Outlook keeps asking for a password with Microsoft 365 when it cannot get or keep an OAuth token for the mailbox. On current Windows and Microsoft 365 Apps builds that almost always traces back to one of four things: broken or blocked Web Account Manager (WAM) plug-ins, an Outlook profile that still negotiates the old RPC-era authentication after a migration, a profile that mixes accounts, or tenant session settings that force reauthentication. Diagnose which one applies, fix it at the source, and do not disable WAM.
Who this is for and what you will have at the end
This guide is for Microsoft 365 administrators and desktop support engineers dealing with classic Outlook for Windows that shows "Need Password", "Trying to connect..." or a sign-in window that returns every few minutes or after every restart. By the end you will have:
- A way to tell which authentication method Outlook is actually using.
- Confirmation that modern authentication is on for the tenant and that the device holds a valid Primary Refresh Token (PRT).
- Re-registered WAM plug-ins and a list of security software exclusions to stop them breaking again.
- The registry fix for hybrid and migrated mailboxes.
- A reviewed set of Microsoft Entra session settings that don't prompt users more than they need to.
How Outlook signs in today
Starting in build 16.0.7967, Microsoft 365 Apps use Web Account Manager for sign-in on Windows 10 version 1703 and later. WAM is a Windows component: the Microsoft Entra WAM plug-in (package Microsoft.AAD.BrokerPlugin) handles work and school accounts, and the Microsoft.Windows.CloudExperienceHost package handles personal Microsoft accounts. Both plug-ins are installed per user profile, so one user on a device can be affected while another is not.
On Microsoft Entra joined and hybrid joined devices, the user also has a Primary Refresh Token that WAM uses for single sign-on. When the plug-ins or the PRT are healthy, Outlook gets tokens silently. When they are not, Outlook shows a credential prompt, and if the token still cannot be issued, the prompt comes back.
Exchange Online no longer accepts Basic authentication for Outlook for Windows, Outlook for Mac, EWS, Autodiscover or the Offline Address Book, and nobody can re-enable it. A prompt that looks like the old grey Windows security dialog rather than the Microsoft sign-in page is therefore a strong sign that Outlook is trying an authentication method the service will reject.
| Symptom | Most likely cause | Section |
|---|---|---|
| Prompts on one user profile only, blank or frozen sign-in window | WAM plug-ins missing or damaged | Step 3 and Step 4 |
| Prompts return after every antivirus scan | Security software blocking or removing WAM | Step 4 |
| Old-style credential dialog after a migration from Exchange on-premises | Outlook limited to RPC authentication schemes | Step 5 |
| Mailbox shows "Disconnected" with several accounts in one profile | Windows supplies the default account instead of the mailbox account | Step 6 |
| Prompts at regular intervals for many users | Session lifetime or MFA settings | Step 7 |
Prerequisites
- Classic Outlook for Windows from Microsoft 365 Apps or a supported perpetual version. Outlook 2007 and Outlook 2010 cannot use modern authentication, so with Basic authentication gone they can't keep a working Exchange Online connection.
- Access to the affected user's Windows session. WAM repairs must run in the user's context, not as a different administrator.
- Exchange Online PowerShell for the tenant check. If
Connect-ExchangeOnlineitself fails, see Connect-ExchangeOnline errors and fixes. - Microsoft Entra admin center access to read sign-in logs, plus the Conditional Access Administrator role to review sign-in frequency policies and the Authentication Policy Administrator role to review the Remember multifactor authentication setting.
Step 1: Confirm what Outlook is actually using
Before changing anything, look at the connection. Press and hold Ctrl, select the Outlook icon in the notification area, and then select Connection Status. The Authn column shows the authentication type for each connection. Values Microsoft documents include Clear (Basic authentication), NTLM, Nego, Kerberos, Anonymous and Bearer. Bearer indicates token-based authentication, which is what modern authentication uses, so that is what a healthy Exchange Online connection should show. If you see Clear against an Exchange Online mailbox, Outlook is not using modern authentication for that connection and will keep prompting.
Note also the SMTP Address column. If only one of several mailboxes in the profile shows the problem, jump to Step 6.
