Why are app passwords a hidden risk in Microsoft 365?

You just enforced MFA for your team. All users are locked in, accounts secured. But one legacy email client still works fine on your boss’s phone. No prompts. No extra step. Why?

Because app passwords—designed as a workaround—bypass MFA entirely and stay active long after they should be gone. They’re like forgotten keys left under a mat: invisible until someone uses them to break in.

App password deletion in Microsoft 365 isn’t a luxury—it’s a necessity. If you don’t manage them, you’re leaving a backdoor open for attackers who exploit old, static credentials even after a password reset.

Key takeaways

  • App passwords can be used to access accounts without MFA, creating a security blind spot.
  • They remain valid indefinitely unless manually deleted, even after a user’s password changes.
  • Most admins don’t track them; unmonitored app passwords are a common exploit vector in Microsoft 365 breaches.

What happens when app passwords aren’t deleted?

Leaving app passwords active after they’re no longer needed creates a persistent entry point for attackers. Even if a user resets their main password, these app passwords can still grant full access—allowing hackers to bypass two-factor authentication and maintain long-term access to sensitive data. This is especially risky if credentials are leaked or stolen in a breach.

App passwords allow bypass of two-factor authentication

App passwords are designed so legacy apps can log in without requiring the full MFA flow. But that same convenience becomes a security hole: once an attacker has an app password, they don’t need the second factor. Even after your team resets passwords or enforces MFA, those old app passwords remain valid—unless manually deleted.

They expand the attack surface for common threats

Unused app passwords stretch your security perimeter. If credentials from one compromised app are exposed, attackers can reuse them across multiple services—especially if you don’t regularly audit app passwords. These tokens also make lateral movement easier in a network—if an attacker gains access via one app password, they may pivot to other systems with the same token.

Phishing attacks become more effective when attackers know an app password is still active. Users might be tricked into giving up a password, but if the real danger is an old, forgotten app password, they won’t realize a breach is still active.

Microsoft recommends disabling app passwords after the app no longer needs access. This is part of a broader strategy used by enterprises to reduce the attack surface. According to guidelines from the National Institute of Standards and Technology (NIST), long-lived credentials—especially those that bypass MFA—should be regularly reviewed and revoked when no longer required. NIST SP 800-63B emphasizes minimizing persistent access tokens to reduce risk.

That’s why regular audit and cleanup are critical. Use identity and access management tools to track app password usage. For teams managing large email lists, ensure that old verification methods don’t leave behind inactive sessions. You can check for risky or obsolete email validation pathways using inboxplacement testing and real-time email verification. With MailTester’s inbox placement and API, you test whether your email interactions are still trusted, reducing the risk of overlooked access points. Keep your systems clean by removing outdated app passwords—automated tools help, but manual review is still essential.

How to find app passwords in Microsoft 365

You can find app passwords in Microsoft 365 by navigating to the Microsoft 365 Admin Center, selecting a user, and viewing their app passwords under Sign-in activity. Only admins have access to this data—users cannot see their own app passwords, and each one is tied to a specific app or device. This visibility helps prevent unauthorized access by allowing you to audit which legacy apps still have access.

Step-by-step process to locate app passwords

  1. Go to the Microsoft 365 Admin Center. Sign in with your admin account and navigate to the Users > Active Users section. This is the central hub for managing user accounts and their authentication settings.
  2. Select a user and open their details. Click on the user’s name to access their profile. App passwords are not listed here—you need to look under Sign-in activity.
  3. Choose 'Manage app passwords'. Under the Sign-in activity section, you’ll find the option to manage app passwords. Selecting it reveals all legacy app passwords associated with that user.
  4. Review each app password. Each entry shows the application or device it was created for (e.g., Outlook, mobile device). This information helps you determine whether a password should still be active.
  5. Revoke unused or suspicious passwords. If you see an app password tied to an unknown or outdated system, delete it immediately. This prevents long-term access without requiring the user to re-authenticate.

Important limitations and security notes

App passwords are only visible to users with admin privileges. They are not stored in the user’s profile or personal settings, which is why regular users can’t see or manage them. This design prevents unintended exposure but requires admins to actively monitor access. According to Microsoft’s security guidelines, regular audit of app passwords is a recommended practice to reduce the risk of credential misuse.

