Microsoft 365

Stop Outlook asking for your password again and again in Microsoft 365

Find out why Outlook for Windows keeps prompting for credentials with Microsoft 365, then fix WAM, profile, hybrid and session policy causes.

14 min read
On this page

Outlook keeps asking for a password with Microsoft 365 when it cannot get or keep an OAuth token for the mailbox. On current Windows and Microsoft 365 Apps builds that almost always traces back to one of four things: broken or blocked Web Account Manager (WAM) plug-ins, an Outlook profile that still negotiates the old RPC-era authentication after a migration, a profile that mixes accounts, or tenant session settings that force reauthentication. Diagnose which one applies, fix it at the source, and do not disable WAM.

Who this is for and what you will have at the end

This guide is for Microsoft 365 administrators and desktop support engineers dealing with classic Outlook for Windows that shows "Need Password", "Trying to connect..." or a sign-in window that returns every few minutes or after every restart. By the end you will have:

  • A way to tell which authentication method Outlook is actually using.
  • Confirmation that modern authentication is on for the tenant and that the device holds a valid Primary Refresh Token (PRT).
  • Re-registered WAM plug-ins and a list of security software exclusions to stop them breaking again.
  • The registry fix for hybrid and migrated mailboxes.
  • A reviewed set of Microsoft Entra session settings that don't prompt users more than they need to.

How Outlook signs in today

Starting in build 16.0.7967, Microsoft 365 Apps use Web Account Manager for sign-in on Windows 10 version 1703 and later. WAM is a Windows component: the Microsoft Entra WAM plug-in (package Microsoft.AAD.BrokerPlugin) handles work and school accounts, and the Microsoft.Windows.CloudExperienceHost package handles personal Microsoft accounts. Both plug-ins are installed per user profile, so one user on a device can be affected while another is not.

On Microsoft Entra joined and hybrid joined devices, the user also has a Primary Refresh Token that WAM uses for single sign-on. When the plug-ins or the PRT are healthy, Outlook gets tokens silently. When they are not, Outlook shows a credential prompt, and if the token still cannot be issued, the prompt comes back.

Exchange Online no longer accepts Basic authentication for Outlook for Windows, Outlook for Mac, EWS, Autodiscover or the Offline Address Book, and nobody can re-enable it. A prompt that looks like the old grey Windows security dialog rather than the Microsoft sign-in page is therefore a strong sign that Outlook is trying an authentication method the service will reject.

SymptomMost likely causeSection
Prompts on one user profile only, blank or frozen sign-in windowWAM plug-ins missing or damagedStep 3 and Step 4
Prompts return after every antivirus scanSecurity software blocking or removing WAMStep 4
Old-style credential dialog after a migration from Exchange on-premisesOutlook limited to RPC authentication schemesStep 5
Mailbox shows "Disconnected" with several accounts in one profileWindows supplies the default account instead of the mailbox accountStep 6
Prompts at regular intervals for many usersSession lifetime or MFA settingsStep 7

Prerequisites

  • Classic Outlook for Windows from Microsoft 365 Apps or a supported perpetual version. Outlook 2007 and Outlook 2010 cannot use modern authentication, so with Basic authentication gone they can't keep a working Exchange Online connection.
  • Access to the affected user's Windows session. WAM repairs must run in the user's context, not as a different administrator.
  • Exchange Online PowerShell for the tenant check. If Connect-ExchangeOnline itself fails, see Connect-ExchangeOnline errors and fixes.
  • Microsoft Entra admin center access to read sign-in logs, plus the Conditional Access Administrator role to review sign-in frequency policies and the Authentication Policy Administrator role to review the Remember multifactor authentication setting.

Step 1: Confirm what Outlook is actually using

Before changing anything, look at the connection. Press and hold Ctrl, select the Outlook icon in the notification area, and then select Connection Status. The Authn column shows the authentication type for each connection. Values Microsoft documents include Clear (Basic authentication), NTLM, Nego, Kerberos, Anonymous and Bearer. Bearer indicates token-based authentication, which is what modern authentication uses, so that is what a healthy Exchange Online connection should show. If you see Clear against an Exchange Online mailbox, Outlook is not using modern authentication for that connection and will keep prompting.

Note also the SMTP Address column. If only one of several mailboxes in the profile shows the problem, jump to Step 6.