Step 2: Check the tenant setting for modern authentication
Modern authentication has been on by default in Exchange Online since August 2017, but older tenants may have turned it off. Check it once, then rule it out:
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
Get-OrganizationConfig | Format-Table Name,OAuth* -AutoOAuth2ClientProfileEnabled should be True. If it is False, turn it on:
Set-OrganizationConfig -OAuth2ClientProfileEnabled $trueThe same switch is in the Microsoft 365 admin center under Settings > Org Settings > Modern Authentication, labelled Turn on modern authentication for Outlook 2013 for Windows and later (recommended). The setting only affects Outlook for Windows. When you enable it, Outlook clients that support modern authentication are prompted to sign in once more, which is expected.
Step 3: Check the device and the user's token state
Run dsregcmd /status from a normal, non-elevated command prompt signed in as the affected user. The SSO and user state fields need the user context to report correctly.
dsregcmd /statusLook at these fields:
| Field | What you want | What it means if not |
|---|---|---|
AzureAdJoined or DomainJoined with AzureAdJoined | YES for Entra joined or hybrid joined | Device can't get a PRT; Outlook relies on per-app tokens |
DeviceAuthStatus | SUCCESS | FAILED. Device is either disabled or deleted means the device object needs fixing in Entra ID |
WamDefaultSet | YES | No default WAM account for this user |
AzureAdPrt | YES | No PRT for the signed-in user |
AzureAdPrtUpdateTime | Recent | PRT is not being renewed |
When PRT acquisition or refresh fails, dsregcmd adds diagnostic fields such as Attempt Status, Server Error Code and Server Error Description (for example an AADSTS error). Those errors point to identity problems outside Outlook, such as a changed password or a disabled device, and must be fixed first.
On devices that are not joined to Entra ID, each app holds its own refresh token, so users can see several prompts, one per app. That is by design rather than a fault; joining or registering the device is the long-term fix.
Step 4: Repair the WAM plug-ins
Microsoft documents the following symptoms of broken or tampered WAM plug-ins: intermittent prompts, a blank or stuck sign-in window, Outlook showing "Trying to connect...", and in Event Viewer > Windows Logs > Application, AppModel-State events such as:
Triggered repair of state locations because operation SettingsInitialize against package Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy hit error
Repair for operation LocalSettings against package Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy with error
Failure to load the application settings for packageSigned in as the affected user, check that both packages exist:
Get-AppxPackage Microsoft.AAD.BrokerPlugin
Get-AppxPackage Microsoft.Windows.CloudExperienceHostIf both return a package, test that they launch. Each command should open a Work or school account or Microsoft account window:
explorer.exe shell:appsFolder\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy!App
explorer.exe shell:appsFolder\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy!AppIf either package is missing or its window does not open, re-register it:
Add-AppxPackage -Register "$env:windir\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Appxmanifest.xml" -DisableDevelopmentMode -ForceApplicationShutdown
Add-AppxPackage -Register "$env:windir\SystemApps\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Appxmanifest.xml" -DisableDevelopmentMode -ForceApplicationShutdownMicrosoft also publishes a conditional form that only re-registers the work account plug-in when it is missing. Where security software keeps removing the plug-ins, Microsoft suggests running a re-installation from a background PowerShell script or Group Policy logon script as a temporary mitigation until the exclusions below are in place:
if (-not (Get-AppxPackage Microsoft.AAD.BrokerPlugin)) { Add-AppxPackage -Register "$env:windir\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Appxmanifest.xml" -DisableDevelopmentMode -ForceApplicationShutdown } Get-AppxPackage Microsoft.AAD.BrokerPluginThen sign out of all accounts in the Office apps, restart Outlook and sign in again. Microsoft recommends monitoring for 48 hours after the repair.
