Exchange OnlineTroubleshooting

EWS switch-off in Exchange Online: EwsEnabled, the app allow list and finding EWS usage

Exchange Web Services is being disabled in Exchange Online from October 2026. What changes, how EwsEnabled and EwsAllowedAppIDs work, how to find what still uses EWS and how to buy time safely.

Exchange Web Services (EWS) has been the back door into mailboxes for almost two decades, and Microsoft is now closing it in Exchange Online. From October 2026 tenants are being switched over in phases, and in April 2027 the door locks for good. This post explains the mechanism Microsoft is using, what quietly depends on EWS in a typical tenant, how to find it, and how to keep approved applications working for the few months you have left to migrate them.

How this guide is organised: What is changing → Who is affected → What breaks if you do nothing → What to do now → How to verify → TimelineFlow diagram of the article's sections in reading order: 1. What is changing. 2. Who is affected. 3. What breaks if you do nothing. 4. What to do now. 5. How to verify. 6. Timeline (milestone). Toolbox: Set-CASMailbox, Get-OrganizationConfig, Set-OrganizationConfig, Exchange › EWS usage, EwsEnabled.1What is changing2Who is affected3What breaks if you do nothing4What to do now5How to verify6TimelineTOOLBOXSet-CASMailboxGet-OrganizationConfigSet-OrganizationConfigExchange › EWS usageEwsEnabledHow this guide is organised: What is changing → Who is affected → What breaks if you do nothing → What to do now → How to verify → TimelineFlow diagram of the article's sections in reading order: 1. What is changing. 2. Who is affected. 3. What breaks if you do nothing. 4. What to do now. 5. How to verify. 6. Timeline (milestone). Toolbox: Set-CASMailbox, Get-OrganizationConfig, Set-OrganizationConfig, Exchange › EWS usage, EwsEnabled.1What is changing2Who is affected3What breaks if you do nothing4What to do now5How to verify6TimelineTOOLBOXSet-CASMailboxGet-OrganizationConfigSet-OrganizationConfigExchange › EWS usageEwsEnabled
At a glance: how this guide is organised · 6 sections, from what is changing to the timeline

Status (October 2026): Microsoft announced the retirement timeline in message center post MC1227454 (February 2026) and started enforcement on 1 October 2026 (Exchange Team blog, 1 October 2026; MC1485116). From 10 October 2026, Worldwide tenants with EwsEnabled set to True must also have an EwsAllowedAppIDs allow list, or EWS calls are blocked. Tenants that never set EwsEnabled will be disabled in waves with a seven-day Message center warning. Full, permanent retirement is 1 April 2027. Exchange Server on-premises is not affected. Re-check the Learn page and Message center, because dates for other clouds and the parity roadmap are still being updated.

What is changing#

EWS is a SOAP API that lets applications read and write mail, calendar, contacts and folders on behalf of users or as an app. It stopped receiving new features in 2018, the 2023 announcement set the disablement for October 2026, and the Midnight Blizzard incident in January 2024 made Microsoft widen the effort to its own products as well as third-party apps. Microsoft Graph is the replacement, and Microsoft publishes an EWS-to-Graph operation mapping plus an analyzer tool to help with code changes.

The retirement is controlled by two organization settings:

SettingMeaning
EwsEnabled = $nullNever configured. EWS works today, and the allow list is ignored. These tenants are the ones Microsoft disables in waves.
EwsEnabled = $true + EwsAllowedAppIDsOnly the listed Entra application (client) IDs can use EWS. Microsoft will not change EwsEnabled on these tenants before April 2027.
EwsEnabled = $true, no listAllowed everything before October; from 10 October 2026 EWS is blocked for all apps.
EwsEnabled = $falseEWS is off for the whole tenant (including per-mailbox overrides).

EwsAllowedAppIDs is a replacement list, not an append: every time you set it you must include every ID you still need. Changes to the list take up to 24 hours to apply; changes to EwsEnabled take about an hour.

Who is affected#

Any Exchange Online tenant with an application that still calls EWS. That includes custom code built on the EWS Managed API, vendor products, and some Microsoft clients. Microsoft's own list of things that may still generate EWS traffic includes Outlook for Windows (be on the August 2026 build 16.0.20430.20092 or later), classic Outlook for Mac (new Outlook for Mac is unaffected, but classic needs the "Microsoft Office" app ID on your list), Excel Power Query, Power BI and Exchange hybrid. On-premises Exchange keeps EWS, but hybrid rich coexistence (free/busy, MailTips, photos) talks EWS to Exchange Online unless you have moved Exchange SE to the Graph-based flow. Cross-tenant organization relationships are not subject to the allow-list requirement.

