Microsoft Exchange Online: Prepare for Exchange Web Services retirement with EWSAllowedAppIDs
Exchange Web Services (EWS) in Exchange Online will retire starting October 1, 2026, with full retirement by April 1, 2027. Microsoft introduced EWSAllowedAppIDs, allowing admins to create an allow list of approved apps to manage EWS access and reduce disruption. Immediate preparation is recommended. Exchange Web Services (EWS) in Exchange Online will begin retirement on October 1, 2026, with full retirement beginning April 1, 2027. To help organizations prepare, Microsoft has released EWSAllowedAppIDs, a new Exchange Online configuration that allows administrators to create an allow list of application IDs that are permitted to use EWS. This capability helps administrators identify remaining EWS dependencies, limit EWS access to approved applications, and reduce the risk of service disruption as EWS retirement enforcement begins. This feature is available today. Rollout schedule General Availability (Worldwide): Available as of late July 2026 General Availability (GCC): Available as of late July 2026 Retirement milestones: October 1, 2026: Retirement enforcement begins in Exchange Online April 1, 2027: Full retirement begins Impact on your organization Who is affected Exchange Online administrators Organizations that continue to use applications or services that depend on EWS Platforms and services Exchange Online Exchange Web Services (EWS) What will happen EWSAllowedAppIDs is a tenant-level allow list that enables administrators to explicitly specify which applications can continue using EWS. Prior to October 2026: If EWSEnabled is not configured (Null), all EWS traffic is allowed. If EWSEnabled=True and no allow list is configured, all EWS traffic is allowed. If EWSEnabled=True and an allow list is configured, only applications included in the allow list can use EWS. If EWSEnabled=False, all EWS traffic is blocked. Beginning in October 2026: If EWSEnabled=True and no allow list is configured, all EWS traffic will be blocked. If EWSEnabled=True and an allow list is configured, only applications included in the allow list can use EWS. If EWSEnabled=False, all EWS traffic will be blocked. Tenants with EWSEnabled not configured (Null) remain subject to Microsoft’s phased retirement process and will have EWS disabled as part of that rollout. The most important change administrators should understand is that, beginning with retirement enforcement, setting EWSEnabled=True […]
The post Microsoft Exchange Online: Prepare for Exchange Web Services retirement with EWSAllowedAppIDs appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Exchange Online: Prepare for Exchange Web Services retirement with EWSAllowedAppIDs
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Dynamics 365 Contact Center – Manage overnight shifts as a single continuous schedule
We are announcing the ability to manage overnight shifts as a single continuous schedule in Dynamics 365 Contact Center. This feature will rea...
Manage who can upload advanced agents and plugins
Starting September 25, Microsoft 365 admins can control who uploads advanced Copilot agents and plugins, limiting access to specific users or ...
Microsoft 365 Copilot: Insights Copilot Analytics cowork adoption impact
Microsoft 365 Copilot now includes Cowork adoption and impact insights in the Consumption dashboard and Viva Insights Advanced Insights. Avail...
Writing Blocks in M365 Copilot
Microsoft 365 Copilot will introduce Writing blocks by mid-September 2026, enabling users to create and refine longer-form content like emails...
Outlook: Change the organizer of meetings
Microsoft is introducing a feature to change the organizer of eligible Outlook meetings, allowing transfer of meeting ownership within an orga...
Code Blocks in M365 Copilot
Microsoft 365 Copilot will support inline previews of code blocks, charts, and diagrams within conversations, eliminating the need for a separ...
Microsoft SharePoint: PowerShell support for brand fonts deletion
Microsoft SharePoint will introduce the Remove-SPOFontFile PowerShell cmdlet by mid-October 2026, allowing admins to delete brand fonts across...
[Outlook Mobile] Purview Data Loss Prevention support for Calendar Events
Outlook for iOS and Android will support Microsoft Purview Data Loss Prevention for calendar events, helping prevent sensitive data sharing in...
[Outlook Mac] Purview Data Loss Prevention support for Calendar Events
Outlook for Mac will support Microsoft Purview Data Loss Prevention for calendar events, detecting sensitive info in meeting details to preven...
[Outlook Mobile] Purview DLP Wait-on-Send Support
Outlook for iOS and Android will support Microsoft Purview DLP wait-on-send policies, allowing organizations to require and configure a wait t...