In this article:
Want us to find IT vendors for you?
Share your vendor requirements with one of our account managers, then we build a vetted shortlist and arrange introductory calls with each vendor.
Book a call

Microsoft EWS Retirement in Exchange Online: What to Do Before April 1, 2027

Microsoft's EWS retirement turns off Exchange Web Services in Exchange Online on April 1, 2027. See what broke, what Graph won't replace, and your runbook.

Author:
Date

Microsoft's retirement of Exchange Web Services (EWS) in Exchange Online is already in force. Enforcement began on October 1, 2026. From October 10, every tenant that keeps EWS on must name each allowed application in an allow list. On April 1, 2027, EWS shuts off permanently and admins lose the setting that controls it.

Early guidance treated October 1 as the finish line. It turned out to be the first of several steps, and each one breaks something different: frontline-licensed mailboxes first, then apps missing from the allow list, then Mac mail clients, and finally every backup, archiving and migration tool that still reads mailboxes through EWS.

I treat April 1, 2027 as a hard stop. Microsoft has told reporters there will be no exceptions, and the setting that lets you turn EWS back on goes away on that date.

EWS retirement at a glance

Oct 1, 2026Enforcement began. Kiosk, F1 and F3 mailboxes started receiving HTTP 403 errors.
Oct 10, 2026An allow list became mandatory for every tenant that keeps EWS on.
Apr 1, 2027EWS shuts off in Exchange Online, and the setting to turn it back on disappears.the hard stop

Three decisions for this week

  1. Confirm your tenant's EWS state with one PowerShell command.
  2. Review Microsoft's automatic allow list for apps it missed and apps nobody approved.
  3. Get dates in writing from your backup, archiving and migration vendors.

IT Leaders Report 2026

What are your IT peers investing in 2026?

We spoke to about 1,300 IT leaders from various organisations to understand what they're evaluating. Most of it is the kind of thing you'd only hear from a peer you know well enough to ask, so we've put it in one place.

Read the report
IT Leaders Report 2026 cover artwork

‍

What is Exchange Web Services, and why is Microsoft retiring it?

Exchange Web Services (EWS) is the SOAP-based API that applications have used since Exchange Server 2007 to read and write mail, calendars, contacts and other mailbox data. In Exchange Online, Microsoft Graph replaces it, and EWS stops working on April 1, 2027.

Microsoft frames the retirement as a security decision. EWS has received no feature updates since July 2018, and the Exchange team describes it as a protocol built nearly 20 years ago that no longer meets current security, scale and reliability requirements (Exchange Team blog, February 2026).

The January 2024 Midnight Blizzard incident sharpened that position. Microsoft's EWS deprecation guidance states that the incident involved EWS, raised the urgency of the retirement, and widened its scope to Microsoft's own products, including Outlook, Office, Teams and Dynamics 365.

That history explains the shape of the transition. The allow list exists so that only applications an admin names can use EWS during the final months, and the retirement stops at the edge of Exchange Online.

What the EWS retirement covers

The cutoff applies to Exchange Online. Anything that crosses into Exchange Online follows the same schedule.

Retiring

Exchange Online

EWS requires an allow list now and shuts off on April 1, 2027. Microsoft Graph is the replacement.

Affected

Hybrid and partner sharing

Rich coexistence and cross-tenant free/busy lose EWS on the same schedule, and need Graph-based or policy-based replacements.

Unchanged

Exchange Server on-premises

EWS keeps working inside your own Exchange servers. Microsoft has announced no change there.

‍

EWS retirement timeline: key dates from October 2026 to April 2027

Enforcement began on October 1, 2026, four milestones landed in the first ten days of October, and EWS ends for every commercial tenant on April 1, 2027. Microsoft's guidance changed several times between February and October 2026, so advice written before October may describe rules that no longer apply.

Enforcement began October 1; EWS ends April 1, 2027

Dates from Microsoft notices. Unconfigured tenants switch off on unpublished, per-tenant dates, so they have no marker.

20262027OctNovDecJanFebMarAprMayJunJul
Enforcement begins; frontline 403 errorsOct 1, 2026
Affected tenants identifiedOct 2, 2026
Automatic allow lists builtOct 8 and 9, 2026
Allow list required if EWS is onOct 10, 2026
Partner calendar policy rollout endsOct 15, 2026 (commercial cloud)
Graph archive mailbox support expectedLate Oct to early Nov 2026
Remaining Graph roadmap targetsQ4 2026
EWS fully disabled, setting removedApr 1, 2027
the hard stop
All-cloud rollout ends (unexplained)Early July 2027

One Microsoft notice gives both October 2 and October 3 as the date it identified affected tenants. The July 2027 row conflicts with the April 1 date, and the next section explains why it shouldn't change your plan.

‍

When do unconfigured tenants lose EWS, and is the deadline April or July 2027?