Step-by-step process to locate app passwordsThe 5 steps described in “Step-by-step process to locate app passwords”, in order.1Go to the Microsoft 365 Admin Center. Sign in with your admin accountand navigate to the Users > Active Users section. This is the centralhub for managing user accounts and their authentication settings.2Select a user and open their details. Click on the user’s name to accesstheir profile. App passwords are not listed here—you need to look underSign-in activity.3Choose 'Manage app passwords'. Under the Sign-in activity section,you’ll find the option to manage app passwords. Selecting it reveals alllegacy app passwords associated with that user.4Review each app password. Each entry shows the application or device itwas created for (e.g., Outlook, mobile device). This information helpsyou determine whether a password should still be active.5Revoke unused or suspicious passwords. If you see an app password tiedto an unknown or outdated system, delete it immediately. This preventslong-term access without requiring the user to re-authenticate.
The 5 steps described in “Step-by-step process to locate app passwords”, in order.

For organizations using email lists to send communications, verifying that contacts are valid helps reduce the risk of sending to outdated or compromised accounts. While not directly related to app passwords, ensuring your list is clean supports broader security hygiene. Tools like MailTester’s bulk verification can help maintain list integrity by identifying invalid, disposable, or risky addresses before sending.

If you're integrating email services or managing senders at scale, consider using MailTester’s real-time API to validate emails on the fly. This adds a layer of protection beyond just endpoint access control.

How to delete app passwords in Microsoft 365

You can remove app passwords in Microsoft 365 by navigating to the app passwords section in your account settings, selecting the password you want to delete, and confirming the removal. Repeat this for each outdated, unused, or suspicious entry. For large-scale cleanup, use PowerShell commands to list and remove multiple app passwords efficiently.

Step-by-step deletion via the Microsoft 365 admin center

  1. Sign in to the Microsoft 365 admin center with an account that has global admin privileges.
  2. Navigate to Users > Active users, then select the user whose app password you want to manage.
  3. Under the user's profile, go to App passwords in the left-hand menu.
  4. Locate the specific app password you want to remove from the list. Each entry shows the app name and when it was created.
  5. Click the Delete button next to the entry. Confirm the deletion when prompted.
  6. Repeat steps 4–5 for every outdated or suspicious app password.

Deleting unused or suspicious app passwords limits the risk of unauthorized access, especially when those apps aren’t actively in use. According to Microsoft’s guidance on identity protection, limiting the lifetime of app passwords reduces the window for credential misuse. This aligns with industry best practices for managing authentication tokens and minimizing attack surface.

Step-by-step deletion via the Microsoft 365 admin centerThe 6 steps described in “Step-by-step deletion via the Microsoft 365 admin center”, in order.1Sign in to the Microsoft 365 admin center with an account that hasglobal admin privileges.2Navigate to Users > Active users, then select the user whose apppassword you want to manage.3Under the user's profile, go to App passwords in the left-hand menu.4Locate the specific app password you want to remove from the list. Eachentry shows the app name and when it was created.5Click the Delete button next to the entry. Confirm the deletion whenprompted.6Repeat steps 4–5 for every outdated or suspicious app password.
The 6 steps described in “Step-by-step deletion via the Microsoft 365 admin center”, in order.

Use PowerShell for bulk deletion

For multiple users or many app passwords, PowerShell streamlines the process. The command Get-MsolUser lists all users with app passwords. You can then iterate over the list and use Remove-MsolUserAppPassword to delete them in bulk.

Running these commands requires the Azure AD Module for PowerShell. Always test scripts in a controlled environment first, and ensure you’re backing up any necessary data before deletion. Microsoft’s official documentation on managing app passwords covers this process in depth.

Even if you don’t manage apps manually, regular audits prevent credential sprawl. A single forgotten app password can be a foothold for attackers, especially if the associated app has weak security practices. Reviewing and purging old or unused credentials is a key step in maintaining account integrity.

For teams managing large email lists, verify the quality of addresses before sending—bad data can lead to bounce loops, delivery issues, and reputation damage. Using reliable tools like MailTester’s bulk verification helps ensure your sender reputation stays strong.

What to do after deleting an app password

After deleting an app password in Microsoft 365, notify the user if they rely on the app for email, calendar, or file sync. Require them to reconfigure the app with a new password or switch to modern authentication. Enforce MFA for all accounts and monitor sign-in logs for suspicious activity tied to the old credential. This stops unauthorized access and maintains security posture.

