Microsoft EWS Retirement in Exchange Online: What to Do Before April 1, 2027
Microsoft's EWS retirement turns off Exchange Web Services in Exchange Online on April 1, 2027. See what broke, what Graph won't replace, and your runbook.

Microsoft's retirement of Exchange Web Services (EWS) in Exchange Online is already in force. Enforcement began on October 1, 2026. From October 10, every tenant that keeps EWS on must name each allowed application in an allow list. On April 1, 2027, EWS shuts off permanently and admins lose the setting that controls it.
Early guidance treated October 1 as the finish line. It turned out to be the first of several steps, and each one breaks something different: frontline-licensed mailboxes first, then apps missing from the allow list, then Mac mail clients, and finally every backup, archiving and migration tool that still reads mailboxes through EWS.
I treat April 1, 2027 as a hard stop. Microsoft has told reporters there will be no exceptions, and the setting that lets you turn EWS back on goes away on that date.
What is Exchange Web Services, and why is Microsoft retiring it?
Exchange Web Services (EWS) is the SOAP-based API that applications have used since Exchange Server 2007 to read and write mail, calendars, contacts and other mailbox data. In Exchange Online, Microsoft Graph replaces it, and EWS stops working on April 1, 2027.
Microsoft frames the retirement as a security decision. EWS has received no feature updates since July 2018, and the Exchange team describes it as a protocol built nearly 20 years ago that no longer meets current security, scale and reliability requirements (Exchange Team blog, February 2026).
The January 2024 Midnight Blizzard incident sharpened that position. Microsoft's EWS deprecation guidance states that the incident involved EWS, raised the urgency of the retirement, and widened its scope to Microsoft's own products, including Outlook, Office, Teams and Dynamics 365.
That history explains the shape of the transition. The allow list exists so that only applications an admin names can use EWS during the final months, and the retirement stops at the edge of Exchange Online.
EWS retirement timeline: key dates from October 2026 to April 2027
Enforcement began on October 1, 2026, four milestones landed in the first ten days of October, and EWS ends for every commercial tenant on April 1, 2027. Microsoft's guidance changed several times between February and October 2026, so advice written before October may describe rules that no longer apply.
One Microsoft notice gives both October 2 and October 3 as the date it identified affected tenants. The July 2027 row conflicts with the April 1 date, and the next section explains why it shouldn't change your plan.
When do unconfigured tenants lose EWS, and is the deadline April or July 2027?
Tenants that never configured EWS switch off one at a time on dates Microsoft has not published, and April 1, 2027 remains the deadline to plan around. Both answers contradict claims that spread widely in early October.
Unconfigured tenants. Many admin guides said tenants that never set EWSEnabled were switched off on October 1, 2026. Microsoft's notices say only that these tenants stay subject to a phased process.
In September, the Exchange team added detail: Microsoft fills in an allow list a few days before it switches each unconfigured tenant off, one tenant at a time, and some tenants may not get a list until later in October (Exchange Team blog, September 2026).
If your tenant is unconfigured, Microsoft controls the timing. Setting EWSEnabled explicitly, either to True with a list you own or to False, puts the timing back in your hands. That's the first change I'd make this week.
The final date. Microsoft repeatedly states that EWS is fully retired on April 1, 2027 and that admins lose the ability to change the setting from that day. Its enforcement notice of October 1, 2026 also says the rollout across the commercial, GCC, GCC High and DoD clouds should complete by early July 2027. Microsoft has not explained how the two dates relate, so treat April 1, 2027 as the hard stop for commercial tenants and any later date as unconfirmed.
Government clouds. The allow list setting reached GCC in late July 2026, but the October milestones (tenant identification, automatic lists, the October 10 requirement) are stated for the commercial cloud only. The EWS usage report in the admin center is also commercial-only, and Microsoft paused the cross-tenant calendar policy rollout for GCC, GCC High and DoD as of October 5, 2026.
How to check your tenant's EWS state (EWSEnabled and EWSAllowedAppIDs)
Two settings decide what your tenant does today. EWSEnabled is the organization-wide switch, and EWSAllowedAppIDs is the allow list of application IDs permitted to use EWS. Run both commands in Exchange Online PowerShell, then find your row in the table below.
The second command needs the -RetrieveEwsOperationAccessPolicy flag. Microsoft returns the allow list only when it is explicitly requested, so a plain Get-OrganizationConfig shows the list as empty even when one exists. An admin who skips the flag can conclude there is no list and overwrite the one Microsoft built.
