
In the window that opens, make sure you select Authenticator App as the method that users will use to. Ensure that the default sign in method is set as Microsoft Authenticator and then click on Add Sign-In Method. Microsoft have said they are working on improving the management experience with hybrid at Ignite last year, but that does not cover the need for SMTP relay scenarios like you describe. Click on Security Info on the left side of the page to access your current sign in methods as shown in the photo below. Given that you have an on-premises server, you would use that as your apps and devices SMTP relay device as well. With hybrid you need to maintain an on-premises Exchange Server for cloud mailbox management as you are doing AD Sync. " that with hybrid you will never move away from this scenario.

This is regardless what it says in the support article under Direct Send about it being for internal mailboxes only (see the other scenarios text where it talks about using Direct Send for mailing lists - which are external by their nature).Īs for #3, you realise when you say "We will eventually move away from this and our internal mail server which is why we are not deploying new services that point to our internal mail server. This is why I did not suggest you try Option #1 and only either #2 or #3.įor either of these, it does not matter if the recipient is internal or external. Therefore for #1 you would need to login with the actual From address and not another account, but then MFA would impact you. The error "Diagnostic-Code: smtp 550 5.7.60 SMTP Client does not have permissions to send as this sender" means that the account you are logging in with does not have permission to send as the From address you are specifying. When I said that MFA has nothing to do with this, I mean this specific error.
