OAuth compatibility by device and product

August 30, 2026 · View on GitHub

Vendors publish their Basic auth advisories as prose, PDFs and support pages, one vendor at a time. There is no single place to check whether the thing on your network has a way out. This is an attempt at one.

The table is generated from data/devices.json, so it can be read by a script as well as by a person, and it cannot disagree with its own data — CI rejects the two drifting apart.

Every row carries a link to the vendor's own statement. A compatibility list is only worth citing if each claim can be checked, so an entry with nothing published behind it does not get added.

How to read the status column

StatusMeaning
No OAuth firmware plannedThe vendor has said it is not coming. Firmware is not a step you have skipped; it does not exist.
No OAuth for this purposeThe feature has no OAuth option at all, regardless of firmware.
Some models or versionsOAuth exists for part of the range. The model or version number decides.
Check vendor advisoryThe vendor publishes a per-model list, revised over time, that is not reproduced here.
OAuth availableSupported — usually a configuration change rather than a migration.

The two top rows are the ones that matter for planning. Everything else means "go and read the advisory for your exact model", which is honest but is not an answer.

SystemOAuth statusNamed modelsEvidence
Konica Minolta / DEVELOP ineo and ineo+ MFPsNo OAuth firmware plannedineo 306, ineo 7228, ineo 266, ineo+ 266, ineo+ 256, ineo+ 226, ineo 4752, ineo 4052, ineo 4750, ineo 4050, ineo+ 3110, ineo+ 3100P, ineo+ 754e, ineo+ 654e, ineo 246, ineo 236, ineo 226, ineo 216, ineo 4700P, ineo 3301P, ineo 4000P, ineo 165 variants, ineo 185 variantsadvisory
Canon Maxify MB2755No OAuth for this purposeMaxify MB2755advisory
QNAP NAS notification settingsNo OAuth for this purposeadvisory
HP printers and MFPsSome models or versionsadvisory
Microsoft Dynamics NAV / Business CentralSome models or versionsadvisory
Sharp printers and MFPsSome models or versionsadvisory
TrueNAS TrueNAS email alertsSome models or versionsadvisory
Veeam Backup for Microsoft 365 and related productsSome models or versionsadvisory
Xerox ConnectKey printers and MFPsSome models or versionsVersaLink B415, VersaLink C415, VersaLink B620, VersaLink C620, VersaLink B625, VersaLink C625, AltaLink, PrimeLinkadvisory
Zabbix email notificationsSome models or versionsadvisory
Brother printers, MFPs and document scannersCheck vendor advisoryadvisory
Cerberus FTP ServerCheck vendor advisoryadvisory
Cisco Unity ConnectionCheck vendor advisoryadvisory
Faxination fax serverCheck vendor advisoryadvisory
Kyocera MFPs reporting send error 1102Check vendor advisoryadvisory
Laserfiche Workflow emailCheck vendor advisoryadvisory
Lexmark printers and MFPsCheck vendor advisoryadvisory
ManageEngine OpManagerCheck vendor advisoryadvisory
Ricoh multifunction printersCheck vendor advisoryadvisory
Synology NAS notification emailCheck vendor advisoryadvisory
Toshiba printers and MFPsCheck vendor advisoryadvisory
Microsoft Teams RoomsOAuth availableadvisory
Sophos Sophos Firewall (email alerts and reports)OAuth availableSophos Firewall 22.0, Sophos Firewall 20.0advisory

Notes per entry

Konica Minolta / DEVELOP — ineo and ineo+ MFPs
Marked "N/A" in the vendor's own OAuth column. The advisory points these owners at a different mail service rather than at an update. Other ineo product groups in the same advisory do have OAuth firmware - check the exact model. A third category exists that is neither: several Product Group 10 models are listed as "Under planning" with no release date, so their owners have no answer yet in either direction.

Canon — Maxify MB2755
Separate failure mode from OAuth: the firmware ships a fixed root CA store predating current Let's Encrypt roots, so certificate validation fails regardless of authentication. Hardware-confirmed, unchanged after a firmware update. Verification has to be disabled on the device.

QNAP — NAS notification settings
The notification settings accept username and password only; there is no OAuth option for Microsoft 365 SMTP.

HP — printers and MFPs
HP documents OAuth 2.0 support for Microsoft 365 Scan to Email on HP Enterprise and HP Managed printers running FutureSmart firmware 5.7 and newer. However, HP also states that certain LaserJet Pro models, including the M478-M479 and M428-M429f, do not support OAuth 2.0. Verify the exact product family and firmware before assuming Microsoft 365 SMTP AUTH compatibility.

Microsoft — Dynamics NAV / Business Central
Newer Business Central handles modern auth. Older on-prem NAV installs generally need the SMTP account repointed.

Sharp — printers and MFPs
Sharp documents OAuth 2.0 authentication for Microsoft 365 and Exchange Online SMTP on multiple newer printer and MFP models, including BP-series devices. Sharp does not appear to publish a centralized compatibility list or universal firmware floor for the full printer/MFP range. Verify the exact model's SMTP settings or current manual before assuming OAuth 2.0 support.

TrueNAS — TrueNAS email alerts
TrueNAS SCALE supports OAuth for Outlook and Gmail, but standard SMTP requires basic authentication. Some forum users report issues with Microsoft 365 enforcing OAuth while configuring standard SMTP on CORE.

