SOLVED

Cannot connect to IMAP and SMTP using OAuth2.0 to Exchange Online

%3CLINGO-SUB%20id%3D%22lingo-sub-1359651%22%20slang%3D%22en-US%22%3ECannot%20connect%20to%20IMAP%20and%20SMTP%20using%20OAuth2.0%20to%20Exchange%20Online%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1359651%22%20slang%3D%22en-US%22%3E%3CP%3ELast%20week%20the%20support%20for%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fexchange-team-blog%2Fannouncing-oauth-2-0-support-for-imap-and-smtp-auth-protocols-in%2Fba-p%2F1330432%22%20target%3D%22_self%22%3EIMAP%20and%20SMTP%20using%20OAuth2.0%3C%2FA%3E%20has%20been%20announced.%3C%2FP%3E%3CP%3EFollowing%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fclient-developer%2Flegacy-protocols%2Fhow-to-authenticate-an-imap-pop-smtp-application-by-using-oauth%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ethe%20instruction%3C%2FA%3E%2C%20I%20added%20the%20required%20API%20permissions%20to%20Azure%20App%20Registration%20and%20tried%20to%20connect%2C%20but%20it%20didn't%20work.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20get%20this%20error%20for%20IMAP%3A%3C%2FP%3E%3CPRE%3E%3CSPAN%20class%3D%22pln%22%3EA1%20NO%20AUTHENTICATE%20failed%3C%2FSPAN%3E%3CSPAN%20class%3D%22pun%22%3E.%3C%2FSPAN%3E%3C%2FPRE%3E%3CP%3EAnd%20this%20one%20for%20SMTP%3A%3C%2FP%3E%3CPRE%3E%3CSPAN%20class%3D%22lit%22%3E535%3C%2FSPAN%3E%20%3CSPAN%20class%3D%22lit%22%3E5.7%3C%2FSPAN%3E%3CSPAN%20class%3D%22pun%22%3E.%3C%2FSPAN%3E%3CSPAN%20class%3D%22lit%22%3E3%3C%2FSPAN%3E%20%3CSPAN%20class%3D%22typ%22%3EAuthentication%3C%2FSPAN%3E%3CSPAN%20class%3D%22pln%22%3E%20unsuccessful%3C%2FSPAN%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20more%20detailed%20summary%20I%20have%20submitted%20to%20the%20%3CA%20href%3D%22https%3A%2F%2Fstackoverflow.com%2Fq%2F61597263%2F1126831%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EStackOverflow%20question%3C%2FA%3E%2C%20please%20check%20it%20for%20more%20in-depth%20details.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20someone%20please%20from%20the%20Exchange%20team%20look%20into%20this%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EUpdate%201%3A%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EIt%20appears%2C%20that%20when%20requesting%20the%20following%20scopes%20everything%20works%20as%20expected%3A%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-java%22%3E%3CCODE%3E%20%20%20%20%22offline_access%22%2C%0A%20%20%20%20%22https%253A%252F%252Foutlook.office365.com%252FIMAP.AccessAsUser.All%22%2C%0A%20%20%20%20%22https%253A%252F%252Foutlook.office365.com%252FSMTP.Send%22%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3EWith%20these%20scopes%2C%20the%20token%20is%20generated%2C%20but%20IMAP%20and%20SMTP%20auth%20fails%3A%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-java%22%3E%3CCODE%3E%20%20%20%20%20%20%20%20%22offline_access%22%2C%0A%20%20%20%20%20%20%20%20%22User.Read%22%2C%0A%20%20%20%20%20%20%20%20%22Mail.ReadWrite%22%2C%0A%20%20%20%20%20%20%20%20%22https%253A%252F%252Foutlook.office365.com%252FIMAP.AccessAsUser.All%22%2C%0A%20%20%20%20%20%20%20%20%22https%253A%252F%252Foutlook.office365.com%252FSMTP.Send%22%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3EAnd%20when%20requesting%20these%3A%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