迁移至Office 365后Exchangelib凭证错误及请求退避问题
Office 365迁移后exchangelib认证失败及退避警告问题
背景
迁移前代码运行正常,此前登录链接为https://webmail.domain.it/owa/shared_mailbox@domain.it,现已迁移至Office 365云端,登录链接变为https://outlook.office365.com/mail。
代码实现
class MyProxyAdapter(requests.adapters.HTTPAdapter): def send(self, request, stream=False, timeout=None, verify=True, cert=None, proxies=None): proxies = { 'http': 'proxy', 'https': 'proxy', } return super().send(request, stream=stream, timeout=timeout, verify=verify, cert=cert, proxies=proxies) def getAccount(): try: user= "UT-*****-DEV" psw = "Password" BaseProtocol.HTTP_ADAPTER_CLS = MyProxyAdapter config = Configuration(server='outlook.office365.com', retry_policy=FaultTolerance(max_wait=900), credentials=Credentials(user, psw) ) return Account( 'shared_mailbox@domain.it', config=config, autodiscover=True, access_type=DELEGATE ) except Exception as e: print(f"Get data error: {e}...") return None
问题现象
迁移后代码抛出"wrong credentials"错误;关闭autodiscover功能后,执行account.protocol.version触发退避警告:WARNING:exchangelib.util:Server requested back off until 2025-07-31 08:42:34.617995. Sleeping 9.998383 seconds。
已尝试方案
- 使用
UT-XXX-DEV@domain.it替代UT-XXX-DEV登录,无效; - 通过os.environ强制设置代理,或使用NoVerifyHTTPAdapter作为协议,均无效果。
解决建议
- 切换OAuth2认证方式
Office 365大多已禁用基础用户名密码认证,需改用OAuth2:
- 在Azure AD注册应用,获取client_id、client_secret、tenant_id;
- 用
OAuth2Credentials替换Credentials,配置对应参数; - 确保服务账号
UT-*****-DEV拥有共享邮箱的委派权限,同时在Azure AD中给应用授予Mail.Read等Exchange相关权限。
- 修正代理配置逻辑
当前代理适配器强制覆盖传入的proxies参数,易引发冲突,改为仅在无代理配置时设置:
class MyProxyAdapter(requests.adapters.HTTPAdapter): def send(self, request, stream=False, timeout=None, verify=True, cert=None, proxies=None): if not proxies: proxies = { 'http': 'proxy', 'https': 'proxy', } return super().send(request, stream=stream, timeout=timeout, verify=verify, cert=cert, proxies=proxies)
同时确认代理服务器能正常访问outlook.office365.com,无防火墙或端口限制。
- 调整服务器与Autodiscover配置
- 开启Autodiscover时,检查服务账号的DNS解析是否能正常获取Office 365的Autodiscover记录;
- 关闭Autodiscover时,需指定正确的Exchange版本,避免版本不匹配触发退避:
from exchangelib import Version, EXCHANGE_O365 config = Configuration( server='outlook.office365.com', version=Version(EXCHANGE_O365), retry_policy=FaultTolerance(max_wait=900), credentials=Credentials(user, psw) )
- 验证账号权限与状态
- 确认
UT-*****-DEV账号未锁定、密码未过期,直接登录https://outlook.office365.com/mail验证可用性; - 在Office 365 admin中心检查共享邮箱
shared_mailbox@domain.it的配置,确保UT-*****-DEV拥有该邮箱的完全访问或委派权限。
- 优化退避处理逻辑
退避警告多因请求频率过高或服务器拒绝导致,需:
- 避免短时间内频繁调用Exchange接口;
- 调整
FaultTolerance的参数,比如增大max_wait或优化重试间隔,减少触发退避的概率。
内容的提问来源于stack exchange,提问作者zacthebigkub
相关产品推荐
相关产品推荐