Cross-tenant organization relationships, which carry partner free/busy and calendar sharing, are exempt from the allow list in every state until April 1, 2027. For the empty-list case, Microsoft states that True with no list blocks everything but never separately describes a list that exists with zero entries. The block-all reading follows from its other statements.
What already broke: Kiosk and F3 403 errors, unlisted apps and Mac mail clients
The first breakages came from two separate changes that landed close together, and help desks routinely mix them up. One is a licensing change. The other is the allow list.
Frontline licenses hit a wall on October 1. Since October 1, 2026, Microsoft blocks EWS for any mailbox licensed only with Exchange Online Kiosk, Microsoft 365 F1 or F3, or Office 365 F1 or F3, and returns an HTTP 403 error. The block is tied to the license, so allow list entries don't help. Microsoft documents one fix: assign a license that includes EWS rights, such as Exchange Online Plan 1 or 2, or E3 or E5. If that pushes frontline users into a new license tier, weigh it alongside your broader Microsoft 365 E3 versus E5 decision. Third-party tools that act on those mailboxes fail the same way; MailStore, for example, states that its Kiosk and frontline customers must move to Graph or IMAP.
Unlisted apps lost access on October 10. From that date, any tenant with EWS on must list every app that uses it. Apps missing from the list stopped working, and unconfigured tenants will see the same result whenever Microsoft switches them over.
Mac users felt it first among end users. Classic Outlook for Mac still uses EWS and needs the Microsoft Office app ID on the list, while new Outlook for Mac is unaffected. Apple's built-in Mail, Calendar and Contacts apps on macOS also use EWS for Exchange accounts. Apple's Platform Deployment guide says Apple is working with Microsoft to move these apps to Graph in a future update to macOS 27, with no date given. iPhone and iPad are unaffected because they connect through Exchange ActiveSync. If you manage Macs centrally, pushing new Outlook for Mac through your Apple device management platform is the fastest way off EWS for those users.
Microsoft documents the Power Query, Dynamics and Teams panel behavior in its Baseline Security Mode guidance, which lists what breaks when EWS is blocked. It has not published Apple Mail's app ID, so tenants that allow Apple Mail must identify it from their own usage report.
Why Microsoft's automatic EWS allow list needs a review
The allow list Microsoft built for your tenant can be wrong in both directions, and Microsoft's own notices acknowledge both risks. I treat it as a draft inventory and review it like any other access grant.
It can be too narrow. Microsoft built each list from 60 days of observed EWS traffic and warns that infrequently used applications may not be identified. Any job that runs less often than that, such as a quarter-end export, a year-end archive run, a disaster recovery test or a legal hold collection, was invisible during the window. It will fail on its next run, often when the team that owns it is busiest.
It can be too broad. The same method admitted everything that ran, whether or not anyone approved it. Microsoft's FAQ concedes the list might include apps you weren't aware of. In practice, that can mean a trial tool someone connected, a script left behind by a departed engineer, or an integration that should have been retired years ago. Each one now holds an explicit EWS grant in your tenant, which is the opposite of what the retirement is meant to achieve.
Microsoft does not mark which entries it added, so save a dated export of the list before you change anything. Then work through both directions with this checklist. The usage report covers 90 days at most, so it will not reveal annual jobs either; only the people who own those systems know they exist.
What breaks on April 1, 2027: EWS features with no Microsoft Graph replacement
On April 1, 2027, every remaining EWS call in Exchange Online fails, and three areas will never get a full Microsoft Graph equivalent: public folders, Microsoft 365 Group mailboxes and discovery mailboxes. Archive mailboxes, the gap backup vendors worried about most, are on track to close before then.
Microsoft's deprecation guidance adds a blunt rule: if a capability is missing from its roadmap table, do not plan on a Graph equivalent arriving before EWS is disabled. Its listed dates are targets and can move.
Two cautions apply to backup in particular. Microsoft states that the Graph mailbox import and export APIs are not designed for backup and restore, and it points customers toward Microsoft 365 Backup instead. A vendor's announcement of Graph support may also cover primary mailboxes only, so ask which mailbox types it includes.
Calendar delta queries, notifications and free/busy do not appear as gaps on Microsoft's roadmap. If your integrations depend on them, test the specific Graph calls against your own workloads before you retire the EWS version.
What happens to public folders after April 1, 2027?
Public folders and their content stay in place on April 1, 2027. What ends is programmatic access through EWS, and Graph will never replace it. Microsoft has not published a recommended destination in the guidance reviewed here. Vendors offer two views: MailStore states that Microsoft recommends Microsoft 365 Groups, and CiraSync recommends shared mailboxes.