Immediate follow-up steps

  • Check if the affected user relies on legacy apps (like older mail clients or mobile sync tools) and inform them that the app will no longer work without re-authentication.
  • Guide the user to reconfigure their app using a new app password or, better yet, switch to modern authentication protocols such as OAuth 2.0 or Microsoft’s modern auth APIs.
  • Verify that Multi-Factor Authentication (MFA) is enabled and enforced for all user accounts. Without MFA, even a valid app password is a single point of failure.
  • Review recent sign-in logs in the Microsoft 365 Defender portal. Look for any activity associated with the deleted password, especially from unfamiliar locations or devices. The Microsoft Defender for Cloud Apps provides visibility into risky logins.
  • Reset the user’s password if any suspicious activity is detected, even if no breach was confirmed. A proactive reset is standard incident response practice.

Long-term security reinforcement

  • Disable app passwords entirely for all users where possible. Use modern authentication and conditional access policies to control access without legacy credentials.
  • Set up continuous monitoring for sign-in anomalies using Microsoft’s built-in Threat Management or third-party tools to catch attempts using old or leaked passwords.
  • Use email verification to ensure that user contact information is accurate and up-to-date. If your organization sends security alerts or MFA prompts, you can reduce false positives by verifying your user list with bulk verification.
  • Enable the Microsoft 365 activity logs to track configuration changes and admin actions. This helps audit when and why app passwords were created or deleted.
  • Train users on why app passwords are risky and how to use more secure alternatives like the Outlook mobile app or browser-based access through Microsoft Defender with conditional access policies.

App passwords vs. modern authentication: what’s the difference?

App passwords are legacy tokens used by older applications that can’t support modern OAuth2 authentication. They grant access without requiring user interaction and persist indefinitely, increasing the risk of unauthorized access if leaked. Modern authentication, by contrast, uses OAuth2 and device trust, requiring re-authentication when tokens expire—making it far more secure. If your app still relies on app passwords, it’s time to update or replace it.

Why app passwords exist—and why they’re risky

App passwords were introduced as a workaround for legacy apps that couldn’t use OAuth2. These apps, often older desktop clients or scripts, can’t handle the modern login flow, so Microsoft issues a one-time password that bypasses multi-factor authentication (MFA). The trade-off is convenience at the cost of security.

Once generated, an app password stays active until manually deleted. If compromised, attackers can use it indefinitely without triggering MFA alerts. This is a known risk vector—Microsoft’s own documentation warns that long-lived credentials increase exposure to credential theft attacks.

How modern authentication improves security

Modern authentication uses OAuth2 and device trust, tying login sessions to verified devices and users. Apps request access through a standardized, encrypted flow. Even if a token is stolen, short expiry times limit the window for abuse. You’re prompted to re-authenticate when tokens expire—usually every 90 days or less—ensuring regular trust verification.

Apps supporting modern auth don’t store passwords at all. Instead, they use short-lived access tokens, which the user approves once and then renew automatically within trusted sessions. This reduces the attack surface significantly compared to static app passwords.

Let’s be clear: if your app still uses an app password, it’s not following current best practices. Microsoft recommends phasing out legacy authentication methods. This includes disabling app passwords in your tenant when possible. If you’re unsure whether an app supports modern auth, refer to the official Microsoft guide on app and user security configurations.

For teams managing large email lists, verifying identities at scale helps avoid sending to invalid or high-risk accounts—reducing the risk of phishing, bounce fatigue, and accidental exposure. You can test how well emails land in inboxes with MailTester’s inbox placement tool, and verify your list’s health with a bulk verification tool like MailTester’s email list verification.

How to reduce reliance on app passwords in your organization

You can reduce app password use by forcing modern authentication in Azure AD, replacing legacy app password integrations with OAuth2 or API-based methods, applying least-privilege access controls, and phasing out tools that only support app passwords. This reduces security risks and aligns with Microsoft’s recommended security posture.

Enforce modern authentication by default

  • Go to the Azure AD portal and set Modern Authentication as the default for all users.
  • Disable legacy auth protocols like Basic Auth for POP/IMAP and SMTP by configuring conditional access policies.
  • Use Microsoft’s conditional access guidance to block older protocols where they aren’t needed.

Replace app passwords with secure integrations

  • Identify tools relying on app passwords—especially email clients, backup software, or automation platforms.
  • Update these tools to use OAuth2 or official APIs. Most major platforms now support this; check your app’s documentation.
  • For custom scripts or bots, use service accounts with Azure AD app registrations and fine-grained permissions.
  • Use MailTester integrations with CRM or marketing tools to verify email lists and catch invalid addresses early, reducing the need for repeated send attempts that depend on flawed credentials.

