to yourself instead

If app passwords are blocked — which is increasingly common on managed Microsoft 365
tenants — the more robust answer is to stop having the printer send mail at all.

Configure the printer to scan to a folder on the network, or scan to a USB drive, and
collect from there. It sounds like a step backwards and it’s usually more reliable, because it
removes the mail server from the chain entirely.

The other variant is SMTP relay, where your administrator permits the printer’s address to
send through the tenant without a password. That’s the proper answer for larger offices, but
it needs someone with tenant access and a fixed address for the printer.

If it’s configured and still failing

Worth deciding deliberately

If scanning is central to how your office works, scan-to-folder with a proper backup behind
it is more dependable than scan-to-email and doesn’t break the next time an authentication
policy changes. That’s usually the recommendation worth making rather than fighting the mail
path each time.

We set this up for Canberra offices regularly, including the awkward cases where the tenant
is locked down — 02 6188 9898.