Choose based on how people use the content today. Then finish the move while EWS still works for your migration tool, because bulk public folder export through Graph is still only a Q4 2026 target.
Will your Microsoft 365 backup keep working after the EWS retirement?
Your backup keeps working only if the vendor moves to Graph before April 1, 2027, or keeps its app IDs on your allow list until it does. Backup, archiving and migration tools carry most of the April risk, because they touch every mailbox type, including the ones Graph will never fully cover.
Vendors' public positions vary widely, and several still depend on EWS today. Everything in this table is the vendor's own statement about its product. If you're already reassessing your platform, compare candidates on how they protect Exchange Online without EWS, alongside the usual RPO and RTO criteria.
The pattern matters more than any single row: vendors still ask you to keep their app IDs on the list, and few publish a date for leaving EWS entirely. That makes archive mailboxes the decision point for most backup and archiving contracts.
If Graph archive support arrives on schedule, and if it doesn't
Microsoft expects archive mailbox support in Graph to reach general availability between late October and early November 2026. Whether it lands, and whether your vendor adopts it, decides your next move.
Microsoft sets no decision date for you. Deciding by the end of January 2027 leaves February and March to replace a vendor or change your archive approach and still test before the cutoff.
Questions to get answered in writing
Send these to every backup, archiving and migration vendor that touches Exchange Online. A vague answer to any of them is an answer in itself.
Which Microsoft apps still use EWS?
Several of Microsoft's own apps still generate EWS traffic, and classic Outlook for Mac needs an allow list entry to keep working. Microsoft is removing EWS from Outlook, Office, Teams and Dynamics 365, but its notices name only some of them, and several common scenarios remain undocumented.
Microsoft does not publish the Office app ID in its EWS notices. Office 365 IT Pros reports it as d3590ed6-52b3-4102-aeff-aad2292ab01c; confirm it against your own usage report before you add it. If any Microsoft app ID shows up in that report, it needs a decision like any other app.
Exchange hybrid and cross-tenant free/busy after the EWS retirement
Exchange Server keeps EWS on-premises, but anything that crosses into Exchange Online loses EWS on the same schedule as everything else. That includes hybrid rich coexistence and calendar sharing with partner companies.
For hybrid, only Exchange Server Subscription Edition with the May 2026 update or later uses Graph for rich coexistence. Older versions lose it permanently in April 2027. Microsoft's hybrid guidance covers the Exchange SE requirements in detail.
Partner sharing moves to Cross-Tenant Access Policy. If those relationships exist because of an acquisition, this is a good moment to revisit whether the tenants should stay separate at all; our tenant consolidation guide covers the tooling.
To see which partner relationships and sharing policies you have today, run these two commands:
How to find every app using EWS in your tenant
The EWS usage report in the Microsoft 365 admin center is the fastest inventory. Go to Reports > Usage > Exchange > EWS usage to see each calling application ID and the EWS operations it used over 7, 30 or 90 days.
The report has three limits. It aggregates data weekly, so a job that ran yesterday may not appear yet. It looks back 90 days at most, which hides anything that runs less often. And it exists only for commercial tenants; government and sovereign tenants use Microsoft's ews-migration-analyzer on GitHub instead.
Step 3 catches a failure that confuses admins. Before the allow list existed, many tenants restricted EWS by client name using the older EwsApplicationAccessPolicy settings. Exchange Online still evaluates those rules alongside the new list, so an app on your new list can still fail because an old rule blocks its client name. Microsoft also warns that blocking by client name can affect REST and Graph connections. Check what you have with this command:
Individual mailboxes can also carry their own EwsEnabled setting through Set-CASMailbox. Turning EWS off for the organization overrides those per-mailbox settings.
EWS allow list mistakes that cause outages
Five documented behaviors of EWSAllowedAppIDs turn routine changes into outages. Each one is easy to trip over during a change that looks harmless.
The commands, exactly as Microsoft documents them:
Microsoft documents no add-only or remove-only syntax. Its Exchange Team post introducing EWSAllowedAppIDs walks through the read, append and write pattern, ending with Set-OrganizationConfig -EwsAllowedAppIDs ($updated -join ","). Shortcut syntax that appears on some blogs isn't in Microsoft's documentation, so test it in a non-production tenant before you trust it.
Baseline Security Mode in the Microsoft 365 admin center offers a second way to maintain the app ID list without PowerShell. The Exchange team also published field notes on testing allow list changes safely in August 2026.
Check your EWS exposure
Six answers tell you what is broken in your tenant today, what stops on April 1, 2027, and which runbook steps apply to you. The checker uses the same Microsoft guidance as the rest of this guide, and it updates as you click.
