Fix it now
Outlook reached the host, spoke POP3, offered a credential and was told no. The network is fine and the server is up, so what is in dispute is the credential, the username format, or whether that server still accepts a plain password at all. In Exchange Online it does not, and no client setting brings it back.
- Sign in to the provider’s webmail with the same credentials. If that also fails, the password is the problem and Outlook is not.
- Put Outlook into offline mode from the Send/Receive tab before you start. Left online it retries on a timer with whatever credential it holds, which on an account with a lockout policy will keep the account locked while you work.
- Clear the stored credential: open Credential Manager, choose Windows Credentials, and remove entries for the mail host and for Office. Restart Outlook and let it prompt.
- Check the username format. Many hosts require the full email address rather than the short name, and some issue an identifier of their own in the hosting control panel.
- If the mailbox is in Microsoft 365, stop repairing the POP account and remove it. Basic authentication is disabled in all Exchange Online tenants; add the mailbox back as a Microsoft 365 or Exchange account instead.
Application passwords are not the way round this in Microsoft 365. Microsoft states that the deprecation of basic authentication also prevents the use of app passwords with apps that do not support two-step verification.
If a send and receive completes without a credential prompt, you are done. If it does not, the next section explains why a password that opens webmail can still be refused here.
Why it happens
None of the four codes in this article has a published meaning. Microsoft documents neither 0x800CCC90 nor its neighbours, and the tidy explanations you will find – this one is the username stage, that one is the password stage – are inference. What is documented is the state of POP3 itself, and that is where the answer usually is.
POP3 authentication is short: the client offers a name, the server accepts or rejects it, the client offers a password, the server accepts or rejects that. There is not much to go wrong inside it, so the interesting question is almost never which half failed. It is whether the door is still open at all.
Webmail is not POP3, which is why “but the password works in the browser” proves less than it seems. Webmail authenticates through the provider’s web sign-in, with multi-factor prompts and tokens. POP3 with a plain password is a separate and much older door into the same mailbox, and providers have spent years closing it. Microsoft removed the ability to use basic authentication in Exchange Online for Exchange ActiveSync, POP, IMAP, Remote PowerShell, EWS, the Offline Address Book, Autodiscover and Outlook for Windows and Mac, and states that basic authentication is now disabled in all tenants.
There is a supported way to keep POP working: Microsoft released OAuth 2.0 support for POP, IMAP and SMTP AUTH in 2020, so a client that implements it can still use the protocol. Outlook against a Microsoft 365 mailbox does not need to, because adding the mailbox as a Microsoft 365 or Exchange account uses modern authentication and never sends a POP password. That is the fix, not a workaround.
The other half of this article is more ordinary. Windows stores mail credentials in Credential Manager and Outlook re-offers them silently, so after a password change a stale entry keeps being submitted and refused. On an account with a lockout policy that quiet retry loop locks the account faster than you can type the new password, which is why the first move is to take Outlook offline rather than to change settings.
A stale password held in Windows Credential Manager
You have this one if Outlook fails instantly without prompting, and the account password was changed recently.
- Put Outlook into offline mode first so it stops retrying while you work.
- Open Credential Manager, choose Windows Credentials, and delete every entry for the mail host and for Office.
- Restart Outlook, enter the current password when prompted, then check phones, tablets and any second computer configured with the same account.
A forgotten device retrying an old password is the single most common reason an account locks out again a few minutes after every unlock.
Basic authentication is no longer accepted for POP on this mailbox
You have this one if The mailbox is in Microsoft 365, other clients using modern authentication work perfectly, and only the POP account is refused.
- Remove the POP account and add the mailbox back as a Microsoft 365 or Exchange account, which uses modern authentication and needs no POP password.
- Where the mailbox genuinely has to stay on POP, the client itself has to support OAuth 2.0 for POP – Microsoft released that support in 2020, and a client that lacks it has no route.
- Confirm no application or device is still submitting a basic password and locking the account.
Do not reach for an application password. Microsoft states that the deprecation of basic authentication also prevents the use of app passwords with apps that do not support two-step verification.
POP3 is switched off for this mailbox
You have this one if Credentials are known good, webmail works, and only this protocol is refused – and it is refused consistently rather than intermittently.
- In Exchange Online, POP3 and IMAP4 support is enabled by default when a mailbox is created, so if it is off somebody turned it off. Ask the administrator to check: Exchange admin centre, Recipients, Mailboxes, the mailbox, General tab, Manage email apps settings.
- For an Outlook.com account the default runs the other way – POP and IMAP access is off until it is turned on in the mailbox’s own settings.
The username is not in the format the server expects
You have this one if The rejection happens immediately and consistently, and the same password works in webmail.
- Try the full email address as the username.
- Try the domain and user form where the server is an on-premises Exchange or another Windows-based host, and check the hosting control panel for the identifier it issues.
- Change one thing at a time so you know which format was the one that worked.
Secure Password Authentication is on and the server does not offer it
You have this one if The credentials are known correct and the account has never worked since it was set up.
- Untick the secure password authentication option in the incoming logon settings, and check the Outgoing Server tab for the same option.
- Confirm the connection is still encrypted; the port and encryption settings are separate from this one.