Step 2: Check the tenant setting for modern authentication

Modern authentication has been on by default in Exchange Online since August 2017, but older tenants may have turned it off. Check it once, then rule it out:

Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
Get-OrganizationConfig | Format-Table Name,OAuth* -Auto

OAuth2ClientProfileEnabled should be True. If it is False, turn it on:

Set-OrganizationConfig -OAuth2ClientProfileEnabled $true

The same switch is in the Microsoft 365 admin center under Settings > Org Settings > Modern Authentication, labelled Turn on modern authentication for Outlook 2013 for Windows and later (recommended). The setting only affects Outlook for Windows. When you enable it, Outlook clients that support modern authentication are prompted to sign in once more, which is expected.

Step 3: Check the device and the user's token state

Run dsregcmd /status from a normal, non-elevated command prompt signed in as the affected user. The SSO and user state fields need the user context to report correctly.

dsregcmd /status

Look at these fields:

FieldWhat you wantWhat it means if not
AzureAdJoined or DomainJoined with AzureAdJoinedYES for Entra joined or hybrid joinedDevice can't get a PRT; Outlook relies on per-app tokens
DeviceAuthStatusSUCCESSFAILED. Device is either disabled or deleted means the device object needs fixing in Entra ID
WamDefaultSetYESNo default WAM account for this user
AzureAdPrtYESNo PRT for the signed-in user
AzureAdPrtUpdateTimeRecentPRT is not being renewed

When PRT acquisition or refresh fails, dsregcmd adds diagnostic fields such as Attempt Status, Server Error Code and Server Error Description (for example an AADSTS error). Those errors point to identity problems outside Outlook, such as a changed password or a disabled device, and must be fixed first.

On devices that are not joined to Entra ID, each app holds its own refresh token, so users can see several prompts, one per app. That is by design rather than a fault; joining or registering the device is the long-term fix.

Step 4: Repair the WAM plug-ins

Microsoft documents the following symptoms of broken or tampered WAM plug-ins: intermittent prompts, a blank or stuck sign-in window, Outlook showing "Trying to connect...", and in Event Viewer > Windows Logs > Application, AppModel-State events such as:

Triggered repair of state locations because operation SettingsInitialize against package Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy hit error
Repair for operation LocalSettings against package Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy with error
Failure to load the application settings for package

Signed in as the affected user, check that both packages exist:

Get-AppxPackage Microsoft.AAD.BrokerPlugin
Get-AppxPackage Microsoft.Windows.CloudExperienceHost

If both return a package, test that they launch. Each command should open a Work or school account or Microsoft account window:

explorer.exe shell:appsFolder\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy!App
explorer.exe shell:appsFolder\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy!App

If either package is missing or its window does not open, re-register it:

Add-AppxPackage -Register "$env:windir\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Appxmanifest.xml" -DisableDevelopmentMode -ForceApplicationShutdown
Add-AppxPackage -Register "$env:windir\SystemApps\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Appxmanifest.xml" -DisableDevelopmentMode -ForceApplicationShutdown

Microsoft also publishes a conditional form that only re-registers the work account plug-in when it is missing. Where security software keeps removing the plug-ins, Microsoft suggests running a re-installation from a background PowerShell script or Group Policy logon script as a temporary mitigation until the exclusions below are in place:

if (-not (Get-AppxPackage Microsoft.AAD.BrokerPlugin)) { Add-AppxPackage -Register "$env:windir\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Appxmanifest.xml" -DisableDevelopmentMode -ForceApplicationShutdown } Get-AppxPackage Microsoft.AAD.BrokerPlugin

Then sign out of all accounts in the Office apps, restart Outlook and sign in again. Microsoft recommends monitoring for 48 hours after the repair.

Stop security software breaking WAM again

If the problem returns after a scan, the likely cause is security software or obsolete Windows Filtering Platform (WFP) drivers blocking or removing the plug-ins. Microsoft's guidance is to test with the security software temporarily removed, then reinstall it with these exclusions configured with the vendor:

Package family names
  Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
  Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
 
Folders
  %windir%\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
  %localappdata%\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
  %windir%\SystemApps\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
  %localappdata%\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
  %localappdata%\Microsoft\TokenBroker
  %localappdata%\Microsoft\OneAuth
  %localappdata%\Microsoft\IdentityCache
 
Processes
  %windir%\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Microsoft.AAD.BrokerPlugin.exe
  %windir%\System32\backgroundTaskHost.exe (for the two packages above)
  %windir%\System32\svchost.exe loading the TokenBroker service

If the issue still recurs, capture a Process Monitor trace while reproducing it. It shows whether third-party modules load alongside the WAM plug-ins or hold file and registry locks during sign-in.

