SMTP authentication is blocked for RM Unify customers
Published Date : 22 Feb 2023
Last Updated : 15 Jun 2023
Content Ref: TEC9038776
Operating System
(none)
Part No
(none)
Summary
Explains why SMTP authentication is blocked for RM Unify customers.
Symptoms
Since the start of 2023, RM Unify monitoring has detected an increased number of automated attempts to 'brute force' Microsoft® 365™ email accounts by repeated attempts to guess the account password.
The main route used for these password-cracking attempts is via the SMTP AUTH (authentication) protocol. This is a legacy email protocol used to connect older desktop/smartphone email apps to an email service like Microsoft 365 (Exchange Online), or Google Workspace, but is increasingly being used by attackers to test thousands of user passwords in the hope of getting one right.
For example, in January 2023 alone, less than 3% of SMTP authentication requests were valid and successful. This equates to over five million failed attempts, which indicates bad actors (hackers) attempting 'brute force' attacks from countries such as Russia, China and Mexico. Obviously, these are not authentic requests from genuine users and present a very serious threat to the stability of the RM Unify platform and our users' Microsoft 365 and Google domains, user accounts and data.
Cause
As a result of this threat, we have decided to disable support for the SMTP AUTH protocol within RM Unify. This means where a Microsoft 365 or Google domain (e.g. stmarys.sch.uk) is federated to RM Unify, any SMTP authentication requests for a user account on that domain (e.g. scanner@stmarys.sch.uk) will be dismissed by RM Unify unless by prior agreement with us. We will cease to support SMTP authentication in its entirety from the end of August 2023.
Whilst the change is necessary, we have not taken this decision without consideration. We are aware that disabling SMTP AUTH will inconvenience some customers who use devices and services that still use SMTP authentication, such as printer monitoring software (e.g. PaperCut), scanners, printers, etc. which are configured with RM Unify-federated Microsoft 365 or Google accounts. However, maintaining the security and availability of RM Unify has to be our highest priority.
Microsoft also highly recommend disabling SMTP AUTH in your Microsoft 365 tenancy.
Procedure
Any user account on the Microsoft 365 service domain (the unfederated domain ending in '.onmicrosoft.com') will be unaffected by the RM Unify change detailed in this article. Also, any Google super admin account on the federated domain, or simply any account on any unfederated Google domain will be unaffected.
Microsoft 365
Where your establishment requires SMTP AUTH via legacy applications such as scanners, printers, etc. and you have not disabled SMTP AUTH in your Microsoft tenancy, you could use a Microsoft 365 account on this service domain (e.g. scanner@stmarys.onmicrosoft.com). Given below are example steps:
In the 'Microsoft 365 admin center', sign in as a global admin user.
Select Users, 'Active users', 'Add a user'.
Complete the user details as needed and in the Domains field, select a domain that is not federated to RM Unify. RM recommends using the Microsoft 365 service domain, which ends in '.onmicrosoft.com.'
Select Next.
Assign a licence as required. The account will need an Exchange Online licence if it is to be used for sending emails.
Select Next, Next, 'Finish adding'.
Sign in as the user you just created to confirm it can be accessed and sign out.
In the affected device or app requiring SMTP authentication, re-configure the SMTP setting to use the new account created in the previous steps. Please refer to the device/app supplier's instructions on how to do this or request support from your usual support provider.
Google
Where your establishment requires SMTP AUTH via legacy applications or devices such as scanners, printers, etc., you can configure those applications/devices to use an account on an unfederated Google domain in your organisation.
Note: Google super admins on the federated domain do not get prompted to authenticate via RM Unify. However, we do not advise creating additional Google super admins on your federated domain solely to configure your applications/devices; the number of Google super admins in your domain should be kept to a minimum.
Sign in to the Google Admin console as a super admin.
Sign in as the user you just created to confirm it can be accessed and sign out.
In the affected device or app requiring SMTP authentication, re-configure the SMTP setting to use the new account created in the previous steps. Please refer to the device/app supplier's instructions on how to do this or request support from your usual support provider.
Checks
This change will not affect anyone using supported versions of Microsoft desktop/mobile apps nor any app using Exchange ActiveSync (this includes iOS Mail, Apple Mail, Gmail app and Android Mail).
Can I check which Microsoft 365 accounts have used SMTP authentication?
Yes, the Azure Manage Portal sign-in logs can be filtered to show which accounts have used SMTP authentication in the last seven days:
Sign in to Azure Manage Portal as a Microsoft 365 user with the global admin role.
From the leftmost menu, select Azure Active Directory.
In the menu that appears, scroll down to Monitoring and select 'Sign-in logs'.
In the right-hand pane, select the 'Date:' filter.
Select the desired time period and click Apply.
Select 'Add filters', select 'Client app' and click Apply.
Select the 'Client app:' filter.
Under Legacy Authentication Clients, select SMTP and click Apply.
In the search results, the User column displays the name of the Microsoft 365 user account. Select each search result for more detailed information.
Note: It is not possible currently to find similar information for user accounts in Google Workspace.
Possible Issues
Microsoft 365
If you decide to disable SMTP AUTH in your Microsoft 365 tenancy, or it has SMTP AUTH disabled already, please see Options 2 and 3 in the following Microsoft article for alternatives for setting up multifunction devices or applications:
If you wish to set up a device or application to send an email via Google Workspace, you have a number of options as per this Google article. Please contact Google Support directly for any specific queries or issues regarding SMTP AUTH.
If this article has not helped provide a solution then it is also possible to
log a call...
Document Keywords: TEC9038776 SMTP authentication is blocked for RM Unify customers, auth, relay, hacking, hacked, brute force, unify