What Outlook app passwords are
Outlook app passwords are special one-time passwords used with older email apps and devices that cannot handle modern authentication.
They were commonly created for Microsoft accounts, Exchange Online, and Office 365 sign-ins when two-factor authentication was enabled.
If you are trying to learn how to remove Outlook app passwords, the first step is understanding that these passwords are not stored inside the Outlook desktop app itself.
They live in your Microsoft account security settings, and they usually remain active until you delete them or disable the feature that allows them.
Removing them matters because app passwords bypass modern sign-in protections such as multifactor authentication, conditional access, and token-based authentication.
Once you migrate to modern authentication, they become unnecessary and should be retired.
Why you should remove app passwords
App passwords are a compatibility workaround, not a security best practice.
They are typically used by legacy mail clients, older mobile devices, or IMAP/POP apps that do not support Microsoft Authenticator, OAuth 2.0, or other modern sign-in flows.
- They can keep outdated devices connected longer than you intended.
- They bypass second-factor prompts, which weakens account protection.
- They can be difficult to track if multiple users created them over time.
- They may continue to work even after you change your normal account password.
For most Microsoft 365 and Outlook users, the preferred approach is to remove app passwords after updating the device or app to support modern authentication.
Before you remove Outlook app passwords
Before deleting anything, verify that every device and email client using your Microsoft account supports modern authentication.
This includes Outlook for Windows, Outlook for Mac, Outlook for iOS and Android, and many current third-party clients.
Check for the following:
- Outlook is updated to the latest version available for your platform.
- Two-factor authentication is enabled on the Microsoft account.
- Any older devices using POP, IMAP, or SMTP AUTH have been replaced or reconfigured.
- Your organization does not require a legacy app for a business-critical workflow.
If you remove an app password before confirming compatibility, the connected app may stop sending or receiving email until it is updated or replaced.
How to remove Outlook app passwords in a Microsoft account
For personal Microsoft accounts, app passwords are managed from the security section of the account portal.
The exact wording may vary slightly depending on current Microsoft account interface updates, but the process is similar.
- Sign in to your Microsoft account at the official account security page.
- Open the Security tab or Security info section.
- Look for Advanced security options, App passwords, or additional security settings.
- Find the app password you want to remove.
- Select Delete, Remove, or a similar option.
- Confirm the change when prompted.
Once removed, that specific app password should no longer work.
If you had multiple app passwords, repeat the process for each one you want to revoke.
How to remove Outlook app passwords in Microsoft 365 work or school accounts
For Microsoft 365 business, education, or enterprise accounts, app password behavior depends on the tenant settings configured by the administrator.
In many environments, users can only create or remove app passwords if the admin has allowed them.
Users should check their security info page or the My Account portal.
If the option is missing, an administrator may need to disable legacy authentication, reset authentication methods, or clear app passwords centrally.
Administrators may use Microsoft Entra ID, Conditional Access, or Exchange Online policies to block legacy protocols.
In some cases, simply removing the app password is not enough if the underlying client still authenticates through POP, IMAP, or basic SMTP methods.
Admin steps that commonly matter
- Disable basic authentication for Exchange Online protocols.
- Require modern authentication for Outlook and other email clients.
- Review sign-in logs in Microsoft Entra ID for legacy protocol usage.
- Update conditional access policies to block risky sign-in methods.
For organizations, the most effective fix is often policy-based removal rather than deleting one password at a time.
How to stop Outlook from asking for app passwords again
If Outlook keeps prompting for an app password, the issue is usually that the account is still using a legacy connection method.
Removing the password is only part of the solution.
Try these steps:
- Update Outlook to the newest supported version.
- Remove and re-add the account using the Microsoft sign-in window.
- Switch from POP or IMAP to Exchange or Microsoft 365 sync if possible.
- Make sure MFA is configured with an authenticator app, SMS, or a hardware security key.
- Remove any stored credentials from Windows Credential Manager or macOS Keychain if they are outdated.
In many cases, the prompt disappears only after the app itself is moved from legacy authentication to modern authentication.
How to verify that an app password was removed
After deletion, test the affected email client or device.
If the password was successfully revoked, the app should fail to sign in with the old credential and may ask for a fresh sign-in method.
You can also review recent activity in your Microsoft account or Microsoft Entra sign-in logs if available.
Look for failed login attempts from the old app or protocol.
This can help confirm that the old credential is no longer valid.
If the app still works after removal, check whether it is using a different saved password, a refresh token, or a separate account credential stored elsewhere on the device.
What to do if you cannot find the app password setting
Not every Microsoft account exposes app passwords the same way.
In some cases, Microsoft has reduced the visibility of app password options as modern authentication becomes standard.
If you do not see the setting, one of these situations may apply.
- Your account does not support app passwords.
- Two-factor authentication is not enabled, so app passwords are unnecessary.
- Your organization has disabled app passwords through policy.
- The account is using a newer authentication flow that does not create separate app passwords.
If you are unsure, check the account’s security settings or contact your Microsoft 365 administrator.
For enterprise environments, the absence of app passwords is often a sign that stronger authentication controls are already in place.
Best practices after removing Outlook app passwords
Once you remove app passwords, take a few additional steps to protect the account and reduce future sign-in issues.
- Use the Microsoft Authenticator app or a hardware security key where supported.
- Review all connected devices and remove anything you no longer use.
- Audit Outlook on desktop, mobile, and web to ensure they all sign in normally.
- Keep recovery email addresses and phone numbers current.
- Monitor account security alerts for unusual sign-in attempts.
These steps help ensure that removing the password does not interrupt your workflow and that your account remains protected with modern identity controls.
Common problems after removing an app password
Some users notice that email, calendar sync, or contacts stop updating after the password is deleted.
That usually means the device or app still depends on legacy authentication.
Typical fixes include reconfiguring the account with the modern Microsoft sign-in experience, replacing the app with a supported Outlook version, or adjusting tenant policies that block outdated protocols without a migration path.
If the device is very old, it may not support OAuth-based authentication at all.
In that case, the most reliable option is to replace the device or move the mailbox access to a supported client.
When to ask an administrator for help
Work and school accounts often have controls that prevent users from independently managing app passwords.
If you cannot remove the password yourself, or if removing it breaks a business app, an IT administrator should review the setup.
An administrator can determine whether the app is using Exchange ActiveSync, IMAP, POP, or SMTP AUTH, and whether those protocols should remain enabled.
They can also check whether Azure AD, now Microsoft Entra ID, is enforcing policies that require a more secure sign-in method.
For shared mailboxes, automated scanners, or third-party migration tools, admin oversight is especially important because one outdated credential can affect multiple services.