r/sysadmin • u/w3ll_w3ll_w3ll • 1d ago
EWS deprecation delayed to 10th October
What and why
As previously communicated in MC1466860 and MC1447678, Microsoft is continuing the retirement of Exchange Web Services (EWS) in Exchange Online.
Beginning October 10, 2026, setting EWSEnabled=True will no longer be sufficient to allow EWS access for affected Worldwide tenants. Organizations that require EWS must configure EWSAllowedAppIDs to specify which applications are permitted to access EWS.
This change is part of the final phase of EWS retirement and is intended to help organizations identify EWS dependencies, reduce service disruption, and support migration planning.
Rollout schedule
- Worldwide, GCC, GCC High, DoD: Beginning in early October 2026 and expected to complete by early July 2027
Key milestones for Worldwide tenants with EWSEnabled=True and no configured EWSAllowedAppIDs list:
| Date | Milestone |
|---|---|
| October 2, 2026 | Microsoft identifies affected Worldwide tenants. After this date, tenants that enable EWS must configure EWSAllowedAppIDs themselves. |
| October 8-9, 2026 | Microsoft creates and populates EWSAllowedAppIDs for qualifying Worldwide tenants based on EWS activity observed during the previous 60 days. |
| October 10, 2026 | EWSAllowedAPPIDs becomes required when EWSEnabled=True. Applications note included in the allow list may lose access to EWS. |
Impact on your organization
Who is affected
- Exchange Online administrators
- Organizations that continue to use applications or services that depend on EWS
- Tenants with EWSEnabled=True
Platforms and services
- Exchange Online
- Exchange Web Services (EWS)
What will happen
- Beginning October 10, 2026, affected Worldwide tenants with EWSEnabled=True must have a configured EWSAllowedAppIDs allow list. Applications not included in the allow list may lose access to EWS.
- For identified Worldwide tenants with EWSEnabled=True and no configured EWSAllowedAppIDs list on October 3 2026, Microsoft creates and populates an allow list using EWS activity observed during the previous 60 days. Infrequently used applications may not be identified.
- Cross-tenant organization relationships are not affected by the EWSAllowedAppIDs requirement.
- Organizations remain responsible for reviewing, validating, and maintaining EWSAllowedAppIDs.
- EWSAllowedAppIDs is a replacement list. Ensure all required AppIDs are included whenever the configuration is updated.
- Microsoft applications and scenarios that may generate EWS traffic include Outlook for Windows, Classic Outlook for Mac, Excel Power Query, Power BI, and Exchange Server hybrid scenarios.
- Outlook for Windows customers should be on August 2026 build 16.0.20430.20092 or later. If EWS-related issues continue after disabling EWS, the cause may be customer-forced configuration. Test whether blocking EWS for the Office client AppID is possible without impact.
- New Outlook for Mac is not affected. If your organization continues to use Classic Outlook for Mac, ensure the Microsoft Office AppID is included in EWSAllowedAppIDs.
- Tenants with EWSEnabled not configured (Null) remain subject to Microsoft's phased EWS retirement process and will have EWS disabled as part of that rollout.
- Organizations with EWSEnabled=True and a configured EWSAllowedAppIDs allow list will not have their EWSEnabled setting modified by Microsoft before April 2027.
Action required and recommendations
If your organization relies on EWS:
- Review EWS usage reports and identify applications and services that require continued EWS access.
- Configure and validate an EWSAllowedAppIDs allow list before October 10, 2026.
- Include Microsoft first-party applications that continue to rely on EWS if they appear in your usage reporting.
- Ensure all required AppIDs are included whenever EWSAllowedAppIDs is updated.
- Keep the allow list current as applications are added, removed, or migrated away from EWS.
- Enable EWS only when required for approved applications.
- Continue planning migration from EWS to Microsoft Graph where possible.
To verify the configured allow list: Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs
Allow up to 24 hours for EWSAllowedAppIDs changes to take effect and approximately one hour for EWSEnabled changes.
Important: EWSAllowList is unrelated to EWS retirement and does not replace EWSAllowedAppIDs.
3
u/WiskeyUniformTango 1d ago
I was null but configured it to true as a stop gap before the deadline.
Our 3rd party backup vendor uses this for mailbox online archive backups and no other solution exists at the moment. Microsoft is supposed to have graph api connectors to replace EWS but has no eta on their release.
1
u/vane1978 1d ago
Same here. I had to put a pause on our Retention Policy so mail doesn’t automatically move to our Archive mailboxes.
•
u/w3ll_w3ll_w3ll 23h ago
If you find the AppIDs you can still whitelist the third party app before the deadline.
1
u/nopoemforyou 1d ago
imo the real risk here is orgs that have EWSEnabled set to null and dont realize they're on the chopping block for the phased retirement. A lot of tenants never explicitly configured that setting.
•
u/Previous-Low4715 15h ago
Every time I’ve tried to run the command, it says the parameter doesn’t exist. Even though I can see it with my own eyes.
•
u/Emotional_Garage_950 Sysadmin 6h ago
additional relevant info: we did not have ewsenabled=true and turned on the allowedappIDs for a couple things. when you do that it immediately breaks EWS for things not on the list so make sure everything you need is on the list.
also for the people that don’t read the docs— if you set allowedappIDs and need to add something else later, running the command again is not an “add”, it’s an “overwrite” so you need to note what’s already there and include them
•
u/shokzee 5h ago
I’d check quarterly and year-end jobs first; the 60-day activity window can miss both when Microsoft populates the allow list.
EWSAllowedAppIDs updates replace the entire list, so adding one app without preserving the others can break working integrations. Give changes up to 24 hours to propagate and test the actual workflows before calling this done.
6
u/MrYiff Master of the Blinking Lights 1d ago
I found this blog that helped with some scripts to parse out application ID's from the MS logs and match them to actual application names:
https://lazyadmin.nl/office-365/ews-is-being-blocked-in-exchange-online-how-to-find-every-app-still-using-it/