The academic webmail Versailles is based on a Zimbra infrastructure currently migrating to Microsoft 365. This transition, initiated since 2025-2026, fundamentally changes the authentication method and connection protocols. Understanding these technical changes before even logging in avoids most of the reported issues since the start of the school year.
Microsoft 365 Migration and OAuth2 Authentication on Versailles Mail
The academy of Versailles is gradually migrating its email accounts from Zimbra to Microsoft 365 with OAuth2 authentication. This protocol change has a direct consequence: email clients configured with standard IMAP using a simple password lose access as soon as the account switches to the new infrastructure.
We recommend checking if your account has already migrated before attempting to configure it on a third-party client. A migrated account requires OAuth2, which excludes the old IMAP/SMTP settings using just a username and password. Thunderbird, Apple Mail, and Outlook support OAuth2, but automatic configuration does not always work: sometimes you need to manually force the authentication mode in the account’s advanced settings.
For agents who simply want to access the academic webmail Versailles without configuring a heavy client, using the browser remains the most reliable method during this transition phase.

End of Redirects to Personal Mailboxes: What Changes Since July 2025
The academy of Versailles has disabled automatic redirects to personal mailboxes on July 17, 2025. Gmail, Outlook.com, Yahoo, or any other external provider no longer receives emails sent to your @ac-versailles.fr address.
This measure, motivated by the protection of professional data, is part of a national trend. Several academies (Grenoble, Amiens, Nancy-Metz) have implemented the same block since the summer of 2025. No error message is sent back to the sender: emails arrive in the academic mailbox and remain there.
If you were relying on a redirect, you have probably missed emails since that date. The only solution is to check the webmail directly via messagerie.ac-versailles.fr or through the Arena portal.
Check for Residual Redirects
Log in to the webmail, then go to the email preferences. In the “Mail” or “Courrier” tab, look for the “Forwarding” section. If an external address is still listed there, it is inactive on the server side but may generate error entries in the logs. Remove it to keep a clean configuration.
Logging into webmail ac-versailles.fr: Technical Settings and Blocking Points
The direct access URL is messagerie.ac-versailles.fr. The SSL/TLS protocol is mandatory. The username follows the initial format of first name + full last name (example: jdupont). In case of name duplication, a number is added (jdupont1). The associated email address is [email protected].
We observe that the majority of login failures stem from three specific situations:
- The user enters their full email address instead of the short username. The “Username” field expects only the username (jdupont), not the @ac-versailles.fr address.
- The initial password has never been changed and has expired. The security policy requires periodic renewal. An expired password does not always trigger an explicit message on the Zimbra interface.
- The browser injects an old password stored in the autocomplete manager. Clear the cache of saved passwords for the domain ac-versailles.fr before trying again.
Reset via MACA-DAM
The MACA-DAM self-service interface allows you to reset a password without contacting support. You will need your username, your date of birth, the answer to your security question, and a verification code. If you have never set up a security question, MACA-DAM will not be able to authenticate you and you will need to go through the CARIINA support platform.

IMAP and SMTP Configuration for Accounts Not Migrated to Microsoft 365
Accounts still hosted on Zimbra accept standard IMAP/SMTP configuration. Here are the settings to enter in your email client:
- Incoming IMAP server: messagerie.ac-versailles.fr, port 993, SSL/TLS encryption
- Outgoing SMTP server: messagerie.ac-versailles.fr, port 465 (SSL) or 587 (STARTTLS)
- Authentication: normal password (not OAuth2 as long as the account remains on Zimbra)
- Username: your short username (jdupont), not the full address
As soon as your account switches to Microsoft 365, these settings will stop working. The client will then display an authentication error without specifying that the protocol has changed. Switch to OAuth2 in the account settings to restore the connection.
Access via the Arena Portal
Arena serves as the unified entry point for applications of the National Education. After authentication on the portal, a direct link to the mail avoids re-entering your credentials. This method has a concrete advantage: Arena authentication natively manages migrated accounts like Zimbra accounts, without the user needing to know the migration status of their account.
The transition to Microsoft 365 and the end of external redirects redefine the habits of accessing academic mail. Properly configuring your access now, whether through direct webmail or an IMAP client in OAuth2, avoids unpleasant surprises at the start of the 2026 school year. Remember to set up your security question in MACA-DAM while your access is functioning: it is the only safety net in case of a forgotten password.