Tenants that never configured EWS switch off one at a time on dates Microsoft has not published, and April 1, 2027 remains the deadline to plan around. Both answers contradict claims that spread widely in early October.

Unconfigured tenants. Many admin guides said tenants that never set EWSEnabled were switched off on October 1, 2026. Microsoft's notices say only that these tenants stay subject to a phased process.

In September, the Exchange team added detail: Microsoft fills in an allow list a few days before it switches each unconfigured tenant off, one tenant at a time, and some tenants may not get a list until later in October (Exchange Team blog, September 2026).

If your tenant is unconfigured, Microsoft controls the timing. Setting EWSEnabled explicitly, either to True with a list you own or to False, puts the timing back in your hands. That's the first change I'd make this week.

The final date. Microsoft repeatedly states that EWS is fully retired on April 1, 2027 and that admins lose the ability to change the setting from that day. Its enforcement notice of October 1, 2026 also says the rollout across the commercial, GCC, GCC High and DoD clouds should complete by early July 2027. Microsoft has not explained how the two dates relate, so treat April 1, 2027 as the hard stop for commercial tenants and any later date as unconfirmed.

Government clouds. The allow list setting reached GCC in late July 2026, but the October milestones (tenant identification, automatic lists, the October 10 requirement) are stated for the commercial cloud only. The EWS usage report in the admin center is also commercial-only, and Microsoft paused the cross-tenant calendar policy rollout for GCC, GCC High and DoD as of October 5, 2026.

EWS claim check: what circulated vs. what Microsoft says

Checked against Microsoft notices revised through October 5, 2026.

Claim in circulationVerdictWhat Microsoft's record says
Unconfigured tenants were switched off on October 1, 2026OverstatedThey switch off one tenant at a time, with an allow list built a few days before. No per-tenant date is published.
A second phase starts after October 10 with a seven-day warningUnconfirmedAppears in one MVP blog. No Microsoft notice describes it.
The retirement runs through July 2027UnreconciledOne Microsoft notice says the all-cloud rollout completes by early July 2027. Every other Microsoft source says full retirement on April 1, 2027.
Government clouds follow the October datesNot supportedThe October milestones are stated for the commercial cloud only. GCC, GCC High and DoD run on their own schedule.
EWS can be turned back on after April 1, 2027IncorrectThe setting is removed for all tenant admins on that date, and Microsoft has told reporters there will be no exceptions.

‍

How to check your tenant's EWS state (EWSEnabled and EWSAllowedAppIDs)

Two settings decide what your tenant does today. EWSEnabled is the organization-wide switch, and EWSAllowedAppIDs is the allow list of application IDs permitted to use EWS. Run both commands in Exchange Online PowerShell, then find your row in the table below.

Exchange Online PowerShell: check your EWS state
Get-OrganizationConfig | Format-List EwsEnabled
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs

The second command needs the -RetrieveEwsOperationAccessPolicy flag. Microsoft returns the allow list only when it is explicitly requested, so a plain Get-OrganizationConfig shows the list as empty even when one exists. An admin who skips the flag can conclude there is no list and overwrite the one Microsoft built.

Find your row: what each EWS tenant state means

Behavior from October 10, 2026. On April 1, 2027, EWS stops in every row.

Your tenant stateEWS todayWhat happens nowThrough April 1, 2027What to do
EWSEnabled blank (never configured)Microsoft's scheduleTreated as on, with no restrictions, until Microsoft reaches your tenant. A list is built a few days before the switch.Switched off on an unpublished dateSet True with your own list, or set False
True since before October 2, no list of your ownListed apps onlyMicrosoft built a list on October 8 or 9 from 60 days of traffic.Microsoft will not change EWSEnabledReview the list in both directions
True, set after October 2, no listBlockedNo automatic list. Only cross-tenant organization relationships still work.Blocked until you add a listBuild a list or set False
True with an empty listBlockedAll EWS blocked under the current rules. Before October, an empty list allowed everything.BlockedAdd entries or set False
True with a list you configuredListed apps onlyOnly listed apps, plus cross-tenant organization relationships. Microsoft leaves your list alone.UnchangedShrink the list as apps move to Graph
FalseOffAll EWS blocked.BlockedSwitch to True with a list only for apps that still need EWS

‍

Cross-tenant organization relationships, which carry partner free/busy and calendar sharing, are exempt from the allow list in every state until April 1, 2027. For the empty-list case, Microsoft states that True with no list blocks everything but never separately describes a list that exists with zero entries. The block-all reading follows from its other statements.

‍

What already broke: Kiosk and F3 403 errors, unlisted apps and Mac mail clients

The first breakages came from two separate changes that landed close together, and help desks routinely mix them up. One is a licensing change. The other is the allow list.

