time 2 minute read

EWS Retirement in Exchange Online

Microsoft is retiring Exchange Web Services (EWS) in Exchange Online, with phased disablement starting on October 1, 2026, and permanent retirement scheduled for April 1, 2027. To support customers during this transition, Microsoft has introduced EWSAllowedAppIDs, a new tenant setting that allows administrators to temporarily approve specific applications to continue using EWS. Organizations should use this transition period to identify EWS dependencies and accelerate their migration to Microsoft Graph, Microsoft's modern and fully supported API platform.

Microsoft Graph replacing EWS
Exchange Web Services (EWS) has been the primary mailbox access API for Exchange workloads for nearly two decades, supporting solutions such as backup and archiving tools, migration platforms, signature management systems, room-booking applications, multifunction printers, and custom business scripts. In 2018, Microsoft announced that EWS would no longer receive new feature investments and identified Microsoft Graph as its strategic replacement. Today, Microsoft Graph provides a modern, OAuth-based REST API with granular permissions, consistent service controls, and support for most scenarios previously served by EWS.


The Timeline — and How to Extend EWS Beyond October 2026

  • October 1, 2026 — Phased, tenant-by-tenant disablement begins. Tenants where EWSEnabled is still Null are flipped to False.

  • October 2026 to March 2027 — EWSAllowedAppIDs is the only mechanism keeping approved applications alive.

  • April 1, 2027 — Full, permanent retirement of EWS in Exchange Online.

EWSAllowedAppIDs is a tenant-level allow list that specifies which applications can continue using Exchange Web Services (EWS) during Microsoft's transition period. A key change administrators need to understand is that, after October 1, 2026, setting EWSEnabled to True without configuring approved application IDs effectively becomes a block-all configuration. Even an allow list that exists but contains no application IDs will block all EWS access, while cross-tenant organization relationship traffic remains unaffected.

How to Run the Report and Configure the Allow List

  1. Run the EWS usage report to identify EWS-dependent applications and build your migration inventory.

  2. Map application IDs to business owners and use cases before approving continued EWS access.

  3. Add only approved applications to EWSAllowedAppIDs to control EWS access during the transition.

  4. Review and reduce the allow list regularly as applications migrate to Microsoft Graph.

Conclusion
The retirement of Exchange Web Services (EWS) marks the end of a long-standing integration platform and reinforces Microsoft's shift toward Microsoft Graph as the future of Microsoft 365 connectivity. While EWSAllowedAppIDs provides a temporary bridge for critical applications, organizations should treat it as a short-term mitigation rather than a permanent solution. By identifying EWS dependencies, prioritizing application modernization, transition before EWS is permanently retired on April 1, 2027.

Please contact the industry-leading experts at Helient to assess your EWS footprint, build your allow list, and plan a clean migration to Microsoft Graph before the April 2027 deadline.