Exchange Web Services (EWS) has been the back door into mailboxes for almost two decades, and Microsoft is now closing it in Exchange Online. From October 2026 tenants are being switched over in phases, and in April 2027 the door locks for good. This post explains the mechanism Microsoft is using, what quietly depends on EWS in a typical tenant, how to find it, and how to keep approved applications working for the few months you have left to migrate them.
Status (October 2026): Microsoft announced the retirement timeline in message center post MC1227454 (February 2026) and started enforcement on 1 October 2026 (Exchange Team blog, 1 October 2026; MC1485116). From 10 October 2026, Worldwide tenants with EwsEnabled set to True must also have an EwsAllowedAppIDs allow list, or EWS calls are blocked. Tenants that never set EwsEnabled will be disabled in waves with a seven-day Message center warning. Full, permanent retirement is 1 April 2027. Exchange Server on-premises is not affected. Re-check the Learn page and Message center, because dates for other clouds and the parity roadmap are still being updated.
What is changing#
EWS is a SOAP API that lets applications read and write mail, calendar, contacts and folders on behalf of users or as an app. It stopped receiving new features in 2018, the 2023 announcement set the disablement for October 2026, and the Midnight Blizzard incident in January 2024 made Microsoft widen the effort to its own products as well as third-party apps. Microsoft Graph is the replacement, and Microsoft publishes an EWS-to-Graph operation mapping plus an analyzer tool to help with code changes.
The retirement is controlled by two organization settings:
| Setting | Meaning |
|---|---|
EwsEnabled = $null | Never configured. EWS works today, and the allow list is ignored. These tenants are the ones Microsoft disables in waves. |
EwsEnabled = $true + EwsAllowedAppIDs | Only the listed Entra application (client) IDs can use EWS. Microsoft will not change EwsEnabled on these tenants before April 2027. |
EwsEnabled = $true, no list | Allowed everything before October; from 10 October 2026 EWS is blocked for all apps. |
EwsEnabled = $false | EWS is off for the whole tenant (including per-mailbox overrides). |
EwsAllowedAppIDs is a replacement list, not an append: every time you set it you must include every ID you still need. Changes to the list take up to 24 hours to apply; changes to EwsEnabled take about an hour.
Who is affected#
Any Exchange Online tenant with an application that still calls EWS. That includes custom code built on the EWS Managed API, vendor products, and some Microsoft clients. Microsoft's own list of things that may still generate EWS traffic includes Outlook for Windows (be on the August 2026 build 16.0.20430.20092 or later), classic Outlook for Mac (new Outlook for Mac is unaffected, but classic needs the "Microsoft Office" app ID on your list), Excel Power Query, Power BI and Exchange hybrid. On-premises Exchange keeps EWS, but hybrid rich coexistence (free/busy, MailTips, photos) talks EWS to Exchange Online unless you have moved Exchange SE to the Graph-based flow. Cross-tenant organization relationships are not subject to the allow-list requirement.
What breaks if you do nothing#
If your tenant is still at $null, Microsoft will populate an allow list from the previous 60 days of usage shortly before it sets EwsEnabled to False. Anything that ran infrequently in that window will be missing, and anything you forgot about will stop with authentication or 401-style errors that look like an outage. Expect it in places you don't think of as "EWS": older backup, archiving and journaling connectors, migration tools, CRM and ticketing integrations, signature managers, meeting-room and digital-signage panels, scripts that process shared mailboxes, and Outlook add-ins that call EWS from the client. You can set EwsEnabled back to True until April 2027, but you will still need a correct allow list.
Plan migrations against the published parity roadmap. Several gaps (archive, public folder and group import/export, in-place archive access, an Exchange Admin API, user configuration objects) have targets through Q4 CY2026, and Microsoft has confirmed that generic public folder CRUD, generic Microsoft 365 Group mailbox CRUD and discovery mailbox access will not come to Graph at all.
What to do now#
- Find your EWS usage. In the Microsoft 365 admin center go to Reports › Usage › Exchange › EWS usage. It lists each Application ID, the SOAP actions it called, call volume and last activity for 7, 30 or 90 days, and exports to CSV. Data is aggregated weekly and can lag up to 10 days. Resolve unknown IDs under Enterprise applications in the Microsoft Entra admin center, or against Microsoft's published list of first-party app IDs. Entra sign-in logs (user and service principal sign-ins filtered to the Exchange Online resource) help you see who is behind an app.
- Check your current state.
ThePowerShell
Connect-ExchangeOnline Get-OrganizationConfig | Format-List EwsEnabled Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs-RetrieveEwsOperationAccessPolicyswitch is required; the list is not returned otherwise. - Build the allow list yourself. Decide which apps genuinely need EWS until they are migrated, then set the complete list and enable EWS. The Learn example for the cmdlet is a comma-separated string of application IDs:
To add one ID without dropping the others, read the current value first:PowerShell
Set-OrganizationConfig -EwsEnabled $true -EwsAllowedAppIDs "aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee,11111111-2222-3333-4444-555555555555"If Microsoft already populated a list for you, review it: it may include apps you no longer want.PowerShell$appId = "33333333-4444-5555-6666-777777777777" $current = (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy).EwsAllowedAppIDs $list = @($current -split "," | ForEach-Object { $_.Trim() } | Where-Object { $_ }; $appId) | Select-Object -Unique Set-OrganizationConfig -EwsAllowedAppIDs ($list -join ",") - Trim per mailbox where it helps.
Set-CASMailbox -Identity user@contoso.com -EwsEnabled $falseturns EWS off for a single mailbox while the organization setting stays on. - Migrate and remove. Work with vendors on Graph-based versions, use the EWS-to-Graph mapping and the EWS Analyzer for in-house code, and delete each app from the list as it moves. The goal is an empty list well before April 2027.
Watch out: EwsAllowList, EwsBlockList and EwsApplicationAccessPolicy are older user-agent controls on the same cmdlet. They are unrelated to the retirement, they also affect REST traffic, and they do not substitute for EwsAllowedAppIDs.
How to verify#
- Re-run
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsEnabled, EwsAllowedAppIDsand confirm every required ID is present. - Wait 24 hours, then exercise each allowed application against a test mailbox. Microsoft's field guidance recommends a positive and a negative test (add the app, confirm access; remove it, confirm it is blocked after propagation) in a test tenant.
- Watch the EWS usage report over the following weeks: active apps should fall as migrations complete, and an unexpected ID appearing is your cue to investigate.
- If something breaks and you need EWS back immediately,
Set-OrganizationConfig -EwsEnabled $nullreturns the tenant to unrestricted EWS within about an hour, because the allow list is ignored while the value is null. Treat that as a rollback, not a destination.
Timeline#
- July 2018: deprecation announced; no new EWS features.
- 2023: disablement set for October 2026.
- 2025: EWS usage report, analyzer and import/export previews released;
EwsAllowedAppIDsgenerally available late July 2026. - 1 October 2026: phased disablement begins. 2 October: snapshot of Worldwide tenants with
EwsEnabledTrue and no list. 8–9 October: Microsoft populates lists for those tenants. 10 October: allow list required wheneverEwsEnabledis True (Worldwide first; other clouds announced separately). - Later in October 2026 onward: tenants still at
$nullreceive a seven-day warning and are set to False in waves. - 1 April 2027: EWS permanently disabled in Exchange Online, with no re-enablement.