Frontline licenses hit a wall on October 1. Since October 1, 2026, Microsoft blocks EWS for any mailbox licensed only with Exchange Online Kiosk, Microsoft 365 F1 or F3, or Office 365 F1 or F3, and returns an HTTP 403 error. The block is tied to the license, so allow list entries don't help. Microsoft documents one fix: assign a license that includes EWS rights, such as Exchange Online Plan 1 or 2, or E3 or E5. If that pushes frontline users into a new license tier, weigh it alongside your broader Microsoft 365 E3 versus E5 decision. Third-party tools that act on those mailboxes fail the same way; MailStore, for example, states that its Kiosk and frontline customers must move to Graph or IMAP.

Unlisted apps lost access on October 10. From that date, any tenant with EWS on must list every app that uses it. Apps missing from the list stopped working, and unconfigured tenants will see the same result whenever Microsoft switches them over.

Mac users felt it first among end users. Classic Outlook for Mac still uses EWS and needs the Microsoft Office app ID on the list, while new Outlook for Mac is unaffected. Apple's built-in Mail, Calendar and Contacts apps on macOS also use EWS for Exchange accounts. Apple's Platform Deployment guide says Apple is working with Microsoft to move these apps to Graph in a future update to macOS 27, with no date given. iPhone and iPad are unaffected because they connect through Exchange ActiveSync. If you manage Macs centrally, pushing new Outlook for Mac through your Apple device management platform is the fastest way off EWS for those users.

EWS status by client and scenario

As of October 10, 2026, and what changes on April 1, 2027.

Client or scenarioNowAfter April 1, 2027Path forward
Kiosk, F1 and F3 mailboxesBlocked (403)BlockedLicense with EWS rights now; Graph-based tools before April
Third-party apps missing from the listBlockedBlockedVendor's Graph version, or add to the list as a bridge
Classic Outlook for MacNeeds Office app IDNo documented pathMove users to new Outlook for Mac
New Outlook for MacWorksWorksNone needed
Apple Mail, Calendar and Contacts on macOSWorks while allowedWaits on Apple updateNew Outlook for Mac, or wait for Apple's macOS 27 update
iPhone and iPad MailWorksWorksNone needed (Exchange ActiveSync)
Power Query Exchange connector (Excel, Power BI, Fabric, Dataflows)Fails if EWS blockedFailsNo replacement documented by Microsoft
Dynamics on-premises server-side sync to Exchange OnlineFails if EWS blockedFailsNo replacement documented by Microsoft
Teams panelsUpdate neededUpdate neededUpdate to app version 1449/1.0.97.2025120101 or later
Third-party room booking and display panelsNeeds listingBlocked unless on GraphVendor's Graph version

‍

Microsoft documents the Power Query, Dynamics and Teams panel behavior in its Baseline Security Mode guidance, which lists what breaks when EWS is blocked. It has not published Apple Mail's app ID, so tenants that allow Apple Mail must identify it from their own usage report.

‍

Why Microsoft's automatic EWS allow list needs a review

The allow list Microsoft built for your tenant can be wrong in both directions, and Microsoft's own notices acknowledge both risks. I treat it as a draft inventory and review it like any other access grant.

It can be too narrow. Microsoft built each list from 60 days of observed EWS traffic and warns that infrequently used applications may not be identified. Any job that runs less often than that, such as a quarter-end export, a year-end archive run, a disaster recovery test or a legal hold collection, was invisible during the window. It will fail on its next run, often when the team that owns it is busiest.

It can be too broad. The same method admitted everything that ran, whether or not anyone approved it. Microsoft's FAQ concedes the list might include apps you weren't aware of. In practice, that can mean a trial tool someone connected, a script left behind by a departed engineer, or an integration that should have been retired years ago. Each one now holds an explicit EWS grant in your tenant, which is the opposite of what the retirement is meant to achieve.

Two ways the automatic allow list goes wrong

Microsoft built each list from 60 days of observed EWS traffic.

Too narrow

Rare jobs fell outside the window

Quarter-end exports, year-end archive runs, disaster recovery tests and legal hold collections may not have run while Microsoft was watching.

Catch it: ask every system owner about jobs that run less often than every 60 days.

Too broad

Everything that ran got in

Approved backup toolTrial tool someone connectedScript from a departed engineerIntegration nobody retired

Microsoft concedes the list might include apps you weren't aware of. Each entry is now an explicit EWS grant.

Catch it: match every app ID to a named owner, and remove what nobody claims.

Microsoft does not mark which entries it added, so save a dated export of the list before you change anything. Then work through both directions with this checklist. The usage report covers 90 days at most, so it will not reveal annual jobs either; only the people who own those systems know they exist.