What breaks if you do nothing#

If your tenant is still at $null, Microsoft will populate an allow list from the previous 60 days of usage shortly before it sets EwsEnabled to False. Anything that ran infrequently in that window will be missing, and anything you forgot about will stop with authentication or 401-style errors that look like an outage. Expect it in places you don't think of as "EWS": older backup, archiving and journaling connectors, migration tools, CRM and ticketing integrations, signature managers, meeting-room and digital-signage panels, scripts that process shared mailboxes, and Outlook add-ins that call EWS from the client. You can set EwsEnabled back to True until April 2027, but you will still need a correct allow list.

Plan migrations against the published parity roadmap. Several gaps (archive, public folder and group import/export, in-place archive access, an Exchange Admin API, user configuration objects) have targets through Q4 CY2026, and Microsoft has confirmed that generic public folder CRUD, generic Microsoft 365 Group mailbox CRUD and discovery mailbox access will not come to Graph at all.

What to do now#

  1. Find your EWS usage. In the Microsoft 365 admin center go to Reports › Usage › Exchange › EWS usage. It lists each Application ID, the SOAP actions it called, call volume and last activity for 7, 30 or 90 days, and exports to CSV. Data is aggregated weekly and can lag up to 10 days. Resolve unknown IDs under Enterprise applications in the Microsoft Entra admin center, or against Microsoft's published list of first-party app IDs. Entra sign-in logs (user and service principal sign-ins filtered to the Exchange Online resource) help you see who is behind an app.
  2. Check your current state.
    PowerShell
    Connect-ExchangeOnline
    Get-OrganizationConfig | Format-List EwsEnabled
    Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs
    The -RetrieveEwsOperationAccessPolicy switch is required; the list is not returned otherwise.
  3. Build the allow list yourself. Decide which apps genuinely need EWS until they are migrated, then set the complete list and enable EWS. The Learn example for the cmdlet is a comma-separated string of application IDs:
    PowerShell
    Set-OrganizationConfig -EwsEnabled $true -EwsAllowedAppIDs "aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee,11111111-2222-3333-4444-555555555555"
    To add one ID without dropping the others, read the current value first:
    PowerShell
    $appId   = "33333333-4444-5555-6666-777777777777"
    $current = (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy).EwsAllowedAppIDs
    $list    = @($current -split "," | ForEach-Object { $_.Trim() } | Where-Object { $_ }; $appId) | Select-Object -Unique
    Set-OrganizationConfig -EwsAllowedAppIDs ($list -join ",")
    If Microsoft already populated a list for you, review it: it may include apps you no longer want.
  4. Trim per mailbox where it helps. Set-CASMailbox -Identity user@contoso.com -EwsEnabled $false turns EWS off for a single mailbox while the organization setting stays on.
  5. Migrate and remove. Work with vendors on Graph-based versions, use the EWS-to-Graph mapping and the EWS Analyzer for in-house code, and delete each app from the list as it moves. The goal is an empty list well before April 2027.

Watch out: EwsAllowList, EwsBlockList and EwsApplicationAccessPolicy are older user-agent controls on the same cmdlet. They are unrelated to the retirement, they also affect REST traffic, and they do not substitute for EwsAllowedAppIDs.

How to verify#

  • Re-run Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsEnabled, EwsAllowedAppIDs and confirm every required ID is present.
  • Wait 24 hours, then exercise each allowed application against a test mailbox. Microsoft's field guidance recommends a positive and a negative test (add the app, confirm access; remove it, confirm it is blocked after propagation) in a test tenant.
  • Watch the EWS usage report over the following weeks: active apps should fall as migrations complete, and an unexpected ID appearing is your cue to investigate.
  • If something breaks and you need EWS back immediately, Set-OrganizationConfig -EwsEnabled $null returns the tenant to unrestricted EWS within about an hour, because the allow list is ignored while the value is null. Treat that as a rollback, not a destination.

Timeline#

  • July 2018: deprecation announced; no new EWS features.
  • 2023: disablement set for October 2026.
  • 2025: EWS usage report, analyzer and import/export previews released; EwsAllowedAppIDs generally available late July 2026.
  • 1 October 2026: phased disablement begins. 2 October: snapshot of Worldwide tenants with EwsEnabled True and no list. 8–9 October: Microsoft populates lists for those tenants. 10 October: allow list required whenever EwsEnabled is True (Worldwide first; other clouds announced separately).
  • Later in October 2026 onward: tenants still at $null receive a seven-day warning and are set to False in waves.
  • 1 April 2027: EWS permanently disabled in Exchange Online, with no re-enablement.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)