MC1485116 - Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs
Microsoft 365 Message Center announcement MC1485116.
MS Message Center's Summary
Microsoft is enforcing strict application allow listing for Exchange Web Services in Exchange Online starting in October 2026. Setting the basic enablement flag to true will no longer suffice. Administrators must audit current application dependencies, review any automatically populated entries, and configure explicit application IDs to prevent service disruptions while planning migrations to Microsoft Graph.
- Administrator impact
- Administrators must audit Exchange Web Services dependencies and configure explicit allow lists before enforcement begins.
- End user impact
- End users may experience connection failures in legacy applications or tools if required application IDs are omitted from the allow list.
- Importance
- 9/10: This change introduces mandatory configuration requirements that can break application connectivity and core mail features if administrators do not act.
Exchange Online EWS, Your Time is Almost Up
Impact of Exchange Online EWS Deprecation on Hybrid Rich Coexistence and Cross org Sharing
Microsoft Summary
Starting October 10, 2026, Exchange Online tenants must configure EWSAllowedAppIDs to allow Exchange Web Services (EWS) access; EWSEnabled=True alone will no longer suffice. Microsoft will auto-populate allow lists for some tenants, but organizations must review, maintain, and migrate from EWS to Microsoft Graph.
- Message Center ID
- MC1485116
- Category
- stay Informed
- Severity
- normal
- Services
- Exchange Online
- Tags
- User impact, Admin impact, Retirement
- Published
- 2026-10-01
- Last updated
- 2026-10-01
- Expires
- 2027-09-01
[What and why] As previously communicated in MC1466860 and MC1447678 , Microsoft is continuing the retirement of Exchange Web Services (EWS) in Exchange Online. Beginning October 10, 2026, setting EWSEnabled=True will no longer be sufficient to allow EWS access for affected Worldwide tenants. Organizations that require EWS must configure EWSAllowedAppIDs to specify which applications are permitted to access EWS. This change is part of the final phase of EWS retirement and is intended to help organizations identify EWS dependencies, reduce service disruption, and support migration planning. [Rollout schedule] Worldwide, GCC, GCC High, DoD: Beginning in early October 2026 and expected to complete by early July 2027 Key milestones for Worldwide tenants with EWSEnabled=True and no configured EWSAllowedAppIDs list: Date Milestone October 2, 2026 Microsoft identifies affected Worldwide tenants. After this date, tenants that enable EWS must configure EWSAllowedAppIDs themselves. October 8-9, 2026 Microsoft creates and populates EWSAllowedAppIDs for qualifying Worldwide tenants based on EWS activity observed during the previous 60 days. October 10, 2026 EWSAllowedAPPIDs becomes required when EWSEnabled=True. Applications note included in the allow list may lose access to EWS. [Impact on your organization] Who is affected Exchange Online administrators Organizations that continue to use applications or services that depend on EWS Tenants with EWSEnabled=True Platforms and services Exchange Online Exchange Web Services (EWS) What will happen Beginning October 10, 2026, affected Worldwide tenants with EWSEnabled=True must have a configured EWSAllowedAppIDs allow list. Applications not included in the allow list may lose access to EWS. For identified Worldwide tenants with EWSEnabled=True and no configured EWSAllowedAppIDs list on October 3 2026, Microsoft creates and populates an allow list using EWS activity observed during the previous 60 days. Infrequently used applications may not be identified. Cross-tenant organization relationships are not affected by the EWSAllowedAppIDs requirement. Organizations remain responsible for reviewing, validating, and maintaining EWSAllowedAppIDs. EWSAllowedAppIDs is a replacement list. Ensure all required AppIDs are included whenever the configuration is updated. Microsoft applications and scenarios that may generate EWS traffic include Outlook for Windows, Classic Outlook for Mac, Excel Power Query, Power BI, and Exchange Server hybrid scenarios. Outlook for Windows customers should be on August 2026 build 16.0.20430.20092 or later. If EWS-related issues continue after disabling EWS, the cause may be customer-forced configuration. Test whether blocking EWS for the Office client AppID is possible without impact. New Outlook for Mac is not affected. If your organization continues to use Classic Outlook for Mac, ensure the Microsoft Office AppID is included in EWSAllowedAppIDs. Tenants with EWSEnabled not configured (Null) remain subject to Microsoft's phased EWS retirement process and will have EWS disabled as part of that rollout. Organizations with EWSEnabled=True and a configured EWSAllowedAppIDs allow list will not have their EWSEnabled setting modified by Microsoft before April 2027. [Action required and recommendations] If your organization relies on EWS: Review EWS usage reports and identify applications and services that require continued EWS access. Configure and validate an EWSAllowedAppIDs allow list before October 10, 2026. Include Microsoft first-party applications that continue to rely on EWS if they appear in your usage reporting. Ensure all required AppIDs are included whenever EWSAllowedAppIDs is updated. Keep the allow list current as applications are added, removed, or migrated away from EWS. Enable EWS only when required for approved applications. Continue planning migration from EWS to Microsoft Graph where possible. To verify the configured allow list: Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs Allow up to 24 hours for EWSAllowedAppIDs changes to take effect and approximately one hour for EWSEnabled changes. Important: EWSAllowList is unrelated to EWS retirement and does not replace EWSAllowedAppIDs. Learn more Exchange Online EWS, Your Time is Almost Up | Microsoft Community Hub How to revert the Outlook Desktop WebView based Room Finder to the legacy Room Finder | Microsoft Support Impact of Exchange Online EWS Deprecation on Hybrid Rich Coexistence and Cross-org Sharing | Microsoft Community Hub Notes from the field: testing EWSAllowedAppIDs safely | Microsoft Community Hub [Compliance considerations] Question Answer Does this change include an admin control? Yes. EWSAllowedAppIDs introduces a tenant-level administrative control that allows Exchange Online administrators to explicitly define which applications are permitted to access EWS. Does this change alter how existing customer data is accessed? Yes. The change modifies how applications are authorized to access Exchange Online data through EWS by requiring administrators to explicitly allow approved application IDs as retirement enforcement begins. Does this change alter how admins monitor, manage, or demonstrate compliance-related activities? Yes. Administrators must identify EWS dependencies, configure and maintain an EWSAllowedAppIDs allow list, and validate application access as part of preparing for EWS retirement.