-java%22%3E%3CCODE%3E%20%20%20%20%20%20%20%20%22offline_access%22%2C%20%2F%2F%20or%20%22https%253A%252F%252Fgraph.microsoft.com%252Foffline_access%22%0A%20%20%20%20%20%20%20%20%22https%253A%252F%252Fgraph.microsoft.com%252FUser.Read%22%2C%0A%20%20%20%20%20%20%20%20%22https%253A%252F%252Fgraph.microsoft.com%252FMail.ReadWrite%22%2C%0A%20%20%20%20%20%20%20%20%22https%253A%252F%252Foutlook.office365.com%252FIMAP.AccessAsUser.All%22%2C%0A%20%20%20%20%20%20%20%20%22https%253A%252F%252Foutlook.office365.com%252FSMTP.Send%22%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3EI%20get%20the%20following%20error%3A%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-json%22%3E%3CCODE%3E%7B%0A%20%20%20%20%22error%22%3A%20%22invalid_request%22%2C%0A%20%20%20%20%22error_description%22%3A%20%22AADSTS28000%3A%20Provided%20value%20for%20the%20input%20parameter%20scope%20is%20not%20valid%20because%20it%20contains%20more%20than%20one%20resource.%20Scope%20offline_access%20https%3A%2F%2Fgraph.microsoft.com%2Fuser.read%20https%3A%2F%2Fgraph.microsoft.com%2Fmail.readwrite%20https%3A%2F%2Foutlook.office365.com%2Fimap.accessasuser.all%20https%3A%2F%2Foutlook.office365.com%2Fsmtp.send%20is%20not%20valid.%5Cr%5CnTrace%20ID%3A%20c3282396-6231-4e11-8300-77bc2ca57f00%5Cr%5CnCorrelation%20ID%3A%205f5145bf-7114-4e6c-ab11-30e7ff84a056%5Cr%5CnTimestamp%3A%202020-05-06%2008%3A08%3A48Z%22%2C%0A%20%20%20%20%22error_codes%22%3A%20%5B%0A%20%20%20%20%20%20%20%2028000%0A%20%20%20%20%5D%2C%0A%20%20%20%20%22timestamp%22%3A%20%222020-05-06%2008%3A08%3A48Z%22%2C%0A%20%20%20%20%22trace_id%22%3A%20%22c3282396-6231-4e11-8300-77bc2ca57f00%22%2C%0A%20%20%20%20%22correlation_id%22%3A%20%225f5145bf-7114-4e6c-ab11-30e7ff84a056%22%0A%7D%3C%2FCODE%3E%3C%2FPRE%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1359651%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1397171%22%20slang%3D%22en-US%22%3ERe%3A%20Cannot%20connect%20to%20IMAP%20and%20SMTP%20using%20OAuth2.0%20to%20Exchange%20Online%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1397171%22%20slang%3D%22en-US%22%3E%3CP%3EA%20quote%20of%20the%20Stack%20Overflow%20reply%20from%3A%3C%2FP%3E%3CBLOCKQUOTE%3E%3CP%3EIMAP%2C%20SMTP%20scopes%20are%20targeted%20for%20Exchange%20resource%20and%20not%20Graph.%20Whereas%20User.Read%2C%20Mail.ReadWrite%20are%20meant%20for%20Graph%20resource.%3C%2FP%3E%3CP%3EWe%20do%20not%20support%20generation%20of%20tokens%20that%20are%20meant%20for%20two%20resources.%20Hence%20the%20error%20%22Provided%20value%20for%20the%20input%20parameter%20scope%20is%20not%20valid%20because%20it%20contains%20more%20than%20one%20resource.%22%3C%2FP%3E%3CP%3EYou%20should%20generate%20two%20tokens%20separately%20by%20two%20calls%20to%20%2Ftoken.%201.%20One%20with%20the%20IMAP%2C%20SMTP%20scopes%20generated%20for%20the%20Exchange%20resource.%202.%20The%20other%20with%20Graph%20scopes%20(User.Read%2C%20Mail.ReadWrite)%20meant%20for%20Graph%20resource.%3C%2FP%3E%3C%2FBLOCKQUOTE%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fstackoverflow.com%2Fa%2F61678485%2F1126831%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fstackoverflow.com%2Fa%2F61678485%2F1126831%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Last week the support for IMAP and SMTP using OAuth2.0 has been announced.