Apply least-privilege access and retire outdated tools

  • Assign only the minimal permissions a tool needs—never grant full mailbox access unless absolutely required.
  • Regularly audit app permissions via Azure AD’s Enterprise Applications section.
  • Discontinue support or disable access for any tool that cannot be updated to use modern auth or API integration.
  • When you find an app that still insists on app passwords, consider alternative tools with better security practices.
“Organizations that continue to allow app passwords are increasing their attack surface. Modern authentication significantly reduces risk from credential theft.”

Tools like MailTester’s API help verify and clean your email list before send. This reduces failed deliveries and lowers the temptation to reuse credentials in unreliable tools. It’s easier to maintain security when you’re not chasing failed login attempts.

Start with a small pilot—disable app passwords for one department, enforce OAuth2 on all supported apps, and monitor for issues. Most problems arise from outdated tools, not modern auth. Upgrade what you can, deprecate the rest.

App passwords and list hygiene: why this matters for email delivery

Active app passwords in Microsoft 365 often point to outdated or poorly managed email lists. If a user’s app password is linked to a compromised system, that system could be sending spam—flagging your domain and harming deliverability. Unverified or stale app passwords increase the risk of your sender reputation being flagged as high-risk. Regularly reviewing and removing unused app passwords helps maintain inbox placement and sender reputation.

App passwords as a red flag for list quality

When a user generates an app password, it usually means they’re connecting a third-party app to their account—often without a strong verification process. If that app is poorly maintained or compromised, it might be used to send unsolicited messages. That activity traces back to your domain, especially if the user is part of a shared mailing list. Even a single compromised account with an active app password can trigger spam filters, leading to hard bounces, blocklists, or blackhole routing.

For example, a study by Microsoft’s Security Intelligence Report noted that compromised credentials were involved in over 80% of cloud-based attacks. While it doesn’t list app passwords specifically, it underscores that outdated or unmonitored access methods amplify risk. That’s why keeping your user base and access controls current is part of sender hygiene.

How list hygiene supports deliverability

Spam scoring systems don’t just look at content—they examine account behavior. A large number of inactive or misused app passwords signals that your list isn’t well maintained. This raises red flags with mailbox providers like Gmail, Outlook, and Yahoo. They’re trained to spot patterns: if a domain has many stale or unverified access points, it may be associated with spam traps or low engagement, reducing inbox placement.

That’s where regular verification helps. Tools like MailTester can help you audit your list for high-risk addresses, catch-all accounts, and inactive email sources—including users whose app passwords might still be active. Use the bulk verification feature to clean outdated entries and assess list strength. The inbox placement test can simulate how your emails actually land in real inboxes across providers, not just based on reputation scores.

Let’s not assume every active app password is dangerous—but don’t ignore them either. Treat them like any other access point: verify use, retire the old ones, and keep your sender reputation clear. Consistent maintenance prevents accidental spam flags, keeps your emails out of the junk folder, and preserves your reputation with mailbox providers.

MailTester’s role in securing your email infrastructure

You can reduce the risk of unauthorized access in Microsoft 365 by ensuring only valid, active, and secure email addresses are in your system. MailTester helps you verify every address before sending, catch risky or impersonated accounts early, and test real-world inbox placement—stopping abuse before it starts. You’re not just deleting app passwords; you’re preventing the conditions that trigger them.

Proactively secure your email list with verification

  • Use MailTester’s bulk verification to check entire lists for invalid, role-based, or disposable emails before sending—reducing bounce rates and minimizing exposure to compromised accounts [RFC 5321].
  • Test your email addresses in real inboxes with our inbox-placement tool inbox tester to confirm deliverability and avoid spam folder placement that could mask abuse attempts.
  • Identify catch-all domains early—these often accept any address, making them prime for bot abuse or credential stuffing, which could lead to app password misuse.
  • Spot role accounts like admin@, support@, or postmaster@ in your list; these are frequently exploited in automated attacks or used to bypass security checks via weak authentication.
  • Use our real-time API verification API to validate every new signup or onboarding record in real time, stopping risky entries before they enter your system.
  • Run periodic audits on old or dormant lists with our bulk email verifier—especially if you’ve ever used third-party services or imported data from untrusted sources.

Stop abuse before credentials are compromised

App password triggers often follow repeated failed logins or suspicious activity. When you clean your lists early, you reduce the surface area for automated abuse. MailTester’s 98.9% accuracy gives you confidence that the addresses you’re verifying are actual, reachable mailboxes—not placeholders or dead ends.