Don't disable WAM

Community posts often suggest registry values that switch Office sign-in away from WAM. Microsoft does not support disabling ADAL or WAM to fix sign-in or activation problems. It puts the Office client into a legacy, unsupported state, some security features on Windows are available only through WAM, and in the European Economic Area sign-in behaviour required by the Digital Markets Act is enforced within WAM. If such a workaround was deployed in the past, remove it as part of the fix.

Step 5: Fix hybrid and migrated mailboxes

Two scenarios produce prompts even though modern authentication is enabled in Exchange Online:

  • Outlook connects to a primary mailbox on Exchange Server on-premises over RPC and also opens a mailbox in Microsoft 365.
  • The mailbox was migrated to Microsoft 365 from an Exchange server that Outlook reached over RPC.

In both cases Outlook limits itself to authentication schemes that RPC supports, which do not include modern authentication. The result is a credential prompt and credentials sent instead of a token. The fix is a per-user registry value that forces Outlook to use modern authentication for web services such as EWS and Autodiscover:

$path = 'HKCU:\Software\Microsoft\Exchange'
if (-not (Test-Path $path)) { New-Item -Path $path | Out-Null }
New-ItemProperty -Path $path -Name 'AlwaysUseMSOAuthForAutoDiscover' -PropertyType DWord -Value 1 -Force

Exit Outlook before you set it and back up the registry first. Office 2016 and later need no update for this value to work; Office 2013 needs the December 2015 updates for Outlook and Office (or later) installed first. If you are planning a cross-tenant move, the tenant-to-tenant migration architecture guide explains why Outlook profiles have to be rebuilt in that scenario.

On very old Outlook 2013 builds, a Logon network security value other than Anonymous Authentication on the Security tab of the Microsoft Exchange account settings also causes continuous prompts. Outlook 2016 and later have that setting disabled or removed, so it is only worth checking on legacy clients.

Step 6: Fix profiles with more than one account

After modern authentication is enabled, Outlook can fail to connect to a mailbox, showing "Disconnected", when the user's primary Windows account is a Microsoft 365 account that does not match the account used for that mailbox. Windows supplies the default credential instead of the one the mailbox needs. It happens most often when a profile contains several mailboxes signed in with different accounts.

Microsoft fixed the underlying issue in later builds, but already affected profiles need to be recreated. Create a new profile from Control Panel > Mail > Show Profiles > Add, add the primary mailbox first, test it, then add the others.

Step 7: Review session and MFA settings

If many users are prompted at regular intervals, the cause is usually tenant policy rather than the client. The default sign-in frequency in Microsoft Entra ID is a rolling 90-day window, and Office clients normally prompt only after a password reset or 90 days of inactivity. Several settings shorten that:

SettingWhereEffect on Outlook
Remember multifactor authentication below 90 daysEntra ID > Multifactor authentication > Additional cloud-based MFA settingsShortens MFA lifetime for modern authentication clients such as Office and increases prompts
Conditional Access Sign-in frequencyEntra ID > Conditional AccessPrompts when the period elapses, for both first and second factor
Sign-in frequency Every timeConditional AccessFull reauthentication each time the session is evaluated; Microsoft warns it can cause sign-in loops without MFA and recommends time-based frequency for Microsoft 365 apps
Configurable token lifetimesMicrosoft Graph policiesReplaced by Conditional Access session controls; don't combine with sign-in frequency for the same users and apps

To find the setting that fired, open the user's sign-in in the Entra sign-in logs, go to the Authentication Details tab and read Session Lifetime Policies Applied. With Entra ID P1 or P2, Microsoft recommends single sign-on through managed devices and using only the Conditional Access Sign-in frequency and Persistent browser session controls where you need reauthentication. If Remember multifactor authentication is enabled, Microsoft advises disabling it before you use sign-in frequency, because the two together can prompt users unexpectedly. The zero trust remote access architecture article shows where Conditional Access fits in a wider access design.

Verification

  1. Restart Outlook and open Connection Status again. Every Exchange Online connection should show Bearer in Authn, and none should show Clear.
  2. Run dsregcmd /status as the user and confirm AzureAdPrt : YES with a current AzureAdPrtUpdateTime.
  3. Check Event Viewer > Windows Logs > Application for new AppModel-State warnings against Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy. There should be none.
  4. In the Entra sign-in logs, filter by the user and the Office client app. Interactive sign-ins should drop to the cadence your session policies intend.
  5. Leave the device in normal use for 48 hours, including at least one antivirus scan, before closing the incident.

