What and why
As previously communicated in MC1466860 and MC1447678, Microsoft is continuing the retirement of Exchange Web Services (EWS) in Exchange Online.
Beginning October 10, 2026, setting EWSEnabled=True will no longer be sufficient to allow EWS access for affected Worldwide tenants. Organizations that require EWS must configure EWSAllowedAppIDs to specify which applications are permitted to access EWS.
This change is part of the final phase of EWS retirement and is intended to help organizations identify EWS dependencies, reduce service disruption, and support migration planning.
Rollout schedule
- Worldwide, GCC, GCC High, DoD: Beginning in early October 2026 and expected to complete by early July 2027
Key milestones for Worldwide tenants with EWSEnabled=True and no configured EWSAllowedAppIDs list:
| Date | Milestone |
| October 2, 2026 | Microsoft identifies affected Worldwide tenants. After this date, tenants that enable EWS must configure EWSAllowedAppIDs themselves. |
| October 8-9, 2026 | Microsoft creates and populates EWSAllowedAppIDs for qualifying Worldwide tenants based on EWS activity observed during the previous 60 days. |
| October 10, 2026 | EWSAllowedAPPIDs becomes required when EWSEnabled=True. Applications note included in the allow list may lose access to EWS. |
Impact on your organization
Who is affected
- Exchange Online administrators
- Organizations that continue to use applications or services that depend on EWS
- Tenants with EWSEnabled=True
Platforms and services
- Exchange Online
- Exchange Web Services (EWS)
What will happen
- Beginning October 10, 2026, affected Worldwide tenants with EWSEnabled=True must have a configured EWSAllowedAppIDs allow list. Applications not included in the allow list may lose access to EWS.
- For identified Worldwide tenants with EWSEnabled=True and no configured EWSAllowedAppIDs list on October 3 2026, Microsoft creates and populates an allow list using EWS activity observed during the previous 60 days. Infrequently used applications may not be identified.
- Cross-tenant organization relationships are not affected by the EWSAllowedAppIDs requirement.
- Organizations remain responsible for reviewing, validating, and maintaining EWSAllowedAppIDs.
- EWSAllowedAppIDs is a replacement list. Ensure all required AppIDs are included whenever the configuration is updated.
- Microsoft applications and scenarios that may generate EWS traffic include Outlook for Windows, Classic Outlook for Mac, Excel Power Query, Power BI, and Exchange Server hybrid scenarios.
- Outlook for Windows customers should be on August 2026 build 16.0.20430.20092 or later. If EWS-related issues continue after disabling EWS, the cause may be customer-forced configuration. Test whether blocking EWS for the Office client AppID is possible without impact.
- New Outlook for Mac is not affected. If your organization continues to use Classic Outlook for Mac, ensure the Microsoft Office AppID is included in EWSAllowedAppIDs.
- Tenants with EWSEnabled not configured (Null) remain subject to Microsoft's phased EWS retirement process and will have EWS disabled as part of that rollout.
- Organizations with EWSEnabled=True and a configured EWSAllowedAppIDs allow list will not have their EWSEnabled setting modified by Microsoft before April 2027.
Action required and recommendations
If your organization relies on EWS:
- Review EWS usage reports and identify applications and services that require continued EWS access.
- Configure and validate an EWSAllowedAppIDs allow list before October 10, 2026.
- Include Microsoft first-party applications that continue to rely on EWS if they appear in your usage reporting.
- Ensure all required AppIDs are included whenever EWSAllowedAppIDs is updated.
- Keep the allow list current as applications are added, removed, or migrated away from EWS.
- Enable EWS only when required for approved applications.
- Continue planning migration from EWS to Microsoft Graph where possible.
To verify the configured allow list: Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs
Allow up to 24 hours for EWSAllowedAppIDs changes to take effect and approximately one hour for EWSEnabled changes.
Important: EWSAllowList is unrelated to EWS retirement and does not replace EWSAllowedAppIDs.
Learn more
Compliance considerations
| Question | Answer |
| Does this change include an admin control? | Yes. EWSAllowedAppIDs introduces a tenant-level administrative control that allows Exchange Online administrators to explicitly define which applications are permitted to access EWS. |
| Does this change alter how existing customer data is accessed? | Yes. The change modifies how applications are authorized to access Exchange Online data through EWS by requiring administrators to explicitly allow approved application IDs as retirement enforcement begins. |
| Does this change alter how admins monitor, manage, or demonstrate compliance-related activities? | Yes. Administrators must identify EWS dependencies, configure and maintain an EWSAllowedAppIDs allow list, and validate application access as part of preparing for EWS retirement. |