Allow list review checklist

0 of 6 done

‍

What breaks on April 1, 2027: EWS features with no Microsoft Graph replacement

On April 1, 2027, every remaining EWS call in Exchange Online fails, and three areas will never get a full Microsoft Graph equivalent: public folders, Microsoft 365 Group mailboxes and discovery mailboxes. Archive mailboxes, the gap backup vendors worried about most, are on track to close before then.

Microsoft's deprecation guidance adds a blunt rule: if a capability is missing from its roadmap table, do not plan on a Graph equivalent arriving before EWS is disabled. Its listed dates are targets and can move.

EWS to Microsoft Graph: what has a replacement

Microsoft's stated positions as of October 2026. Targets can move.

EWS capabilityGraph statusMicrosoft's positionWhat it means for you
Public folder read and writeWill not be addedConfirmed as never coming to Graph.Tools that read or write public folders through EWS stop on April 1, 2027.
Microsoft 365 Group mailbox read and writeWill not be addedUse Graph group conversations, threads and posts.Tools that treat Group mailboxes as ordinary mailboxes need a redesign.
Discovery mailbox accessWill not be addedUse Microsoft Purview eDiscovery.Legacy eDiscovery workflows move to Purview.
Archive mailbox accessExpected Oct to Nov 2026General availability expected late October to early November 2026, including auto-expanding archives.Ask vendors when they adopt it. Archive tools left on EWS stop on April 1.
Archive import and exportConflictingQ4 2026 target on the roadmap; other Microsoft pages list archive as already supported.Confirm in your own tenant before relying on it.
Public folder and Group import and exportQ4 2026 targetCovers bulk import and export only.A path for moving content out, with no day-to-day access.
Exchange Admin API, Report Message, non-draft MIME, user configuration objects, Mark All As ReadQ4 2026 targetListed on Microsoft's roadmap.Check each against what your tools actually call.
Notes, contact lists, extra contact propertiesUnconfirmedQ3 2026 targets; current status not confirmed.Verify before you plan on them.
Government and sovereign cloud availabilityQ4 2026 targetNew APIs reach these clouds later.GCC and other clouds may trail the commercial cloud.

Two cautions apply to backup in particular. Microsoft states that the Graph mailbox import and export APIs are not designed for backup and restore, and it points customers toward Microsoft 365 Backup instead. A vendor's announcement of Graph support may also cover primary mailboxes only, so ask which mailbox types it includes.

Calendar delta queries, notifications and free/busy do not appear as gaps on Microsoft's roadmap. If your integrations depend on them, test the specific Graph calls against your own workloads before you retire the EWS version.

What happens to public folders after April 1, 2027?

Public folders and their content stay in place on April 1, 2027. What ends is programmatic access through EWS, and Graph will never replace it. Microsoft has not published a recommended destination in the guidance reviewed here. Vendors offer two views: MailStore states that Microsoft recommends Microsoft 365 Groups, and CiraSync recommends shared mailboxes.

Choose based on how people use the content today. Then finish the move while EWS still works for your migration tool, because bulk public folder export through Graph is still only a Q4 2026 target.

‍

Will your Microsoft 365 backup keep working after the EWS retirement?

Your backup keeps working only if the vendor moves to Graph before April 1, 2027, or keeps its app IDs on your allow list until it does. Backup, archiving and migration tools carry most of the April risk, because they touch every mailbox type, including the ones Graph will never fully cover.

Vendors' public positions vary widely, and several still depend on EWS today. Everything in this table is the vendor's own statement about its product. If you're already reassessing your platform, compare candidates on how they protect Exchange Online without EWS, alongside the usual RPO and RTO criteria.

What backup, archiving and migration vendors say about EWS

Vendor statements about their own products, taken from their documentation. Not verified independently.

Vendor and productEWS statusVendor statesDoc date
Veeam Backup for Microsoft 365Still on EWSUses EWS for Exchange Online backup because Graph lacks what incremental backup needs. Customers should keep EWS on and list Veeam's app IDs. Archive mailboxes stay on EWS until Graph supports them.October 7, 2026
MailStore ServerPartly on GraphRegular mailboxes moved to Graph from version 26.1. Archive mailboxes and public folders still use EWS and cannot be archived after April 2027.Undated
MimecastNeeds allow listCustomers should add Mimecast's app IDs to the allow list.September 22, 2026
Backup ExecNeeds allow listCustomers copy the app IDs from the console and add them to the list.Undated
BitTitan MigrationWizGraph in developmentA Graph-based mailbox migration path is in development, and public folder migrations should not wait.Undated
Riva (CRM sync)Needs allow listCustomers should set EWSEnabled to True and list Riva's app IDs.Undated
CiraSync (public folder sync)EWS sync endingEWS-based public folder sync will stop; recommends moving to shared mailboxes.Undated
ManageEngine (help desk)EWS support endedHas stopped supporting EWS for Exchange Online mailboxes.Undated

The pattern matters more than any single row: vendors still ask you to keep their app IDs on the list, and few publish a date for leaving EWS entirely. That makes archive mailboxes the decision point for most backup and archiving contracts.