Following the instruction, I added the required API permissions to Azure App Registration and tried to connect, but it didn't work.

 

I get this error for IMAP:

A1 NO AUTHENTICATE failed.

And this one for SMTP:

535 5.7.3 Authentication unsuccessful

 

The more detailed summary I have submitted to the StackOverflow question, please check it for more in-depth details.

 

Can someone please from the Exchange team look into this?

 

Update 1:

It appears, that when requesting the following scopes everything works as expected:

    "offline_access",
    "https%3A%2F%2Foutlook.office365.com%2FIMAP.AccessAsUser.All",
    "https%3A%2F%2Foutlook.office365.com%2FSMTP.Send"

With these scopes, the token is generated, but IMAP and SMTP auth fails:

        "offline_access",
        "User.Read",
        "Mail.ReadWrite",
        "https%3A%2F%2Foutlook.office365.com%2FIMAP.AccessAsUser.All",
        "https%3A%2F%2Foutlook.office365.com%2FSMTP.Send"

And when requesting these:

        "offline_access", // or "https%3A%2F%2Fgraph.microsoft.com%2Foffline_access"
        "https%3A%2F%2Fgraph.microsoft.com%2FUser.Read",
        "https%3A%2F%2Fgraph.microsoft.com%2FMail.ReadWrite",
        "https%3A%2F%2Foutlook.office365.com%2FIMAP.AccessAsUser.All",
        "https%3A%2F%2Foutlook.office365.com%2FSMTP.Send"

I get the following error:

{
    "error": "invalid_request",
    "error_description": "AADSTS28000: Provided value for the input parameter scope is not valid because it contains more than one resource. Scope offline_access https://graph.microsoft.com/user.read https://graph.microsoft.com/mail.readwrite https://outlook.office365.com/imap.accessasuser.all https://outlook.office365.com/smtp.send is not valid.\r\nTrace ID: c3282396-6231-4e11-8300-77bc2ca57f00\r\nCorrelation ID: 5f5145bf-7114-4e6c-ab11-30e7ff84a056\r\nTimestamp: 2020-05-06 08:08:48Z",
    "error_codes": [
        28000
    ],
    "timestamp": "2020-05-06 08:08:48Z",
    "trace_id": "c3282396-6231-4e11-8300-77bc2ca57f00",
    "correlation_id": "5f5145bf-7114-4e6c-ab11-30e7ff84a056"
}
4 Replies
Highlighted
Best Response confirmed by ledniov (New Contributor)
Solution

A quote of the Stack Overflow reply from:

IMAP, SMTP scopes are targeted for Exchange resource and not Graph. Whereas User.Read, Mail.ReadWrite are meant for Graph resource.

We do not support generation of tokens that are meant for two resources. Hence the error "Provided value for the input parameter scope is not valid because it contains more than one resource."

You should generate two tokens separately by two calls to /token. 1. One with the IMAP, SMTP scopes generated for the Exchange resource. 2. The other with Graph scopes (User.Read, Mail.ReadWrite) meant for Graph resource.

https://stackoverflow.com/a/61678485/1126831

Highlighted

Hi @ledniov ,

 

I'm trying to perform similar task , connect with exchange online through IMAP and send mail using SMTP. Even I'm getting similar error described above. 

 

Could you please share screenshot of scopes added in MS Azure. I was not able to look for scopes 

https://outlook.office365.com/IMAP.AccessAsUser.All https://outlook.office365.com/SMTP.Send.

 

I do have "https://graph.microsoft.com/IMAP.AccessAsUser.All and https://graph.microsoft.com/SMTP.Send" scopes add but I get error for IMAP "javax.mail.AuthenticationFailedException: AUTHENTICATE failed.
at com.sun.mail.imap.IMAPStore.protocolConnect(IMAPStore.java:731)"

and for SMTP "535 5.7.3 Authentication unsuccessful "

Access Token Request

" {
"token_type": "Bearer",
"scope": "IMAP.AccessAsUser.All SMTP.Send User.Read",
"expires_in": "3599",
"ext_expires_in": "3599",
"expires_on": "1593612618",
"not_before": "1593608718",
"resource": "https://graph.microsoft.com",
"access_token": "**",
"refresh_token": "**",
"id_token": "**"
}"

 

It would be help full if you are able to share the screenshot. I have attached mine permission screen , let me know if I'm doing something wrong

Highlighted

@ledniov Even Microsoft support team says that they have removed scopes

https://outlook.office365.com/IMAP.AccessAsUser.All 

https://outlook.office365.com/SMTP.Send 

They are recommending to use Graph permission/scopes.

Is your application still able to connect using Graph scopes 

Highlighted

@VinyakPM 

 

The correct scope is "offline_access https://outlook.office.com/IMAP.AccessAsUser.All https://outlook.office.com/POP.AccessAsUser.All https://outlook.office.com/SMTP.Send"

 

Also, I've seen it fail if you are trying to use a secondary alias.  Make it primary by going to "Manage how you sign in to Microsoft" in your Microsoft account settings at https://account.live.com