EWS migration runbook: from now to April 1, 2027
The runbook follows Microsoft's own sequence: inventory, build and validate the list, keep it current, then move each app to Graph. Front-load the discovery work, because every later phase depends on knowing who owns each app ID.
Microsoft sets none of these internal dates. I built them backward from April 1, 2027 so that every replacement runs on its new path for several weeks, including early test runs of quarter-end and annual jobs, before EWS disappears.
Clean up full_access_as_app permissions while you're in there
The app inventory doubles as an access review, and the highest-value target is the full_access_as_app permission. It lets an application reach every mailbox in the tenant through EWS, and it tends to outlive the projects that needed it.
In Microsoft Entra ID, review the API permissions on your app registrations and enterprise applications for Office 365 Exchange Online's full_access_as_app. Microsoft's EWS guidance doesn't publish a discovery script for this, so treat any community script as a starting point and verify its results.
What Microsoft still hasn't confirmed about the EWS retirement
Microsoft has revised its EWS notices several times since February 2026, and several points remain unsettled or contradictory. Re-check these before you act on them, and expect further revisions before April.
One mirror of Microsoft's Message Center reports that the enforcement notice was updated again on October 7, 2026. That revision could not be verified for this guide.
Replacing an EWS-dependent tool?
If your backup, archiving or migration vendor can't commit to a Microsoft Graph date, find and match with vendors that fit your environment. Your information stays anonymous until you choose to talk, and it's always free to you.
FAQ
When does EWS stop working in Exchange Online?
EWS stops working in Exchange Online on April 1, 2027, when Microsoft disables it for every tenant and removes the setting that controls it. Enforcement began on October 1, 2026, and since October 10, 2026 any tenant that keeps EWS on must list each allowed app.
What is EWSAllowedAppIDs?
EWSAllowedAppIDs is the Exchange Online setting that lists the application IDs allowed to use EWS. Since October 10, 2026, a tenant with EWS on blocks every app that isn't on the list, and each write to the setting replaces the entire list.
Can I turn EWS back on in Exchange Online?
Yes, until April 1, 2027, and only for named apps. Set EWSEnabled to True and list those apps in EWSAllowedAppIDs, because True with no list blocks everything. On April 1, 2027, EWS shuts off for good and the setting goes away.
Does the EWS retirement affect Outlook?
It affects some versions. Outlook for Windows should run build 16.0.20430.20092 or later, classic Outlook for Mac needs the Microsoft Office app ID on the allow list, and new Outlook for Mac is unaffected.
Does the EWS retirement affect on-premises Exchange Server?
EWS keeps working inside Exchange Server. Hybrid rich coexistence and sharing with other companies' Exchange Online tenants are affected, and only Exchange Server Subscription Edition with the May 2026 update keeps rich coexistence after April 2027.
Does Apple Mail still work with Exchange Online?
On iPhone and iPad, yes, because they connect through Exchange ActiveSync. On the Mac, Apple Mail, Calendar and Contacts work only while EWS is allowed for them; Apple says a future macOS 27 update will move them to Microsoft Graph but hasn't given a date.
Why are my Kiosk or F3 users getting a 403 error?
Since October 1, 2026, Microsoft blocks EWS for mailboxes licensed only with Exchange Online Kiosk, F1 or F3, and returns HTTP 403. The documented fix is a license with EWS rights, such as Exchange Online Plan 1 or 2, or E3 or E5; allow list entries don't override the license check.
How do I find which apps use EWS?
Open the EWS usage report in the Microsoft 365 admin center under Reports > Usage > Exchange. It shows each app ID and the EWS operations it called over up to 90 days. Government and sovereign tenants use Microsoft's ews-migration-analyzer on GitHub instead.
What replaces EWS?
Microsoft Graph replaces EWS, with the Exchange Admin API covering some management tasks. Microsoft says not to expect any capability missing from its roadmap before April 1, 2027.
What happens to public folders when EWS is retired?
The folders and their content stay, but programmatic access through EWS ends on April 1, 2027, and Microsoft Graph will never offer full public folder access. Bulk public folder import and export through Graph is a Q4 2026 target, which gives you a way to move content out.
Will my Microsoft 365 backup keep working after EWS is retired?
Your backup keeps working only if the vendor moves to Microsoft Graph, or keeps its app IDs on your list until April 1, 2027 and moves before then. Ask specifically about archive mailboxes, public folders and Microsoft 365 Group mailboxes, where Graph support is newest or absent.


