Microsoft Exchange Online: Review and configure EWSAllowedAppIDs before Exchange Web Services access changes
Microsoft is updating how EWSAllowedAppIDs is applied in Exchange Online as part of EWS retirement starting October 1, 2026. Organizations using EWS must review and configure their EWSAllowedAppIDs list to avoid service disruption and plan to migrate to Microsoft Graph before retirement completes. As part of the final phase of Exchange Web Services (EWS) retirement, Microsoft is updating how the EWSAllowedAppIDs setting is applied in Exchange Online. This change is designed to help organizations identify and manage applications that still require EWS access while reducing the risk of unexpected service disruption. Organizations that continue to use EWS should review and maintain their own EWSAllowedAppIDs list. If a tenant administrator has already configured this list, Microsoft will not overwrite or modify it. Beginning on October 1, 2026, Microsoft will start enabling this updated behavior by cloud as part of the EWS retirement rollout. Rollout schedule Worldwide, GCC, GCC High, DoD: Beginning in early October 2026 and expected to complete by late June 2027 The updated behavior will apply when the rollout reaches your cloud. Impact on your organization Who is affected Organizations that continue to use Exchange Web Services (EWS) Exchange Online administrators responsible for managing EWS access Tenants with EWSEnabled set to True or Null Platforms and services Exchange Online Exchange Web Services (EWS) What will happen After the updated behavior is enabled in a cloud: EWS will require a configured EWSAllowedAppIDs list when EWSEnabled is set to True. Before enabling the change, Microsoft will ensure that tenants with EWSEnabled already set to True have an EWSAllowedAppIDs list. If a customer-managed list does not exist, Microsoft will generate a list based on EWS application usage observed during the previous 60 days to help reduce the risk of service interruption. Microsoft-generated lists may omit applications that run infrequently and may include applications that no longer require EWS access. If EWSEnabled remains Null, Microsoft will populate EWSAllowedAppIDs only when a customer-managed list does not already exist. This will occur shortly before Microsoft updates EWSEnabled to False as part of the retirement rollout. Microsoft will not modify an EWSAllowedAppIDs list that has already […]
The post Microsoft Exchange Online: Review and configure EWSAllowedAppIDs before Exchange Web Services access changes appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Exchange Online: Review and configure EWSAllowedAppIDs before Exchange Web Services access changes
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.