MC1469960: Exchange Online Requires EWSAllowedAppIDs Configuration as EWS Retirement Progresses

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
63
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Tenant AdminsMicrosoft 365 AdminsExchange AdminsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
Timeline for enforcing EWSAllowedAppIDs before EWS retirement has shifted, requiring admins to review configuration and application dependencies. Action is mandatory for tenants that still use EWS to avoid disruptions, with planning and validation tasks needed well before the phased rollout. User impact is minor and indirect, mostly affecting apps reliant on EWS rather than end-user interaction. Urgency is high due to clear start date and risk of service interruption if no action is taken.
78
🛡️ Admin Impact
18
👥 User Impact
72
Urgency
65
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Exchange Online is tightening control over EWS access. Review and configure EWSAllowedAppIDs now to avoid unexpected disruptions during the EWS retirement rollout.
👥

END USERS

No major end-user change expected.
🛡️

IT ADMINS

Check whether EWS is still in use and configure or validate your EWSAllowedAppIDs list before October.
📅

ROLLOUT TIMELINE

Upcoming:
October 2026

📢 Official Microsoft Message Center Announcement


(Updated) Microsoft Exchange Online: Review and configure EWSAllowedAppIDs before Exchange Web Services access changes
Message ID: MC1469960 (Updated)

Updated September 11, 2026: We have updated the timeline. Thank you for your patience.

[What and why]

As part of the final phase of Exchange Web Services (EWS) retirement, Microsoft is updating how the EWSAllowedAppIDs setting is applied in Exchange Online. This change is designed to help organizations identify and manage applications that still require EWS access while reducing the risk of unexpected service disruption.

Organizations that continue to use EWS should review and maintain their own EWSAllowedAppIDs list. If a tenant administrator has already configured this list, Microsoft will not overwrite or modify it.

Beginning on October 1, 2026, Microsoft will start enabling this updated behavior by cloud as part of the EWS retirement rollout.

[Rollout schedule]

  • Worldwide, GCC, GCC High, DoD: Beginning in early October 2026 and expected to complete by late April 2027

The updated behavior will apply when the rollout reaches your cloud.

[Impact on your organization]

Who is affected

  • Organizations that continue to use Exchange Web Services (EWS)
  • Exchange Online administrators responsible for managing EWS access
  • Tenants with EWSEnabled set to True or Null

Platforms and services

  • Exchange Online
  • Exchange Web Services (EWS)

What will happen

After the updated behavior is enabled in a cloud:

  • EWS will require a configured EWSAllowedAppIDs list when EWSEnabled is set to True.
  • Before enabling the change, Microsoft will ensure that tenants with EWSEnabled already set to True have an EWSAllowedAppIDs list.
  • If a customer-managed list does not exist, Microsoft will generate a list based on EWS application usage observed during the previous 60 days to help reduce the risk of service interruption.
  • Microsoft-generated lists may omit applications that run infrequently and may include applications that no longer require EWS access.
  • If EWSEnabled remains Null, Microsoft will populate EWSAllowedAppIDs only when a customer-managed list does not already exist. This will occur shortly before Microsoft updates EWSEnabled to False as part of the retirement rollout.
  • Microsoft will not modify an EWSAllowedAppIDs list that has already been configured by a tenant administrator.

[Action required and recommendations]

If your organization still relies on EWS, we recommend taking the following actions as soon as possible:

  • Review EWS usage from the previous 60 days and identify all applications that require continued EWS access, including applications with infrequent usage patterns.
  • Configure and validate your EWSAllowedAppIDs list before the rollout reaches your cloud.
  • Ensure EWSEnabled is set to True if continued EWS access is required.
  • Keep the EWSAllowedAppIDs list current as applications are added, removed, or migrated away from EWS.
  • Plan for up to a 24-hour propagation delay after changes are made to the EWSAllowedAppIDs list.

Microsoft’s safeguard helps reduce the risk of service disruption but does not replace customer review and validation of EWSAllowedAppIDs.

We also recommend continuing plans to migrate applications from EWS to Microsoft Graph before EWS retirement is completed.

Learn more

[Compliance considerations]

No compliance considerations identified, review as appropriate for your organization.

Source: Microsoft Message Center • Analysed by MWPro

<<< [MC1469960] Archive
Tooltip: View earlier revisions of this post

Share This Update