Stop security software breaking WAM again
If the problem returns after a scan, the likely cause is security software or obsolete Windows Filtering Platform (WFP) drivers blocking or removing the plug-ins. Microsoft's guidance is to test with the security software temporarily removed, then reinstall it with these exclusions configured with the vendor:
Package family names
Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
Folders
%windir%\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
%localappdata%\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
%windir%\SystemApps\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
%localappdata%\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
%localappdata%\Microsoft\TokenBroker
%localappdata%\Microsoft\OneAuth
%localappdata%\Microsoft\IdentityCache
Processes
%windir%\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Microsoft.AAD.BrokerPlugin.exe
%windir%\System32\backgroundTaskHost.exe (for the two packages above)
%windir%\System32\svchost.exe loading the TokenBroker serviceIf the issue still recurs, capture a Process Monitor trace while reproducing it. It shows whether third-party modules load alongside the WAM plug-ins or hold file and registry locks during sign-in.
Don't disable WAM
Community posts often suggest registry values that switch Office sign-in away from WAM. Microsoft does not support disabling ADAL or WAM to fix sign-in or activation problems. It puts the Office client into a legacy, unsupported state, some security features on Windows are available only through WAM, and in the European Economic Area sign-in behaviour required by the Digital Markets Act is enforced within WAM. If such a workaround was deployed in the past, remove it as part of the fix.
Step 5: Fix hybrid and migrated mailboxes
Two scenarios produce prompts even though modern authentication is enabled in Exchange Online:
- Outlook connects to a primary mailbox on Exchange Server on-premises over RPC and also opens a mailbox in Microsoft 365.
- The mailbox was migrated to Microsoft 365 from an Exchange server that Outlook reached over RPC.
In both cases Outlook limits itself to authentication schemes that RPC supports, which do not include modern authentication. The result is a credential prompt and credentials sent instead of a token. The fix is a per-user registry value that forces Outlook to use modern authentication for web services such as EWS and Autodiscover:
$path = 'HKCU:\Software\Microsoft\Exchange'
if (-not (Test-Path $path)) { New-Item -Path $path | Out-Null }
New-ItemProperty -Path $path -Name 'AlwaysUseMSOAuthForAutoDiscover' -PropertyType DWord -Value 1 -ForceExit Outlook before you set it and back up the registry first. Office 2016 and later need no update for this value to work; Office 2013 needs the December 2015 updates for Outlook and Office (or later) installed first. If you are planning a cross-tenant move, the tenant-to-tenant migration architecture guide explains why Outlook profiles have to be rebuilt in that scenario.
On very old Outlook 2013 builds, a Logon network security value other than Anonymous Authentication on the Security tab of the Microsoft Exchange account settings also causes continuous prompts. Outlook 2016 and later have that setting disabled or removed, so it is only worth checking on legacy clients.
Step 6: Fix profiles with more than one account
After modern authentication is enabled, Outlook can fail to connect to a mailbox, showing "Disconnected", when the user's primary Windows account is a Microsoft 365 account that does not match the account used for that mailbox. Windows supplies the default credential instead of the one the mailbox needs. It happens most often when a profile contains several mailboxes signed in with different accounts.
Microsoft fixed the underlying issue in later builds, but already affected profiles need to be recreated. Create a new profile from Control Panel > Mail > Show Profiles > Add, add the primary mailbox first, test it, then add the others.
Step 7: Review session and MFA settings
If many users are prompted at regular intervals, the cause is usually tenant policy rather than the client. The default sign-in frequency in Microsoft Entra ID is a rolling 90-day window, and Office clients normally prompt only after a password reset or 90 days of inactivity. Several settings shorten that:
| Setting | Where | Effect on Outlook |
|---|---|---|
| Remember multifactor authentication below 90 days | Entra ID > Multifactor authentication > Additional cloud-based MFA settings | Shortens MFA lifetime for modern authentication clients such as Office and increases prompts |
| Conditional Access Sign-in frequency | Entra ID > Conditional Access | Prompts when the period elapses, for both first and second factor |
| Sign-in frequency Every time | Conditional Access | Full reauthentication each time the session is evaluated; Microsoft warns it can cause sign-in loops without MFA and recommends time-based frequency for Microsoft 365 apps |
| Configurable token lifetimes | Microsoft Graph policies | Replaced by Conditional Access session controls; don't combine with sign-in frequency for the same users and apps |
To find the setting that fired, open the user's sign-in in the Entra sign-in logs, go to the Authentication Details tab and read Session Lifetime Policies Applied. With Entra ID P1 or P2, Microsoft recommends single sign-on through managed devices and using only the Conditional Access Sign-in frequency and Persistent browser session controls where you need reauthentication. If Remember multifactor authentication is enabled, Microsoft advises disabling it before you use sign-in frequency, because the two together can prompt users unexpectedly. The zero trust remote access architecture article shows where Conditional Access fits in a wider access design.