If Graph archive support arrives on schedule, and if it doesn't

Microsoft expects archive mailbox support in Graph to reach general availability between late October and early November 2026. Whether it lands, and whether your vendor adopts it, decides your next move.

Archive mailboxes: what to do before April 1, 2027

Microsoft documents no fallback for archive operations that still run through EWS.

Does your backup or archiving tool read archive mailboxes through EWS?
No →
No archive action needed. Get the vendor's answer in writing anyway.
Yes ↓
Has Microsoft shipped Graph archive support?Expected late October to early November 2026
No →
Plan as if archive access ends on April 1, 2027, and start evaluating alternatives now.
Yes ↓
Has your vendor committed to a dated release that uses it?
→
YesTest archive backup and restore in your tenant, including auto-expanding archives. Then remove the vendor's archive app IDs from the list.
NoReplace the vendor or change your archive approach. Put Microsoft 365 Backup on the evaluation list.decide by end of January 2027

Microsoft sets no decision date for you. Deciding by the end of January 2027 leaves February and March to replace a vendor or change your archive approach and still test before the cutoff.

Questions to get answered in writing

Send these to every backup, archiving and migration vendor that touches Exchange Online. A vague answer to any of them is an answer in itself.

EWS questions for your vendors

1Which mailbox types still use EWS in your product today: primary, shared, archive, auto-expanding archive, public folder or Group?
2Which app IDs must stay on our allow list, and on what date does each one come off?
3On what date will your product use Microsoft Graph for archive mailboxes?
4What happens to public folder and Group mailbox content in your product on April 1, 2027?
5How does your product handle mailboxes licensed with Kiosk, F1 or F3?
6Does your Graph-based version keep incremental backup and item-level restore?
7Which clouds does your Graph-based version support: commercial, GCC, GCC High?

Which Microsoft apps still use EWS?

Several of Microsoft's own apps still generate EWS traffic, and classic Outlook for Mac needs an allow list entry to keep working. Microsoft is removing EWS from Outlook, Office, Teams and Dynamics 365, but its notices name only some of them, and several common scenarios remain undocumented.

Microsoft's own apps and EWS

Where Microsoft has published nothing, your EWS usage report is the authority.

Microsoft app or scenarioStatusWhat to do
Outlook for WindowsMay use EWSUpdate to build 16.0.20430.20092 (August 2026) or later.
Classic Outlook for MacUses EWSKeep the Microsoft Office app ID on the list, or move users to new Outlook for Mac.
New Outlook for MacNot affectedNone.
Excel Power Query and Power BI (Exchange connector)Fails if EWS blockedNo replacement documented. Inventory the reports and dataflows that use it.
Dynamics 365 on-premises server-side sync to Exchange OnlineFails if EWS blockedNo replacement documented.
Teams calendarApp ID documentedMicrosoft documents the Teams app ID cc15fd57-2c6c-4117-a88c-83b1d56b4bbe for tenants that still use older user-agent policies.
Teams panelsUpdate neededUpdate to app version 1449/1.0.97.2025120101 or later.
Outlook on the web and Outlook mobileNot addressedWatch your usage report for their traffic.
Teams add-in in classic Outlook, Teams Rooms, Power AutomateUndocumentedNo guidance or app IDs published. Find them in your usage report.
Legacy Room FinderUndocumentedMicrosoft links to instructions for reverting to it without stating its EWS role. Test room booking before April.

‍

Microsoft does not publish the Office app ID in its EWS notices. Office 365 IT Pros reports it as d3590ed6-52b3-4102-aeff-aad2292ab01c; confirm it against your own usage report before you add it. If any Microsoft app ID shows up in that report, it needs a decision like any other app.

‍

Exchange hybrid and cross-tenant free/busy after the EWS retirement

Exchange Server keeps EWS on-premises, but anything that crosses into Exchange Online loses EWS on the same schedule as everything else. That includes hybrid rich coexistence and calendar sharing with partner companies.

For hybrid, only Exchange Server Subscription Edition with the May 2026 update or later uses Graph for rich coexistence. Older versions lose it permanently in April 2027. Microsoft's hybrid guidance covers the Exchange SE requirements in detail.

Partner sharing moves to Cross-Tenant Access Policy. If those relationships exist because of an acquisition, this is a good moment to revisit whether the tenants should stay separate at all; our tenant consolidation guide covers the tooling.

Hybrid and partner sharing: before and after April 1, 2027

Cross-tenant dates apply to the commercial cloud. Microsoft paused the government cloud rollout as of October 5, 2026.

