The short answer
If your product or internal tooling reads Exchange Online mailboxes, calendars or contacts through EWS, it now has a hard expiry date: April 1, 2027. Before that, a tenant admin can keep it alive only by putting your app on an allow list, and from October 10, 2026, “EWS enabled” without that list no longer works.
This is not a security patch you can apply in an afternoon. It is an API migration: EWS SOAP calls have to be rewritten against Microsoft Graph, with new permissions, throttling rules and data shapes. Teams that own mail or calendar integrations should treat it as an API development project with a fixed deadline, not a configuration change.
What changed on October 1?
EWS is the SOAP-based API that shipped with Exchange Server 2007 and became the default way for third-party tools to talk to Exchange. Microsoft stopped adding features to it in 2018 and announced its retirement from Exchange Online in 2023. On October 1, 2026, the Exchange Team posted that the deprecation “starts today” and laid out the first enforcement steps.
The key change is that switching EWS on is no longer a blanket permission. An admin who sets EWSEnabled to True must also maintain EWSAllowedAppIDs, a list of the application IDs allowed to call EWS. Anything not on the list is refused. Microsoft says changes to the allow list take 24 hours to apply, and changes to EWSEnabled usually under an hour but up to four.
What is the EWS retirement timeline?
Microsoft is rolling the change out in stages, starting with its worldwide multi-tenant cloud; tenants in other clouds get their own timelines through Message Center.
- October 2, 2026: Microsoft records tenants that have EWSEnabled = True but no allow list.
- October 8–9: for those tenants, Microsoft creates EWSAllowedAppIDs and fills it with the AppIDs that called EWS in the previous 60 days.
- From October 10: the allow list is required whenever EWS is enabled.
- Second phase: tenants that never touched the EWSEnabled setting are selected in batches, warned 7 days ahead in Message Center and switched to EWSEnabled = False. Microsoft pre-fills their allow list from 60 days of usage first, so an admin can switch EWS back on if needed.
- April 1, 2027: EWS is shut down permanently. As The Register reports, there will be no exceptions; neither EWSEnabled nor the allow list will restore access.
Which apps and teams are affected?
Anything that calls EWS against Exchange Online: CRM and help-desk mail sync, calendar and room-booking tools, archiving and backup products, e-discovery and compliance connectors, migration tools, and the many internal scripts written years ago and forgotten. Some Microsoft software is also on the list. The Exchange Team says Outlook for Windows should be on build 16.0.20430.20092 (August 2026) or later, classic Outlook for Mac needs the “Microsoft Office” AppID on the allow list, Excel Power Query has its own guidance, and a Power BI update is still pending.
The hardest part, as an integration vendor told The Register, is that many organizations do not have a complete inventory of what calls EWS. The 60-day usage data that Microsoft uses to pre-fill allow lists is a useful starting point, but quarterly or yearly jobs may not show up in it.
What it means for US & EU software teams
First, SaaS vendors carry the risk for their customers. If your product connects to customers’ Microsoft 365 tenants through EWS, every customer admin now has to allow-list your AppID, and each one who does not will see your integration break. That is a support load now and a churn risk in April 2027.
Second, Graph is not a drop-in swap. Graph uses REST and different permission scopes, so customers must grant new admin consent. Its throttling, paging and change-notification models differ from EWS, and some EWS operations have no exact Graph equivalent. Each call needs to be mapped, and gaps need a design decision.
Third, permissions are a compliance question. Moving to Graph is a chance to replace broad mailbox access with narrower scopes and application access policies. For teams in FinTech or HealthTech that answer to GDPR, HIPAA or SOC 2 auditors, least-privilege access to mail data is easier to defend than legacy full-mailbox impersonation.
What to do now
- Find every EWS caller. Pull the EWS usage report in the Microsoft 365 admin center and compare it with your own code search for EWS libraries and endpoints, including rarely run jobs.
- Check the allow list. Make sure each app you still need is in EWSAllowedAppIDs before October 10, and remember changes take up to 24 hours.
- Watch Message Center. If your tenant never set EWSEnabled, a 7-day warning is the only notice before EWS is switched off.
- Map EWS operations to Graph. List each call, its Graph equivalent and any gap; decide early how to handle the gaps.
- Plan consent and permissions. Prepare new Entra ID app registrations and narrow Graph scopes, and tell customers what they will be asked to approve.
- Set an internal deadline. Aim to finish migration and testing well before April 1, 2027, leaving time for customer rollouts.
Frequently asked questions
When does Exchange Web Services stop working in Exchange Online?
Microsoft started the phased retirement on October 1, 2026. From October 10, 2026, tenants that keep EWS enabled must list approved apps in EWSAllowedAppIDs. On April 1, 2027, EWS in Exchange Online is permanently disabled for all tenants, and no setting will restore it.
Does the EWS retirement affect on-premises Exchange Server?
No. The retirement applies to Exchange Online. EWS in on-premises Exchange Server is not being removed by this change, although hybrid features that rely on Exchange Online EWS are affected and Microsoft has published separate guidance for them.
What is EWSAllowedAppIDs?
It is a tenant-level allow list of application IDs that may keep calling EWS during the retirement window. From October 10, 2026, setting EWSEnabled to True is no longer enough on its own; apps not on the list are blocked. Changes to the list take up to 24 hours to apply.
What replaces EWS?
Microsoft Graph is the replacement API for mail, calendar and contacts in Exchange Online. Most EWS operations have Graph equivalents, but some gaps remain, so each integration should be mapped call by call before migration.
Can we just add our app to the allow list and wait?
Only until April 1, 2027. The allow list buys time to migrate; it does not extend EWS beyond the final date. Teams that rely on it should plan the move to Microsoft Graph now and finish testing well before the cutoff.
Sources
Microsoft Exchange Team — EWS Deprecation Is Here: What This Means To You (October 1, 2026)
Microsoft Exchange Team — Introducing EWSAllowedAppIDs: Preparing for the final phase of EWS retirement
The Register — Exchange Web Services enters the final stretch before Microsoft pulls access
TechRadar — Microsoft starts the countdown for the end of Exchange Web Services