If you wish to enable Microsoft OAuth 2 authentication for your email connection then you will need to enable the OAuth 2 plugin on your Totara site and go to the Microsoft developer console to configure authentication.
Go to the Microsoft Azure portal.
Click New registration under App registrations.
Give your app a name, e.g. 'Totara Email'.
Select the appropriate option for Supported account types. Either Accounts in any organizational directory (Any Azure AD directory - Multitenant) or Accounts in this organizational directory only (Single tenant) may be used, depending on the organisation's Azure configuration.
Many organisations use a Single tenant configuration for security and organisational reasons. If Single tenant is selected, the endpoints configured later must reference the Tenant ID rather than /common/ (see the note at step 25).
Choose Web for Redirect URI.
Add your site's URL appended with /admin/oauth2callback.php to the Redirect URLs section e.g. 'https://totaralearn.com/admin/oauth2callback.php'.
Click Register.
Take a note of the Application (client) ID.
Select Authentication from the side menu.
Ensure that the Implicit grant settings are disabled.
Select API permissions from the side menu.
Ensure that the SMTP.Send and offline_access permissions are available under Microsoft Graph, and if they are not then add them as delegated permissions.
Select Certificates & secrets from the side menu and click New client secret.
Add a description, e.g. your app name (Totara Email), and select when the password/secret will expire.
Copy the generated secret Value (not the Secret ID) for use in Totara.
Recommended: create a Microsoft SMTP service
From Totara 18.7 onwards, the OAuth 2 issuers page includes a Create new Microsoft SMTP service button. This option is recommended because it creates the correct endpoints by default and configures the required scopes automatically. Only the Client ID and Client Secret need to be added. If this option is used, the manual custom service steps below are not required.
In Totara go to Quick-access menu > Server > OAuth 2 > OAuth 2 consumer details.
Click Create new Microsoft SMTP service.
Enter the application ID from the Microsoft Azure portal as the Client ID, and the Secret Value copied in step 16 as the Secret.
Uncheck Show on login page (it is recommended that the email and login OAuth services are not mixed).
Click Save changes.
If the Azure app is configured as Single tenant, edit the endpoints created for this service and replace /common/ in each endpoint URL with the Tenant ID (see the note at step 25). If the app is Multitenant, no change is required.
Once the Microsoft SMTP service is created and connected, continue from the Connect to a system account step below (step 27).
Alternative: create a custom service manually
If the Create new Microsoft SMTP service option is not available (for example on sites earlier than Totara 18.7), a custom service can be created manually as follows.
In Totara go to Quick-access menu > Server > OAuth 2 > OAuth 2 consumer details.
Click Create a new custom service.
Enter a name, e.g. 'Microsoft Email OAuth'.
Enter the Secret Value generated in the Microsoft Azure portal (copied in step 16) as the Secret and the application ID as the Client ID.
In Scopes included in a login request enter any value. This field is not used, but a value must be provided.
In Scopes included in a login request for offline access add the following:
https://outlook.office.com/SMTP.Send offline_accessUncheck Show on login page (it is recommended that you do not mix the email and login OAuth services).
Click Save changes.
Click the Configure endpoints icon for the new service.
Click Create new endpoints, then add the following:
Name | URL |
|---|---|
authorization_endpoint | https://login.microsoftonline.com/common/oauth2/v2.0/authorize |
token_endpoint |
If the Azure app is configured as Single tenant, the /common/ segment in each endpoint URL must be replaced with the Tenant ID of the OAuth 2 app in Azure. For example, if the Tenant ID is 46314b30-b357-4da6-8f22-0184a12371c0, the authorization_endpoint becomes:
https://login.microsoftonline.com/46314b30-b357-4da6-8f22-0184a12371c0/oauth2/v2.0/authorize
and the token_endpoint becomes:
https://login.microsoftonline.com/46314b30-b357-4da6-8f22-0184a12371c0/oauth2/v2.0/token
If the app is configured as Multitenant, the /common/ endpoints above should be used unchanged. If a Single tenant app is used but the endpoints are not updated accordingly, the connection will not work.
Connect the account and configure outgoing mail
Return to the OAuth 2 services page.
Click the Connect to a system account icon.
Click Continue.
Sign in with your Microsoft email account that is used for your Totara email service.
Accept the permissions in Microsoft.
Go to Quick-access menu > Server > Email > Outgoing mail configuration.
Change SMTP Auth Type to XOAUTH2.
Change Oauth2 Service and choose the OAuth service you just created.
Set SMTP Username to the email of the account used for sending email (this should be the same as the No-reply address, i.e. the email address of the user connected via OAuth).
Set SMTP Password to any random text. It must not be blank, but otherwise, it does not matter.
Click Save changes.
Join the Totara Community for more resources to help you get the most out of Totara.
© Copyright 2026 Totara Learning Solutions. All rights reserved.