ScenarioUntil April 1, 2027From April 1, 2027What to do
Hybrid rich coexistence (free/busy and MailTips between on-premises and cloud)Works with listing
EWSEnabled True and the dedicated hybrid app on the list
Exchange SE only
Requires the May 2026 update or later, which uses Graph
Upgrade to Exchange SE and give the hybrid app Graph permissions
Older Exchange versions in hybridWorks with listingEnds
Rich coexistence stops permanently
Plan the upgrade now
Partner free/busy and MailTips (organization relationships)Exempt from list
While EWSEnabled is True
Cross-Tenant Access PolicyRollout was due to finish September 15, 2026; confirm it reached you
Partner calendar sharing (sharing policies)Exempt from list
While EWSEnabled is True
Cross-Tenant Access PolicyRollout due to finish October 15, 2026
On-premises Exchange sharing with another company's Exchange OnlineWorks while allowedNo solution announcedMicrosoft is collecting customer feedback; watch for its next notice

To see which partner relationships and sharing policies you have today, run these two commands:

Exchange Online PowerShell: list partner sharing
Get-OrganizationRelationship | Format-List Name, DomainNames, Enabled, FreeBusyAccessEnabled, FreeBusyAccessLevel, FreeBusyAccessScope, MailTipsAccessEnabled, MailTipsAccessLevel, MailTipsAccessScope
Get-SharingPolicy | Format-List Name, Domains, Enabled, Default

‍

How to find every app using EWS in your tenant

The EWS usage report in the Microsoft 365 admin center is the fastest inventory. Go to Reports > Usage > Exchange > EWS usage to see each calling application ID and the EWS operations it used over 7, 30 or 90 days.

The report has three limits. It aggregates data weekly, so a job that ran yesterday may not appear yet. It looks back 90 days at most, which hides anything that runs less often. And it exists only for commercial tenants; government and sovereign tenants use Microsoft's ews-migration-analyzer on GitHub instead.

From usage report to decision in four steps

Every app ID that still needs EWS should end with an owner, an outcome and a date.

1

Pull the usage report

Reports, Usage, Exchange, EWS usage. Export 90 days of app IDs and the operations they call.

2

Turn IDs into owners

Match Microsoft's IDs to its first-party app list. Look up the rest under Enterprise applications in Microsoft Entra ID.

3

Check older policies

Client-name rules in EwsAllowList and EwsBlockList still apply, and a connection must pass both checks.

4

Pick an outcome and a date

Choose one outcome per app and record when it leaves the list.

RetireVendor upgradeRewrite to GraphReplaceBridge with exit date

‍

Step 3 catches a failure that confuses admins. Before the allow list existed, many tenants restricted EWS by client name using the older EwsApplicationAccessPolicy settings. Exchange Online still evaluates those rules alongside the new list, so an app on your new list can still fail because an old rule blocks its client name. Microsoft also warns that blocking by client name can affect REST and Graph connections. Check what you have with this command:

Exchange Online PowerShell: check older EWS policies
Get-OrganizationConfig | Format-List EwsEnabled,EwsApplicationAccessPolicy,EwsAllowList,EwsBlockList

‍

Individual mailboxes can also carry their own EwsEnabled setting through Set-CASMailbox. Turning EWS off for the organization overrides those per-mailbox settings.

‍

EWS allow list mistakes that cause outages

Five documented behaviors of EWSAllowedAppIDs turn routine changes into outages. Each one is easy to trip over during a change that looks harmless.

Five allow list mistakes and how to avoid them

Each behavior below is documented by Microsoft.

MistakeRiskWhat happensHow to avoid it
Adding one app with a plain writeHighEvery write replaces the entire list, so the new ID becomes the only one.Read the current list, append the new ID, and write the full set back.
Reading the list without the retrieve flagHighThe list does not come back, so it looks empty and invites an overwrite.Always include -RetrieveEwsOperationAccessPolicy.
Clearing the list to start freshHighSince October 2026, EWS on with no entries blocks every app. Before October, an empty list allowed everything.Retire old scripts and runbooks written for the old meaning.
Expecting changes to apply at onceMediumList changes take up to 24 hours. EWSEnabled changes take about an hour.Change the list at least a day before the job that depends on it.
Forgetting older client-name policiesMediumThey stay active and can block an app your new list allows.Review EwsAllowList and EwsBlockList alongside the new list.

‍

The commands, exactly as Microsoft documents them:

Exchange Online PowerShell: read and write the EWS allow list
# Read the current list (the flag is required)
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs

# Write the list (replaces everything already there)
Set-OrganizationConfig -EwsAllowedAppIDs "11111111-2222-3333-4444-555555555555,aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee"

# Turn EWS on or off for the organization
Set-OrganizationConfig -EwsEnabled:$true
Set-OrganizationConfig -EwsEnabled:$false

‍

Microsoft documents no add-only or remove-only syntax. Its Exchange Team post introducing EWSAllowedAppIDs walks through the read, append and write pattern, ending with Set-OrganizationConfig -EwsAllowedAppIDs ($updated -join ","). Shortcut syntax that appears on some blogs isn't in Microsoft's documentation, so test it in a non-production tenant before you trust it.