Integrate MailTester with your CRM, marketing platform, or identity system via our integrations to maintain consistent validation across teams. Even if you can’t delete app passwords in bulk, you can stop the root causes: bad addresses, fake domains, and compromised roles.

With all your data validated and your sending practices hardened, you reduce the need for emergency app password resets—because you never had a compromised account in the first place.

App password deletion is just one part of email hygiene

Deleting outdated app passwords is necessary, but it’s only one layer of email hygiene. True security and deliverability require auditing your entire email ecosystem—including list quality, authentication settings, and sender reputation. Even with valid credentials, a dirty list can still trigger spam filters and harm your domain’s standing with inbox providers.

Authentication alone doesn’t guarantee inbox placement

Secure authentication via SPF, DKIM, and DMARC is essential, but it’s not enough. These protocols verify sender identity, not list quality. If your list includes invalid or dormant addresses, even properly authenticated emails can be rejected or marked as spam. Inconsistent sender reputation—caused by poor list hygiene—can result in throttling or outright blocking by email providers.

Studies show that senders with high bounce and complaint rates see a measurable drop in inbox placement. For example, a single spam complaint can impact deliverability across many platforms, regardless of technical setup. That’s why continuous list hygiene is not optional—it’s mandatory.

Automated verification is the only reliable way to maintain list quality

Let’s be honest: manual checks don’t scale, and guesswork fails. You need tools that check each email in real time for syntax, domain validity, and inbox placement potential. Services like MailTester’s bulk verification can process thousands of addresses at once, flagging invalid, catch-all, or risky addresses before you send.

Use the real-time verification API to verify emails during sign-up or data ingestion. Combine that with regular inbox placement testing to see how your messages land across Gmail, Outlook, and other providers. These aren’t just convenience features—they’re essential for detecting subtle delivery issues before they escalate.

Don’t stop with app passwords. Run periodic DNS checks to ensure your SPF and DMARC records are properly configured. Monitor your sender reputation through third-party services like Spamhaus or MxToolbox. These services track blacklists and provide early warnings.

Ultimately, email hygiene is a continuous cycle: verify your lists, clean them often, test deliverability, and audit authentication settings. The goal isn’t just security—it’s reliability. When you combine all these practices, you reduce risk, maintain good reputation, and maximize inbox placement.

Final step: secure your email ecosystem today

Unused app passwords are a persistent risk vector. Delete them now to eliminate forgotten or leaked credentials that bypass modern security checks.

Enforce modern authentication across your organization. This shuts down outdated access methods that allow unauthorized apps and scripts to bypass MFA and other protections.

Run a full email list cleanup using real-time verification tools. Confirm active, valid addresses and remove inactive, invalid, or risky ones to reduce exposure to phishing and spam exploits.

Monitor for sign-in anomalies monthly. Revalidate access controls and audit app permissions to ensure no outdated or unauthorized access persists.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Can app passwords be re-enabled after deletion?

No. Once deleted, app passwords cannot be restored. Users must reconfigure their apps with a new password or switch to modern authentication.

Do app passwords expire automatically?

No. App passwords remain active until manually deleted by an administrator, even if the user’s main password changes.

How do I check if an app password was used recently?

Review the sign-in logs in the Microsoft 365 Admin Center. Look for failed or suspicious sign-in attempts tied to app password use.

Can app passwords be disabled for all users at once?

Yes, via PowerShell or by disabling legacy authentication policies in Azure AD, but this may break older apps.

What happens if a user needs app password access for a legacy system?

Replace the legacy system with a modern equivalent or add access via secure API integration instead of app passwords.

Are app passwords still supported in 2026?

Microsoft continues to support them for backward compatibility but strongly recommends migrating to OAuth2.

How often should I audit app passwords?

At minimum once per quarter, or whenever a user leaves, changes role, or a security incident occurs.

Do app passwords affect sender reputation?

Indirectly. They increase risk of compromised accounts, which can lead to spam triggers, blacklisting, and poor inbox placement.

Can MailTester detect if an email address was used with an app password?

No. MailTester verifies address validity and deliverability, not authentication methods or app password history.

Does deleting an app password affect my email list hygiene?

Yes. It reduces the risk from stale or compromised accounts, which improves list quality and deliverability.

How do I start cleaning my email list with MailTester?

Use our free 100-verification allowance. Upload your list and receive verdicts: valid, invalid, catch-all, or risky.

Do MailTester credits expire?

No. Purchased credits never expire, so you can maintain consistent list hygiene over time.