Microsoft Exchange Online Device Authentication Guide
For Epson Devices
Introduction
Due to security enhancements in Microsoft Exchange Online, the traditional "Basic Authentication" method has been deprecated, and SMTP authentication (SMTP AUTH) is disabled by default. To continue using email services with your devices, you must now use the "OAuth 2.0" authentication method. This guide explains the necessary steps for configuring your printer or scanner's email sending and notification functions to use OAuth 2.0 authentication with your mail server.
The following steps are required:
- Enable SMTP AUTH in Exchange Online.
- Configure OAuth 2.0 authentication for the mail server.
Ensure your printer or scanner is updated with the latest firmware.
Enabling SMTP AUTH in Exchange Online
Printers and scanners use the SMTP protocol for sending emails, so SMTP AUTH must be enabled in Exchange Online.
Procedure
- In the [Exchange Admin Center], disable [Security defaults] for the entire organization and enable SMTP AUTH.
- In the [Microsoft 365 Admin Center], enable SMTP AUTH for the mailboxes designated for printer administrators.
For detailed instructions, please refer to the "Microsoft Learn" website.
Setting up OAuth 2.0 Authentication for Mail Server
Configure OAuth 2.0 authentication for your mail server using Web Config.
? Reference: For models supporting extended networks, please use the standard network settings. Extended networks do not support OAuth 2.0 authentication.
- Launch Web Config by entering the printer's IP address in your browser. Access the printer's IP address from a computer connected to the same network. You can find the IP address in the operation panel under [Settings] > [Device Settings] > [Network Settings] > [Network Information] > [Wired/Wireless Connection Status].
- Log in as an administrator by entering the administrator password. Select [Logon], enter the password, and click [Settings].
- Navigate through the tabs: [Network] > [Mail Server] > [Basic].
- Select [OAuth2] for the [Authentication Method].
- Select [Microsoft Exchange Online] for the [Mail Service].
? Reference: For personal use, select [Outlook.com]. - Sign in. Click [Sign in] and then click [Sign in with Microsoft Account] on the displayed screen.
- Copy the authentication code displayed on the screen and click the provided URL.
- On the access permission code input screen, paste the copied authentication code and click [Next].
- On the Microsoft sign-in screen, enter the email address of the administrator account with global administrator role privileges and click [Next].
- Enter the password and click [Sign in].
- On the requested permissions screen, check the box for "Consent on behalf of your organization" and click [Accept].
After successful authentication, a sign-in message will appear. You can close the browser window. The sign-in status can be confirmed on the Web Config page: [Network] tab > [Mail Server] > [Basic].
The screen will show "Signed in."
Once sign-in is complete, account information for OAuth 2.0 authentication will be displayed.
Click [Settings] to send the configuration information to the printer.
Verifying OAuth 2.0 Authentication Information
Mail server configuration information can be verified using the following methods:
? Reference: If an icon is displayed on the printer's screen, select the icon to log in as an administrator.
Via Operation Panel
- From the operation panel's home screen, navigate to [Settings] > [Device Settings] > [Network Settings] > [Network Information] > [Mail Server Settings Confirmation].
The mail server settings information will be displayed.
Via Network Status Sheet
- From the operation panel's home screen, navigate to [Settings] > [Device Settings] > [Network Settings] > [Network Information] > [Print Status Sheet].
- Check the messages and start printing.
The Network Status Sheet will print, displaying network information including mail server settings.
Fax Server OAuth 2.0 Support (Supported Models Only)
For models that support sending email content via a fax server to a recipient's fax machine, if the fax server of the internet fax service provider is using OAuth 2.0 authentication, you must configure OAuth 2.0 authentication for the device.
In Web Config, navigate to the [Fax] tab > [Fax Server] > [Mail Server Settings] screen, and set the [Authentication Method] for the mail server to [OAuth2].
For other configuration details, please contact the service provider.
Epson Print Admin Serverless [To My Mail] Feature OAuth 2.0 Authentication (Supported Models Only)
With Epson Print Admin Serverless, if the [Sender Address] is set to [User's Email Address], each user must sign in with their own email address in addition to configuring the mail server's OAuth 2.0 authentication.
First, use the printer administrator's email address to log in as the administrator and set the access permission scope by checking [Consent on behalf of your organization].
- Log in with a user who has administrator privileges on the Epson Print Admin Serverless screen.
- Select [To My Mail].
? Reference: Menu names may vary depending on the model.
The sign-in screen will appear.
- Enter the email address of the account with global administrator role privileges and click [Next].
- Enter the password and click [Sign in].
- On the access permission screen, check [Consent on behalf of your organization] and select [Accept].
Upon successful sign-in, a message will be displayed on the Epson Print Admin Serverless screen. Select [OK] to close the screen.
After the administrator's sign-in is complete, each user registered in Epson Print Admin Serverless can use the email sending function by signing in themselves. When a user selects the [To My Mail] menu for the first time, the sign-in screen will appear, prompting them to sign in. Use your company or organization's Microsoft account (email address and password) to sign in.
Troubleshooting
Cannot Sign In or User Cannot Log In
This may be due to conditional access policies in Entra ID blocking access.
Troubleshooting Method:
Check the conditional access policies in Entra ID. For detailed instructions, please refer to the "Microsoft Learn" website.
Cannot Send Email
The message "Sign-in to the mail service is required to use this function. Please contact your administrator." is displayed.
Troubleshooting Method:
Check the current status in Web Config by navigating through [Network] tab > [Mail Server] > [Basic].
If the [Current Status] is [Signed in], the sign-in information may not have been saved correctly to the printer. Click [Settings] to send the configuration information to the printer. If the [Current Status] is not displayed and the [Sign in] button is visible, perform the sign-in operation.
Expiration Message is Displayed
A certain period has passed since the last email sending operation after signing in.
If the printer using OAuth 2.0 authentication has not been used for a long time, or the email sending function has not been utilized, the access token and refresh token become invalid.
Troubleshooting Method:
The administrator needs to perform the sign-in operation again.
Error Code Displayed in Job Confirmation Menu
If an error occurs with the email sending function, an error code will be displayed in the job history. You can check this by selecting [Job/Status] > [Job Status]. Refer to the table below for error situations and countermeasures.
Error Code | Status | Countermeasures |
---|---|---|
360 | Integration with cloud service or mail service is not established. | Establish integration with the cloud service or mail service. |
361 | The integration period with the cloud service or mail service has expired. | Establish integration with the cloud service or mail service. |
370 | Re-sign-in to the cloud service is required. | Sign in to the cloud service. |
Related Information
Trademarks
- Microsoft, Exchange Online, Microsoft 365, Microsoft Entra ID, Outlook.com, and other product names are registered trademarks or trademarks of Microsoft Corporation in the United States and other countries.
- General: Other product names mentioned in this document are trademarks or registered trademarks of their respective companies. Epson is not involved with these trademarks or registered trademarks.
- © 2025 Seiko Epson Corporation