535 5.7.139: SMTP authentication disabled (Microsoft 365)
Microsoft 365 returns 535 5.7.139 "Authentication unsuccessful" when an app tries SMTP AUTH but it is switched off, most often by the tenant setting "Turn off SMTP AUTH protocol for your organization" or by security defaults. Enable Authenticated SMTP for that mailbox, or connect with OAuth instead.
The exact message
Microsoft 365 / Exchange Online
535 5.7.139 Authentication unsuccessful, SmtpClientAuthentication is disabled for the Tenant.
Why it happens
- SMTP AUTH is disabled organization-wide (the default for many tenants).
- Security defaults are on, which disables SMTP AUTH.
- The mailbox has Authenticated SMTP turned off, overriding the tenant setting.
How to fix it
- In the Microsoft 365 admin center: Users > Active users > the user > Mail > Manage email apps > tick Authenticated SMTP.
- Or in PowerShell: Set-CASMailbox -Identity <mailbox> -SmtpClientAuthenticationDisabled $false.
- If security defaults are on, SMTP AUTH stays off. Prefer an OAuth connection where the tool supports it.
If you send cold email
This is the most common error when connecting a new Microsoft 365 mailbox to an outreach or warmup tool. It is a one-time admin setting per mailbox.
How WarmHawk handles it
WarmHawk sends through your own Google Workspace or Microsoft 365 mailboxes. When the provider stops accepting a mailbox’s sign-in (approval removed, password reset, no Exchange Online license), WarmHawk marks that mailbox as needing a reconnect and says why, instead of showing it as connected while every send fails. How WarmHawk works →
Related bounce codes
Sources, checked 2026-09-29: Microsoft Learn: Enable or disable SMTP AUTH in Exchange Online. Have a different bounce? Paste it into the decoder →
Questions
5.7.139 questions
What does 5.7.139 mean?+
Microsoft 365 returns 535 5.7.139 "Authentication unsuccessful" when an app tries SMTP AUTH but it is switched off, most often by the tenant setting "Turn off SMTP AUTH protocol for your organization" or by security defaults. Enable Authenticated SMTP for that mailbox, or connect with OAuth instead.
Is 5.7.139 a temporary or permanent error?+
Permanent. The message will not be retried, and sending it again unchanged will fail the same way until the cause is fixed.
How do I fix 5.7.139?+
In the Microsoft 365 admin center: Users > Active users > the user > Mail > Manage email apps > tick Authenticated SMTP. Or in PowerShell: Set-CASMailbox -Identity <mailbox> -SmtpClientAuthenticationDisabled $false. If security defaults are on, SMTP AUTH stays off. Prefer an OAuth connection where the tool supports it.