Verification
- Restart Outlook and open Connection Status again. Every Exchange Online connection should show
Bearerin Authn, and none should showClear. - Run
dsregcmd /statusas the user and confirmAzureAdPrt : YESwith a currentAzureAdPrtUpdateTime. - Check Event Viewer > Windows Logs > Application for new
AppModel-Statewarnings againstMicrosoft.AAD.BrokerPlugin_cw5n1h2txyewy. There should be none. - In the Entra sign-in logs, filter by the user and the Office client app. Interactive sign-ins should drop to the cadence your session policies intend.
- Leave the device in normal use for 48 hours, including at least one antivirus scan, before closing the incident.
Troubleshooting
"The connection to Microsoft Exchange is unavailable. Outlook must be online or connected to complete this action." appears when you cancel a repeated prompt while creating a profile. On legacy Outlook 2013 builds, set Logon network security to Anonymous Authentication. On current builds, work through Steps 3 to 5.
Outlook shows "Need Password" with no prompt at all. Microsoft links this state to missing package information for the WAM plug-in on Windows 10 version 1703 and later with Microsoft 365 version 1807 and later. Re-register Microsoft.AAD.BrokerPlugin as in Step 4.
dsregcmd shows DeviceAuthStatus : FAILED. Device is either disabled or deleted. The device object was removed or disabled in Entra ID. Re-enable it or rejoin the device; no Outlook change will help until the device is healthy.
Server Error Description : AADSTS50126 in the PRT diagnostics. Entra ID rejected the username or password used to acquire the PRT. Confirm the account is not locked or expired and that the user signs in to Windows with their current password, then check the PRT state again.
The prompt is the old grey Windows dialog, not the Microsoft sign-in page. Outlook is attempting Basic or RPC-era authentication. Confirm OAuth2ClientProfileEnabled is True and apply the AlwaysUseMSOAuthForAutoDiscover value for hybrid or migrated mailboxes.
For a guided check on a single machine, Microsoft's Microsoft 365 Sign-in troubleshooter (aka.ms/SaRA-OfficeSignIn-sarahome) runs many of these tests automatically.
Checklist
- Connection Status reviewed; every Exchange Online connection shows
Bearer. OAuth2ClientProfileEnabledconfirmed asTrue.- Device joined,
DeviceAuthStatusisSUCCESSand the user has a PRT. - WAM plug-ins present, launching and re-registered where needed.
- Security software exclusions in place for the WAM packages, folders and processes.
- Any registry workaround that disables ADAL or WAM removed wherever it was deployed.
AlwaysUseMSOAuthForAutoDiscoverset for hybrid and migrated mailboxes.- Multi-account profiles recreated where mailboxes show "Disconnected".
- Remember MFA, sign-in frequency and token lifetime settings reviewed against Microsoft's recommendations.
References
- Outlook continually prompts for password when you try to connect to Microsoft 365
- Outlook prompts for password when Modern Authentication is enabled
- Outlook disconnected after enabling modern authentication
- Description of the Connection Status dialog box
- Enable or disable modern authentication for Outlook in Exchange Online
- Deprecation of Basic authentication in Exchange Online
- Authentication automatically fails in Microsoft 365 services
- Can't sign in to Microsoft 365 desktop applications
- Disabling ADAL or WAM to fix Microsoft 365 sign-in or activation issues not supported
- Connection issues when signing in after updating to Office 2016 build 16.0.7967
- Troubleshoot devices by using the dsregcmd command
- Microsoft Entra multifactor authentication prompts and session lifetime
- Conditional Access adaptive session lifetime policies