Gmail/Workspace Oauth for SMTP

  • Zbulo
    Asked on April 23, 2024 at 2:33 AM

    Hi Jotform team, I'm using my Google Workspace account to deliver notifications from Jotform via an app password, this option will be discontinued in September. Is there are way to use OAuth instead? Thanks!

    Starting September 30, 2024, Google Workspace accounts will only allow access to apps using OAuth. Password-based access (with the exception of App Passwords) will no longer be supported. POP and IMAP are NOT going away and can still be enabled with apps that connect using OAuth.

  • Jeric JotForm Support
    Replied on April 23, 2024 at 4:46 AM

    Hi Zbulo,

    Thanks for reaching out to Jotform Support. I understand your concern, but I’ll need a bit of time to work out a solution. I’ll get back to you shortly.

  • Jeric JotForm Support
    Replied on April 23, 2024 at 5:02 AM

    Hi Zbulo,

    Thanks for your patience. Right now, we still don't use Oauth when setting up SMTP. We still ask for the SMTP details to complete the set up. However, I understand that Google will implement changes in the future and we know that it will significantly affect users who use their Google account to set SMTP. Normally, when there are changes that will affect significant number of Jotform users, developers are made aware about such so they can make necessary adjustment before the changes are implemented.

    However, I'd to confirm because it says, with the exception of App Passwords, so I assume they will still keep App Passwords which is what we need when setting up SMTP for Google. Can you clarify this to them?

    Once we hear back from you, we can look into it further.

  • Zbulo
    Replied on April 23, 2024 at 5:36 AM

    Hi Jeric,

    Thanks, I will check on that with Google and return as necessary.

    Else it sounds good that the developers would take care of this.

    Thanks,
    Ricardo

  • Sean_Hardaker
    Replied on April 23, 2024 at 6:09 PM

    Google Workspace logo Screenshot 10

    Starting September 30, 2024, Google Workspace accounts will only allow access to apps using OAuth. Password-based access (with the exception of App Passwords) will no longer be supported. POP and IMAP are NOT going away and can still be enabled with apps that connect using OAuth.

    Dear Administrator,

    We’re writing to remind you that as we previously shared in this blog post and in an email sent in mid-January, we’ll be turning off access to less secure apps (LSA) — non-Google apps that can access Google accounts with only a username and password (basic authentication) — starting June 15, 2024.

    What do you need to know?

    Access through basic authentication makes accounts more vulnerable to hijacking attempts. Moving forward, only apps that support a more modern and secure access method called OAuth will be able to access Google Workspace accounts.

    Access to LSAs will be turned off in two stages:

    1. Beginning June 15, 2024 - The LSA settings will be removed from the Admin console and can no longer be changed. Enabled users can connect after that time, but disabled users will no longer be able to access LSAs. This includes all third-party apps that require password-only access to Gmail, Google Calendar, Contacts via protocols such as CalDAV, CardDAV, IMAP, SMTP, and POP.
    2. The IMAP enable/disable settings will be removed from users’ Gmail settings.
    3. If you’ve been using LSAs prior to this date, you can continue using them until September 30, 2024.
    4. Beginning September 30, 2024 - Access to LSAs will be turned off for all Google Workspace accounts. CalDAV, CardDAV, IMAP, and POP will no longer work when signing in with just a password — you will need to login with a more secure type of access called OAuth.
    What do you need to do?

    In order for your end users to continue using these types of apps with their Google Workspace accounts, they must switch to a more secure type of access called OAuth (a list of affected users is attached). This authentication method allows apps to access accounts with a digital key instead of requiring a user to reveal their username and password. We recommend that you share the user instructions (in this PDF file) with individuals in your organization to help them make the necessary changes. Alternatively, if your organization is using custom tools, you can ask the developer of the tool to update it to use OAuth. Developer instructions are also in this PDF file.

    MDM configuration

    If your organization uses a mobile device management (MDM) provider to configure IMAP, CalDAV CardDAV, or POP profiles, these services will be phased out according to the timeline below:

    1. Beginning June 15, 2024 - MDM push of password based IMAP, CalDAV, CardDAV, and POP will no longer work for customers who try to connect for the first time. If you use Google MDM, you will not be able to turn on "Custom Push Configuration" settings for CalDAV and CardDAV.
    2. Beginning September 30, 2024 - MDM push of password based IMAP, CalDAV, CardDAV, and POP will no longer work for existing users. Admins will need to push a Google Account using their MDM provider, which will re-add their Google accounts to iOS devices using OAuth. If you use Google MDM, “Custom push configuration-CalDAV” and “Custom push configuration-CardDAV” (more details about the settings here) will stop being effective.

    Other less secure apps

    • For any other LSA, ask the developer of the app you are using to start supporting OAuth.

    Scanners and other devices

    For scanners or other devices using simple mail transfer protocol (SMTP) or LSAs to send emails, configure to use OAuth, use an alternative method, or configure an App Password for use with the device. If you replace your device, look for one that sends email using OAuth.

    We’re here to help

    If you have additional questions or need assistance, please contact Google Workspace support. When you call or submit your support case, reference issue number 319688531.

    Thanks for choosing Google Workspace.

    —The Google Workspace Team

 
Your Answer