Baseline Security Mode in the Microsoft 365 admin center offers a second way to maintain the app ID list without PowerShell. The Exchange team also published field notes on testing allow list changes safely in August 2026.

‍

Check your EWS exposure

Six answers tell you what is broken in your tenant today, what stops on April 1, 2027, and which runbook steps apply to you. The checker uses the same Microsoft guidance as the rest of this guide, and it updates as you click.

Check your EWS exposure

Six questions. Results update as you answer. Nothing is stored or sent.

1. How is EWSEnabled set in your tenant?

2. Which Mac mail clients connect to Exchange Online?Pick all that apply

3. Which mailbox types do your tools touch?Pick all that apply

4. Which third-party tools might still use EWS?Pick all that apply

5. Do any users have Kiosk, F1 or F3 licenses?

6. Do you run Exchange hybrid or share calendars with partner companies?Pick all that apply

Broken or at risk now

    Stops on April 1, 2027

      Your next steps

        Based on Microsoft guidance as of October 2026.

        ‍

        EWS migration runbook: from now to April 1, 2027

        The runbook follows Microsoft's own sequence: inventory, build and validate the list, keep it current, then move each app to Graph. Front-load the discovery work, because every later phase depends on knowing who owns each app ID.

        Your EWS runbook, phase by phase

        Planning dates, not Microsoft deadlines. They leave time to test before a cutoff Microsoft says it won't extend.

        1. This week

          • Check your tenant state with the two state commands.
          • Export Microsoft's automatic list and review it in both directions.
          • Confirm licenses for Kiosk, F1 and F3 users who rely on EWS-based tools.
          • If your tenant is unconfigured, set EWSEnabled explicitly.

          Done when: you know your state, and every list entry is kept or under investigation.

        2. October to November 2026

          • Map every app ID to an owner, an outcome and a migration date.
          • Send vendors the seven written questions.
          • Confirm the Exchange SE update for hybrid and the Cross-Tenant Access Policy rollout.
          • Inventory Power Query and Power BI reports that use the Exchange connector.
          • Plan Mac client moves to new Outlook for Mac.

          Done when: every app has an owner, a vendor answer and a target date.

        3. December 2026 to January 2027

          • Decide your archive scenario based on whether Graph archive support shipped and your vendors adopted it.
          • Choose a public folder destination and start moving content.
          • Select replacements for any vendor without a committed date.

          Done when: replacement decisions are made by the end of January.

        4. February to March 2027

          • Cut over each app to its Graph-based version or replacement.
          • Remove each app ID from the list once it runs on Graph.
          • Run quarter-end and annual jobs early on the new path to prove they work.

          Done when: the list holds only apps with a dated exit before April 1.

        5. April 1, 2027

          • Final check: backups, archive jobs, room booking, hybrid free/busy and partner calendars all work without EWS.

          Done when: no business process depends on EWS.

        Microsoft sets none of these internal dates. I built them backward from April 1, 2027 so that every replacement runs on its new path for several weeks, including early test runs of quarter-end and annual jobs, before EWS disappears.

        ‍

        Clean up full_access_as_app permissions while you're in there

        The app inventory doubles as an access review, and the highest-value target is the full_access_as_app permission. It lets an application reach every mailbox in the tenant through EWS, and it tends to outlive the projects that needed it.

        In Microsoft Entra ID, review the API permissions on your app registrations and enterprise applications for Office 365 Exchange Online's full_access_as_app. Microsoft's EWS guidance doesn't publish a discovery script for this, so treat any community script as a starting point and verify its results.

        Turn a forced migration into less standing access

        full_access_as_app grants an app EWS access to every mailbox in your tenant. Use the EWS inventory to shrink that exposure in three moves.

        Find itCheck app registrations and enterprise applications in Microsoft Entra ID for Office 365 Exchange Online's full_access_as_app.
        Remove itStrip the permission from apps missing from your usage report or without an owner, and delete registrations nobody claims.
        Scope the restAs apps move to Graph, use RBAC for Applications in Exchange Online to limit each one to the mailboxes it needs.

        ‍

        What Microsoft still hasn't confirmed about the EWS retirement

        Microsoft has revised its EWS notices several times since February 2026, and several points remain unsettled or contradictory. Re-check these before you act on them, and expect further revisions before April.

        Open questions in Microsoft's EWS record

        Status as of October 9, 2026. This guide's change log tracks updates.

