Keywords: Microsoft 365, OAuth2, SMTP, email settings, Azure, Client ID, Tenant ID, Basic Authentication, email configuration, Microsoft Entra
Summary
This article covers how to configure Microsoft OAuth2 as the SMTP authentication type in Cloud 9 for Microsoft 365 email accounts. It outlines what your IT administrator needs to set up in Microsoft Azure and what gets entered into Cloud 9.
Why Is Basic Authentication No Longer Working?
Microsoft has made the decision to disable Basic SMTP Authentication to strengthen security across Microsoft 365 accounts. In response, Cloud 9 has updated its email functionality to support Microsoft OAuth2 to ensure practices can continue sending emails without interruption as this change takes effect.
If your practice can still use Basic Authentication, the following articles may be helpful:
Cloud 9: Setting Up an App Password for Email in Cloud 9.
Cloud 9: Unable to Send Emails - Troubleshooting Basic Authentication.
For more information on Microsoft's decision and timeline, see this: Microsoft Article.
Overview
Cloud 9 supports Microsoft OAuth2 as an SMTP authentication type for practices using Microsoft 365 email. Unlike standard username and password authentication, OAuth2 requires additional credentials that are generated inside your organization's Microsoft Azure portal.
Important: These credentials must be generated by your IT administrator or Microsoft 365 administrator. Cloud 9 Support cannot generate them on your behalf.
Who Does What?
Understanding the division of responsibility will help this process go smoothly.
Cloud 9 Support is responsible for:
- Explaining which fields need to be filled in.
- Confirming the correct SMTP Auth Type is selected (Microsoft OAuth2.)
- Troubleshooting Cloud 9-side configuration after credentials are entered.
Your IT Administrator is responsible for:
- Registering an application in Microsoft Azure Active Directory (Entra ID.)
- Generating the Tenant ID, Client ID, Client Secret, Scope, and Authority values.
- Granting the required API permissions in Azure
- Providing the completed credentials to the practice for entry into Cloud 9
Required Fields in Cloud 9
The following fields must be completed in Cloud 9 under Practice Information > Email Server tab when using Microsoft OAuth2. Your IT administrator will supply the values for the OAuth2-specific fields listed below:
Field |
Description |
Provided By |
Tenant ID |
Your organization's Microsoft 365 directory identifier. |
IT Admin |
Client ID |
The registered app's application identifier in Azure. |
IT Admin |
Client Secret |
The secret key generated for the registered app. |
IT Admin |
Scope |
The permission scope for OAuth2 access |
IT Admin |
Authority |
The Microsoft login authority URL for your tenant. |
IT Admin |
Note: Microsoft restricts Azure app registration to certain account types. If your IT administrator is unable to register an app or generate these credentials, they should contact Microsoft support directly to verify your organization's account eligibility.
Resources to Share with Your IT Team
If your IT administrator needs guidance on generating these credentials, the following Microsoft resources may be helpful:
OAuth 2.0 and OIDC authentication flow in the Microsoft identity platform
Authenticate an IMAP, POP or SMTP connection using OAuth
Note: Cloud 9 Support does not provide step-by-step Azure configuration assistance. All Azure-related questions should be directed to your IT team or Microsoft support.
Next Steps
Once you have reviewed this article and identified your IT administrator, here is the step-by-step process:
- Share this article and the Microsoft resource links above with your IT administrator so they can register the application in Azure and generate the required credentials.
- Your IT administrator will provide you with the Tenant ID, Client ID, Client Secret, Scope, and Authority values once they are ready.
- In Cloud 9, go to Edit > Practice Information > Email Server tab OR Edit > Setup > Location > Pick Location > Email Server tab, (wherever your email settings live in Cloud 9), and select Microsoft OAuth2 as the SMTP Auth Type.
- The SMTP Server Host is smtp.office365.com and the SMTP Server Port is 587. Make sure SMTP Server Requires SSL is checked.
- Enter the credentials provided by your IT administrator into the corresponding fields and save your settings.
- If you need help confirming the configuration is complete or want to test connectivity after entering your credentials, reach out to Cloud 9 Support and we will be happy to assist.
As always, if you have any further questions, please do not hesitate to reach out to Cloud 9 Support by emailing us at cloud9support@planetdds.com, or chatting us online using the chat bubble on the lower right at https://cloud9support.planetdds.com/hc/en-us, or giving us a call during our business hours of 8:00 AM EST to 8:00 PM EST at the 1.800.394.6050 option 2.