Veeam — Backup for Microsoft 365 and related products
Corrected 2026-08-16 - the previous note claimed newer versions added OAuth for SMTP, which the linked page does not support. The v8 documentation offers "SMTP server (basic authentication)" and does not describe an OAuth option for SMTP notifications; modern app-only authentication appears elsewhere in the product, for Entra applications, not here. So the fix is not "upgrade and SMTP gets OAuth" - check whether your build offers a notification method that is not SMTP at all, and treat the SMTP path as basic-auth only.

Xerox — ConnectKey printers and MFPs
Device Code Flow is supported broadly; Client Credentials Flow only on the ConnectKey models listed. Devices not on Xerox's supported-firmware list are the problem cases and are not promised an update. Affects Scan to Email, Internet Fax (Send), Fax Forward to Email and Auto Email Notifications.

Zabbix — email notifications
Zabbix 7.4 introduced OAuth 2.0 authentication for SMTP, including automated OAuth configuration for Office365 and Gmail. Verify the Zabbix version and Office365 SmtpClientAuthentication configuration before assuming Microsoft 365 SMTP AUTH compatibility.

Brother — printers, MFPs and document scanners
Brother publishes a per-model Product Support List and states plainly that a machine not on it does not support OAuth 2.0, with no firmware promised - the vendor's own guidance for those owners is to use a different mail service. Listed models split into two tiers: OAuth already present, or present after a firmware update that is already downloadable. Affects Scan to Email Server, Internet Fax, Email Reports and Email Notifications. Check the exact model: support is firmware-dependent as well as model-dependent.

Cerberus — FTP Server
Vendor support article covers the exact 535 5.7.139 failure.

Cisco — Unity Connection
Named in Microsoft's own deprecation documentation. OAuth support depends on the release; check yours before assuming either way.

Faxination — fax server
Vendor published a timeline notice. Apply their update if one exists for the version in use; otherwise the outbound SMTP account has to be repointed.

Kyocera — MFPs reporting send error 1102
1102 / 0x1102 is Kyocera's device-side code for an SMTP authentication failure, not a model list. No public per-model OAuth statement located; check with the vendor for a specific model.

Laserfiche — Workflow email
Workflow emails failing on Basic auth removal, reported in the vendor's own community.

Lexmark — printers and MFPs
Lexmark documents OAuth 2.0 authentication for printers starting with the FW24 firmware release, including Outlook Live and Microsoft 365. The Email Server flow is configured through the printer's Embedded Web Server and requires OAuth 2.0 registration. Verify the specific device and firmware before assuming support.

ManageEngine — OpManager
OpManager supports OAuth 2.0 from build 126306, so for anyone on that build or later this is a settings change rather than a migration - the vendor's guide states it directly. The same page also documents re-enabling SMTP AUTH in the Exchange admin centre, which works until the end of December 2026 and not after; treat it as breathing room, not a fix.

Ricoh — multifunction printers
Ricoh publishes affected products with per-product firmware status, revised on 2026-01-30 into two tables - products with released OAuth firmware, and products newly added - plus a third group the Ricoh Firmware Update Tool cannot update, where the local representative has to do it. Not reproduced here because the list is long and still moving; check the model against the advisory. Ricoh does not say any product is permanently excluded, but for devices still waiting its own recommendation is to stop relying on email from the device or to use a mail service other than Exchange Online.

Synology — NAS notification email
Synology DSM 7 supports Outlook as an email notification service with an interactive Sign In flow rather than manual SMTP credentials. Synology documents OAuth-based authentication for this Outlook integration, but availability and behavior depend on the DSM version. Verify the exact DSM version and current Outlook notification configuration before assuming Microsoft 365 SMTP AUTH OAuth compatibility.

Toshiba — printers and MFPs
Toshiba Tec publishes a model-by-model Exchange Online OAuth 2.0 compatibility table for its MFPs, including firmware release information, compatible models, pending firmware updates, and explicitly incompatible models. Verify the exact model and current firmware status against Toshiba's published advisory before assuming Microsoft 365 SMTP AUTH compatibility.

Microsoft — Teams Rooms
Microsoft's own product. Enable modern auth on the resource account - no relay needed.

Sophos — Sophos Firewall (email alerts and reports)
Sophos publishes an official guide 'Configure OAuth 2.0 on Microsoft 365' for Sophos Firewall 22.0: register the firewall as an app in Microsoft Entra, add delegated SMTP.Send + offline_access permissions, turn on Authenticated SMTP for the sending user, and configure notifications with client ID / secret / refresh token. Confirms Modern (OAuth 2.0) SMTP AUTH support; availability depends on the firewall version.

23 entries, last reviewed 2026-08-27.

What this list is not

It is not exhaustive, and it is not a substitute for the vendor's advisory. It records what vendors have published, which is a different thing from what is true of every unit in the field: firmware branches, regional model names and OEM rebadges all diverge from the headline list.

It also says nothing about whether a device is worth keeping. A 2016 MFP with no OAuth path and no security updates is a decision about hardware, not about mail configuration.

Once firmware is ruled out

Three options remain, and they differ from each other more than they look:

  • Direct Send — free, works only for recipients inside your own tenant, needs a connector and a static IP
  • A relay that still accepts a username and password — works for any recipient; check whether the sender domain has to be your own
  • Replace the hardware — the only option that also survives the next deprecation

The migration guide covers all three, including the ones that are not this project. Devices that will never get OAuth firmware goes into the ruled-out cases in prose.

Adding an entry

The list grows by report. If you have a model whose status is documented somewhere and is not here, or a vendor has since shipped firmware for something listed as ruled out, edit data/devices.json and run:

python tools/build-device-table.py

That regenerates the table above. Entries need a vendor, a product, a status from the list, and an evidence URL — without the last one the build refuses the entry. Hardware-confirmed reports get credited by username.