Enable security passwords for third-party clients

更新时间:
复制 MD 格式

Learn how a domain administrator can enable security passwords for third-party clients.

Note

By default, email services are open and accessible through standard protocols. This allows users to access their email accounts from any third-party client, such as Outlook or Foxmail. However, a drawback is that these protocols only support basic account and password authentication.

If your organization lets employees use third-party clients and you need to ensure account security, enable the security password feature.

Security password for third-party clients

A security password is an independent password used for signing in to your Alibaba Mail account from a third-party client.

Procedure

Sign in to the Alibaba Mail console as the postmaster domain administrator.

Important

To enhance account security, new Alibaba Mail subscriptions include a default, enabled blacklist policy named "Third-party Client Access Policy." This policy blocks logins from all third-party clients. If an account needs to use a third-party client, navigate to the mail admin console > security management > account security > access policy. Click Edit to add the account as an exception or disable the policy entirely. The change takes effect within five minutes.

image

Go to Security Settings > Account Security > Password Policy. Turn on the switch, configure the scope of the policy, and save the settings.

image

Note

You must either add members who need a security password to the policy's exclusion list, or disable the policy for all members.

When enforce security password is enabled, employees must generate a security password from the web-based mail client before they can use it to sign in to a third-party client. For more information, see How employees can enable and use a security password for a third-party client.

FAQ

Q: Can an administrator (postmaster) view or generate security passwords for sub-accounts?

No. The postmaster account cannot view, generate, or reset security passwords for sub-accounts. The domain admin console only supports deleting existing security passwords or configuring global policies.

Employees must sign in to their own sub-accounts on the Alibaba Mail web client and generate security passwords themselves. Go to Settings > More Settings > Account & Security > Account Security. For more information, see How employees can enable and use a security password for a third-party client.

If an employee cannot sign in to their account, the administrator can reset the employee's web-based login password in the domain admin console. The employee can then sign in and generate a security password.

Q: What should I keep in mind when generating a security password for a third-party client?

  1. You must enter a Device Name (a custom identifier such as "Phone" or "Outlook") and click OK to activate the password. If you copy the password without clicking OK to confirm, the password will not take effect and sign-in will fail.

  2. The security password is a 16-character random string that is displayed only once at the time of generation. Copy and save it immediately, as it cannot be retrieved later.

  3. The same security password can be used on multiple devices, but generating a separate password for each device is recommended for easier management.

  4. If you suspect the password has been leaked or was generated by someone else, delete it immediately and generate a new one.

Q: After enabling the security password feature, what should I do if a third-party client (such as Outlook, WeCom, or Foxmail) fails to sign in?

  1. Core cause: After you enable the feature, employees must use the security password — not the web-based login password — to sign in to third-party clients. Using the original password results in errors such as 80002-5ac2fe or C4 NO LOGIN failed.

  2. Checklist:

    • Confirm that the security password generation process was completed on the web client, including entering a device name and clicking OK.

    • Verify that the server address and port settings are correct: IMAP — imap.qiye.aliyun.com, port 993, SSL; SMTP — smtp.qiye.aliyun.com, port 465, SSL.

    • Check that the domain suffix in the email address is correct.

  3. Alternative: If enhanced security is not required, you can disable Enforce Security Password or the account-level security password feature, allowing employees to sign in with the web-based password.

  4. International access: Ensure that the network connection is stable and that the encryption protocol settings are correctly configured, so that connection issues are not mistaken for password errors.

Q: What should I do if abnormal sign-in activity or security risks occur after enabling the security password feature?

  1. Possible causes: The security password may have been leaked, stored in plaintext, or stolen by malware.

  2. Immediate actions:

    • Delete the existing security password on all devices and generate a new one.

    • Run a virus scan on affected devices.

    • Avoid storing passwords in plaintext.

  3. Log review: In the domain admin console, use Log Query to identify suspicious IP addresses. Go to Security Settings > IP Login Restriction to configure a whitelist and block unauthorized access.

  4. Long-term security: Even with the security password feature enabled, change passwords regularly, review unknown device authorizations, and enable two-factor authentication to further strengthen account security.