MC1447678: Exchange Online Adds EWSAllowedAppIDs to Manage Access Before EWS Retirement

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
63
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Exchange AdminsMicrosoft 365 AdminsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
The announcement introduces EWSAllowedAppIDs, a new administrative control required to manage EWS dependencies ahead of retirement enforcement in October 2026. Admin impact is high because organizations must inventory usage, configure and validate allow lists, and adjust policies to prevent disruption. User impact is moderate since application access to Exchange data through EWS may be blocked if configuration is incomplete. Urgency is significant as preparation should begin well before the enforcement date to avoid service issues.
80
🛡️ Admin Impact
20
👥 User Impact
65
Urgency
70
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

A new setting, EWSAllowedAppIDs, lets you create an allow list for apps using Exchange Web Services. This is key for preparing before EWS retirement in 2026–2027.
👥

END USERS

No major end-user change expected.
🛡️

IT ADMINS

Inventory EWS usage and configure EWSAllowedAppIDs for any apps that need access after October 2026.
📅

ROLLOUT TIMELINE

Available:
Now

📢 Official Microsoft Message Center Announcement


Microsoft Exchange Online: Prepare for Exchange Web Services retirement with EWSAllowedAppIDs
Message ID: MC1447678

[What and why]

Exchange Web Services (EWS) in Exchange Online will begin retirement on October 1, 2026, with full retirement beginning April 1, 2027.

To help organizations prepare, Microsoft has released EWSAllowedAppIDs, a new Exchange Online configuration that allows administrators to create an allow list of application IDs that are permitted to use EWS.

This capability helps administrators identify remaining EWS dependencies, limit EWS access to approved applications, and reduce the risk of service disruption as EWS retirement enforcement begins.

This feature is available today.

[Rollout schedule]

General Availability (Worldwide): Available as of late July 2026

General Availability (GCC): Available as of late July 2026

Retirement milestones:

  • October 1, 2026: Retirement enforcement begins in Exchange Online
  • April 1, 2027: Full retirement begins

[Impact on your organization]

Who is affected

  • Exchange Online administrators
  • Organizations that continue to use applications or services that depend on EWS

Platforms and services

  • Exchange Online
  • Exchange Web Services (EWS)

What will happen

EWSAllowedAppIDs is a tenant-level allow list that enables administrators to explicitly specify which applications can continue using EWS.

Prior to October 2026:

  • If EWSEnabled is not configured (Null), all EWS traffic is allowed.
  • If EWSEnabled=True and no allow list is configured, all EWS traffic is allowed.
  • If EWSEnabled=True and an allow list is configured, only applications included in the allow list can use EWS.
  • If EWSEnabled=False, all EWS traffic is blocked.

Beginning in October 2026:

  • If EWSEnabled=True and no allow list is configured, all EWS traffic will be blocked.
  • If EWSEnabled=True and an allow list is configured, only applications included in the allow list can use EWS.
  • If EWSEnabled=False, all EWS traffic will be blocked.
  • Tenants with EWSEnabled not configured (Null) remain subject to Microsoft’s phased retirement process and will have EWS disabled as part of that rollout.

The most important change administrators should understand is that, beginning with retirement enforcement, setting EWSEnabled=True without configuring EWSAllowedAppIDs will no longer permit unrestricted EWS access.

Organizations that require EWS after October 2026 should ensure an EWSAllowedAppIDs allow list is configured and validated before enforcement begins.

Organizations that have EWSEnabled=True and a configured EWSAllowedAppIDs allow list will not have their EWSEnabled setting modified by Microsoft before April 2027.

[Action required and recommendations]

We strongly recommend that Exchange Online administrators begin preparation immediately.

1. Inventory EWS usage

Identify applications and services currently using EWS in your organization.

2. Create and validate an allow list

Create an EWSAllowedAppIDs allow list containing applications that must continue using EWS.

Important considerations:

  • Applications appearing in EWS usage reports that you intend to continue using should be included in the allow list.
  • Microsoft first-party applications that continue to rely on EWS must also be included if they appear in your usage reporting.
  • Setting EWSAllowedAppIDs replaces the existing list. Ensure all required App IDs are included when updating the configuration.

Verify the configured allow list: Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs

The use of RetrieveEwsOperationAccessPolicy is required for performance reasons. The EWSAllowedAppIDs list is only retrieved when explicitly requested. Changes to EWSAllowedAppIDs can take up to 24 hours to take effect. Allow sufficient time after updating the allow list before validating application access or troubleshooting connectivity issues.

3. Prepare for retirement enforcement

Before October 2026:

  • Validate your EWS dependencies.
  • Confirm required applications are included in EWSAllowedAppIDs.
  • Enable EWS only if required for approved applications.

Organizations that complete this work before retirement enforcement begins are less likely to experience service disruption.

Learn more

[Compliance considerations]

QuestionAnswer
Does this change include an admin control?Yes. EWSAllowedAppIDs introduces a new tenant-level administrative control that allows Exchange Online administrators to explicitly define which applications are permitted to access Exchange Web Services (EWS).
Does this change alter how customer data is accessed?Yes. The change modifies how applications are authorized to access Exchange Online data through EWS by requiring administrators to explicitly allow approved application IDs as retirement enforcement begins.
Does this change alter how admins monitor, manage, or demonstrate compliance-related activities?Yes. Administrators must identify EWS dependencies, configure and maintain an EWSAllowedAppIDs allow list, and validate application access as part of preparing for EWS retirement.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update