If you wish to enable Microsoft OAuth 2 authentication for your email connection then you will need to enable the OAuth 2 plugin on your Totara site and go to the Microsoft developer console to configure authentication.
Configure the app in the Microsoft Azure portal
- Go to the Microsoft Azure portal.
- Click New registration under App registrations.
- Give your app a name, e.g. 'Totara Email'.
- Select the appropriate option for Supported account types. Either Accounts in any organizational directory (Any Azure AD directory - Multitenant) or Accounts in this organizational directory only (Single tenant) can be used. Many organisations use Single tenant for security and organisational reasons.Note: If Single tenant is selected, the OAuth 2 endpoints configured later in Totara must use the Tenant ID rather than /common/ (see the Single tenant note in the endpoint configuration below).
- Choose Web for Redirect URI.
- Add your site's URL appended with /admin/oauth2callback.php to the Redirect URLs section e.g. 'https://totaralearn.com/admin/oauth2callback.php'.
- Click Register.
- Take a note of the Application (client) ID. If Single tenant was selected, also take a note of the Directory (tenant) ID.
- Select Authentication from the side menu.
- Ensure that the Implicit grant settings are disabled.
- Select API permissions from the side menu.
- Ensure that the SMTP.Send and offline_access permissions are available under Microsoft Graph, and if they are not then add them as delegated permissions.
- Select Certificates & secrets from the side menu and click New client secret.
- Add a description, e.g. your app name (Totara Email), and select when the password/secret will expire.
- Copy the generated secret Value for use in Totara. Copy the Value column, not the Secret ID — the value cannot be retrieved again once you navigate away from this page.
Configure the OAuth 2 service in Totara (recommended)
From Totara 18.7 onwards, the OAuth 2 issuers page provides a Create new Microsoft SMTP service option. This option creates the correct endpoints and configures the required scopes automatically, so only the Client ID and Client Secret need to be added.
- In Totara go to Quick-access menu > Server > OAuth 2 > OAuth 2 consumer details and click Create new Microsoft SMTP service.
- Enter a name, e.g. 'Microsoft Email OAuth'.
- Enter the Client ID (the Application (client) ID from Azure) and the Client secret (the secret Value generated in Azure in the previous step, not the Secret ID).
- Uncheck Show on login page (it is recommended that you do not mix the email and login OAuth services).
- Click Save changes.
https://login.microsoftonline.com/common/oauth2/v2.0/authorize
becomes
https://login.microsoftonline.com/46314b30-b357-4da6-8f22-0184a12371c0/oauth2/v2.0/authorize
Alternative: create a custom OAuth 2 service manually
If the Create new Microsoft SMTP service option is not available, a custom service can be configured manually. The endpoints and scopes must then be added by hand.
- In Totara go to Quick-access menu > Server > OAuth 2 > OAuth 2 consumer details.
- Click Create a new custom service.
- Enter a name, e.g. 'Microsoft Email OAuth'.
- Enter the secret Value generated in the Microsoft Azure portal (not the Secret ID) as the Secret and the application ID as the Client ID.
- In Scopes included in a login request enter any value. This field is not used, but a value must be provided.
- In Scopes included in a login request for offline access add the following:
https://outlook.office.com/SMTP.Send offline_access - Uncheck Show on login page (it is recommended that you do not mix the email and login OAuth services).
- Click Save changes.
- Click the Configure endpoints icon for the new service.
- Click Create new endpoints, then add the following:
| Name | URL |
|---|---|
authorization_endpoint | https://login.microsoftonline.com/common/oauth2/v2.0/authorize |
token_endpoint |
Connect the account and configure outgoing mail
- Return to the OAuth 2 services page.
- Click the Connect to a system account icon.
- Click Continue.
- Sign in with your Microsoft email account that is used for your Totara email service.
- Accept the permissions in Microsoft.
- Go to Quick-access menu > Server > Email > Outgoing mail configuration.
- Change SMTP Auth Type to XOAUTH2.
- Change Oauth2 Service and choose the OAuth service you just created.
- Set SMTP Username to the email of the account used for sending email (this should be the same as the No-reply address, i.e. the email address of the user connected via OAuth).
- Set SMTP Password to any random text. It must not be blank, but otherwise, it does not matter.
- Click Save changes.
Join the Totara Community for more resources to help you get the most out of Totara.
© Copyright 2026 Totara Learning Solutions. All rights reserved.