That option is a specific mechanism, not a general security setting. Ticking it to make things safer usually removes the only method both ends had in common.
Full reference
Reading the situation before you touch anything
| What you see | Where the fault is |
|---|---|
| Webmail refuses the same password | The account password, or the account itself |
| Webmail works, Outlook fails and never prompts | A stale credential in Credential Manager |
| Webmail works, Outlook prompts and the correct password is refused | The protocol or its authentication method, not the credential |
| The account locks out repeatedly | Something is retrying an old password, often a forgotten phone or tablet |
| Only this mailbox is affected | POP is switched off for it, or its authentication route has changed |
What is documented, and what is not
This matters more here than in most articles, because the codes are the reason people go looking in the wrong place. Microsoft publishes no meaning for 0x800CCC90, 0x800CCC91, 0x800CCC92 or 0x800CCC18. It does publish, plainly, that basic authentication is disabled in all Exchange Online tenants for POP among other protocols, and that OAuth 2.0 support exists for POP, IMAP and SMTP AUTH. If the mailbox is in Microsoft 365 and the client is offering a plain password, you already know the answer without decoding anything.
Where the protocol setting lives
| Platform | Default | Where it is changed |
|---|---|---|
| Exchange Online mailbox | POP3 and IMAP4 enabled when the mailbox is created | Exchange admin centre: Recipients, Mailboxes, the mailbox, General, Manage email apps settings |
| Outlook.com account | POP and IMAP access disabled | The account’s own mail settings |
| Other hosts | Varies | The hosting control panel |
Stopping the lockout loop while you work
- Put Outlook into offline mode from the Send/Receive tab before anything else.
- List every device that has this mailbox configured, including ones that have been in a drawer for a year.
- Remove or update the credential on each of them, not just on the machine in front of you.
- Clear Credential Manager on this machine and let Outlook prompt once.
- Go back online and run a single manual send and receive rather than letting the scheduled cycle start.
POP, IMAP or a full account
- POP downloads mail and by default removes it from the server, which suits a single machine that wants everything held locally.
- IMAP leaves the server holding the authoritative copy, which is the right shape if you read mail on more than one device.
- A Microsoft 365 or Exchange account gives you the mailbox properly – calendar, contacts, shared folders – and uses modern authentication, which is why it sidesteps this whole category of failure.
- Neither POP nor IMAP fixes a rejected logon by itself. Changing protocol to escape a credential problem just gives you the same problem on a different port.
- If you are choosing now, choose the full account. The legacy protocols are being narrowed year on year and this will not be the last time they need attention.
When a licence is the actual fix
In most cases nothing needs buying. Clearing a stale credential, correcting a username format, or asking an administrator to turn the protocol back on are all free, and switching a Microsoft 365 mailbox from a POP account to a Microsoft 365 account is a five-minute change with no licensing implication at all. The exception is a mailbox on an old hosting package that offers POP3 with a basic password and nothing else, on a client that cannot do OAuth. Providers are steadily withdrawing that door and no client-side setting reopens it. Moving to Microsoft 365 Business Standard gives you a mailbox and desktop applications in one licence with modern authentication throughout, and Arco can tell you what a migration from your current host involves before you commit to it.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x800CCC90 |
Seen when the POP3 server refuses the logon. No published meaning; treat it as a refusal and work on the credential, the username format and the protocol’s availability | not published by the vendor |
0x800CCC91 |
Seen in the same refusal, commonly associated with the username. No published meaning | not published by the vendor |
0x800CCC92 |
Seen in the same refusal, commonly associated with the password. No published meaning | not published by the vendor |
0x800CCC18 |
Seen where a secure authentication mechanism is in use rather than a plain password. No published meaning | not published by the vendor |
Confirm the fix worked
- A send and receive completes without a credential prompt.
- Credential Manager holds exactly one current entry for the account rather than several old ones.
- The account is not locking out again an hour later, which would mean another device is still retrying.
- Where the provider offers a sign-in activity log, it shows a successful logon at the time you tested.
- Outlook is closed completely, reopened, and does not prompt again on a cold start.
Questions people ask about this
Why does the same password work on my phone?
The phone is almost certainly not using POP3 with a plain password. Mobile apps generally use the provider’s own protocol or modern authentication, which is a different door with different rules. It proves the account is healthy, not that POP is available.
Can I use an app password instead?
Not in Microsoft 365. Microsoft states that the deprecation of basic authentication also prevents the use of app passwords with apps that do not support two-step verification. Other providers still issue them; check that provider’s own documentation rather than assuming.
Is POP3 still supported at all?
The protocol works, but it is gated. It is a per-mailbox setting an administrator can disable, and in Exchange Online it now requires OAuth 2.0 rather than a plain password. Treat a working POP account as something that will need attention eventually.
Should I switch from POP to IMAP?
That is a design decision about where your mail lives, not a fix for a rejected logon. If you read mail on more than one device, IMAP or a full account is the better shape – but neither makes a refused credential accepted.
Do I have to buy a Microsoft 365 licence to fix this?
No, not in most cases. Most of these failures are a stale stored credential, a wrong username format, or a protocol switched off at the mailbox, and all three cost nothing to correct. A licence is only the answer when the mailbox has no supported authentication route left on its current host.