        Open questionStatusWhere Microsoft's record stands
        When does an unconfigured tenant switch off?UndatedPer tenant, with no published date. Some may not get a list until later in October.
        Is the end date April 1 or July 2027?ConflictingApril 1, 2027 everywhere except one line saying the all-cloud rollout completes by early July 2027.
        Were tenants identified on October 2 or October 3?ConflictingThe same Microsoft notice gives both dates.
        Is Graph archive support shipped, scheduled or targeted?ConflictingThree Microsoft pages say three things: already supported, general availability in late October to early November 2026, and a Q4 2026 target.
        What happens if you set EWSEnabled back to blank?ConflictingOne Exchange Team post says it re-enables EWS without restrictions; the enforcement notice says blank tenants stay subject to phased switch-off.
        Does a list with zero entries block everything?ImpliedFollows from Microsoft's rules but is never stated directly.
        Where should public folder content go?UndocumentedNo Microsoft recommendation in the guidance reviewed; vendors disagree.
        How does on-premises Exchange share free/busy with another company's Exchange Online?No solution yetMicrosoft is collecting customer feedback.
        What about Outlook on the web, Outlook mobile, Teams Rooms, Power Automate and Apple Mail app IDs?UndocumentedNo EWS guidance or app IDs published.
        How do delegated and app-only access differ in the report and in enforcement?UndocumentedNot explained in the guidance reviewed.
        Do calendar delta queries, notifications and free/busy have full Graph parity?ImpliedNot listed as gaps; parity unconfirmed.

        ‍

        One mirror of Microsoft's Message Center reports that the enforcement notice was updated again on October 7, 2026. That revision could not be verified for this guide.

        Replacing an EWS-dependent tool?

        If your backup, archiving or migration vendor can't commit to a Microsoft Graph date, find and match with vendors that fit your environment. Your information stays anonymous until you choose to talk, and it's always free to you.

        Find vetted vendors

        FAQ

        When does EWS stop working in Exchange Online?

        EWS stops working in Exchange Online on April 1, 2027, when Microsoft disables it for every tenant and removes the setting that controls it. Enforcement began on October 1, 2026, and since October 10, 2026 any tenant that keeps EWS on must list each allowed app.

        What is EWSAllowedAppIDs?

        EWSAllowedAppIDs is the Exchange Online setting that lists the application IDs allowed to use EWS. Since October 10, 2026, a tenant with EWS on blocks every app that isn't on the list, and each write to the setting replaces the entire list.

        Can I turn EWS back on in Exchange Online?

        Yes, until April 1, 2027, and only for named apps. Set EWSEnabled to True and list those apps in EWSAllowedAppIDs, because True with no list blocks everything. On April 1, 2027, EWS shuts off for good and the setting goes away.

        Does the EWS retirement affect Outlook?

        It affects some versions. Outlook for Windows should run build 16.0.20430.20092 or later, classic Outlook for Mac needs the Microsoft Office app ID on the allow list, and new Outlook for Mac is unaffected.

        Does the EWS retirement affect on-premises Exchange Server?

        EWS keeps working inside Exchange Server. Hybrid rich coexistence and sharing with other companies' Exchange Online tenants are affected, and only Exchange Server Subscription Edition with the May 2026 update keeps rich coexistence after April 2027.

        Does Apple Mail still work with Exchange Online?

        On iPhone and iPad, yes, because they connect through Exchange ActiveSync. On the Mac, Apple Mail, Calendar and Contacts work only while EWS is allowed for them; Apple says a future macOS 27 update will move them to Microsoft Graph but hasn't given a date.

        Why are my Kiosk or F3 users getting a 403 error?

        Since October 1, 2026, Microsoft blocks EWS for mailboxes licensed only with Exchange Online Kiosk, F1 or F3, and returns HTTP 403. The documented fix is a license with EWS rights, such as Exchange Online Plan 1 or 2, or E3 or E5; allow list entries don't override the license check.

        How do I find which apps use EWS?

        Open the EWS usage report in the Microsoft 365 admin center under Reports > Usage > Exchange. It shows each app ID and the EWS operations it called over up to 90 days. Government and sovereign tenants use Microsoft's ews-migration-analyzer on GitHub instead.

        What replaces EWS?

        Microsoft Graph replaces EWS, with the Exchange Admin API covering some management tasks. Microsoft says not to expect any capability missing from its roadmap before April 1, 2027.

        What happens to public folders when EWS is retired?

        The folders and their content stay, but programmatic access through EWS ends on April 1, 2027, and Microsoft Graph will never offer full public folder access. Bulk public folder import and export through Graph is a Q4 2026 target, which gives you a way to move content out.

        Will my Microsoft 365 backup keep working after EWS is retired?

        Your backup keeps working only if the vendor moves to Microsoft Graph, or keeps its app IDs on your list until April 1, 2027 and moves before then. Ask specifically about archive mailboxes, public folders and Microsoft 365 Group mailboxes, where Graph support is newest or absent.