Troubleshooting

"The connection to Microsoft Exchange is unavailable. Outlook must be online or connected to complete this action." appears when you cancel a repeated prompt while creating a profile. On legacy Outlook 2013 builds, set Logon network security to Anonymous Authentication. On current builds, work through Steps 3 to 5.

Outlook shows "Need Password" with no prompt at all. Microsoft links this state to missing package information for the WAM plug-in on Windows 10 version 1703 and later with Microsoft 365 version 1807 and later. Re-register Microsoft.AAD.BrokerPlugin as in Step 4.

dsregcmd shows DeviceAuthStatus : FAILED. Device is either disabled or deleted. The device object was removed or disabled in Entra ID. Re-enable it or rejoin the device; no Outlook change will help until the device is healthy.

Server Error Description : AADSTS50126 in the PRT diagnostics. Entra ID rejected the username or password used to acquire the PRT. Confirm the account is not locked or expired and that the user signs in to Windows with their current password, then check the PRT state again.

The prompt is the old grey Windows dialog, not the Microsoft sign-in page. Outlook is attempting Basic or RPC-era authentication. Confirm OAuth2ClientProfileEnabled is True and apply the AlwaysUseMSOAuthForAutoDiscover value for hybrid or migrated mailboxes.

For a guided check on a single machine, Microsoft's Microsoft 365 Sign-in troubleshooter (aka.ms/SaRA-OfficeSignIn-sarahome) runs many of these tests automatically.

Checklist

  • Connection Status reviewed; every Exchange Online connection shows Bearer.
  • OAuth2ClientProfileEnabled confirmed as True.
  • Device joined, DeviceAuthStatus is SUCCESS and the user has a PRT.
  • WAM plug-ins present, launching and re-registered where needed.
  • Security software exclusions in place for the WAM packages, folders and processes.
  • Any registry workaround that disables ADAL or WAM removed wherever it was deployed.
  • AlwaysUseMSOAuthForAutoDiscover set for hybrid and migrated mailboxes.
  • Multi-account profiles recreated where mailboxes show "Disconnected".
  • Remember MFA, sign-in frequency and token lifetime settings reviewed against Microsoft's recommendations.

References

Questions people ask

Why does Outlook keep asking for my password with Microsoft 365?

Outlook for Windows signs in through Windows Web Account Manager (WAM) and caches tokens. If the WAM plug-ins are missing or blocked by security software, Outlook falls back to asking for credentials. Other common causes are a profile that still uses RPC-era authentication after a migration, mixed accounts in one profile, and tenant session settings that force reauthentication too often.

Should I disable WAM in the registry to stop the prompts?

No. Microsoft does not support disabling ADAL or WAM as a fix for sign-in problems. It puts the Office client into a legacy, unsupported state. Repair or re-register the WAM plug-ins and fix the underlying cause instead.

How do I check whether Outlook is using modern authentication?

Hold Ctrl, select the Outlook icon in the notification area and choose Connection Status. The Authn column shows the authentication type for each connection; Bearer indicates token-based (OAuth) authentication, while Clear indicates Basic authentication, which Exchange Online no longer accepts.

Can Conditional Access cause repeated Outlook sign-in prompts?

Yes. A short sign-in frequency, a sign-in frequency of Every time, or Remember multifactor authentication set below 90 days all shorten how long Office clients can use their tokens. Review the Session Lifetime Policies Applied field in the Entra sign-in logs to see which setting triggered the prompt.

OutlookModern authenticationEntra IDWAMExchange Online
  1. Control the new Outlook for Windows rollout with policies and toggles

    The admin controls for new Outlook for Windows: hide the toggle, stop automatic migration, block the app or mailbox access, and migrate on your own schedule before the March 2027 opt-out.

    Microsoft 36513 min read
  2. Fix Microsoft 365 email going to Junk by reading SFV, CAT and compauth

    Work out why Exchange Online delivered a message to Junk Email from its anti-spam headers, then apply the fix that matches the component that filtered it.

    Microsoft 36513 min read
  3. Full Access, Send As and Send on Behalf in Exchange Online with PowerShell

    Grant, remove and audit the three mailbox delegation permissions in Exchange Online with PowerShell, control Outlook automapping, and fix the errors delegates hit most often.

    Microsoft 3659 min read