Microsoft EWS Retirement: Key Dates and What to Do Next
Microsoft is retiring Exchange Web Services (EWS) in Exchange Online in two phases — a controlled, tenant-by-tenant disablement starting October 1, 2026, and a full, permanent shutdown on April 1, 2027 (MC1227454, MC1447678).
If EWS is left on with no AppID Allow List configured, all EWS traffic gets blocked automatically once enforcement begins. Kiosk, F1, and F3 licensed mailboxes lose EWS entirely regardless of any allow list (MC1191578).
The fix: configure EWSAllowedAppIDs and set EWSEnabled=True before September 30, 2026, or accept the block.
Why Is Exchange Web Services (EWS) Being Retired?
EWS is a nearly 20-year-old protocol that no longer meets Microsoft's current security bar, and the January 2024 Midnight Blizzard nation-state attack accelerated its shutdown. Microsoft first flagged EWS as deprecated back in 2018, and in 2023 set October 2026 as the disablement date. The Midnight Blizzard security incident in January 2024 involved EWS and widened the retirement's scope from third-party applications to Microsoft's own products too, including Outlook, Office, Teams, and Dynamics 365. Microsoft Graph has since reached near-complete feature parity with EWS for the vast majority of scenarios, per the official deprecation page.
Importantly, this retirement applies only to Exchange Online and Microsoft 365. There are no changes to EWS in on-premises Exchange Server.
What Are the Key EWS Retirement Dates? (MC1227454, MC1447678)
There are two hard dates: October 1, 2026 for phased disablement, and April 1, 2027 for full, permanent shutdown with no admin override.
Microsoft sets out the phased disablement process and final shutdown in its Exchange Team announcement, Exchange Online EWS, Your Time is Almost Up.
- Now through September 30, 2026 — Preparation window: EWS remains available. Admins should review usage, build an AppID Allow List, and start migrating apps to Microsoft Graph.
- October 1, 2026 — Phased disablement begins (MC1227454): Any tenant still running EWSEnabled=Null gets switched to False automatically, blocking EWS for every app in that tenant until an admin re-enables it.
- September 30, 2026 — Act-by date on MC1447678: Configure your AppID Allow List and set EWSEnabled=True by this date and your tenant is excluded from the automatic October 1 switch to False.
- April 1, 2027 — Full retirement: EWS is fully and permanently disabled. The ability for tenant admins to control EWSEnabled is removed entirely. Microsoft has confirmed there will be no exceptions past this date.
How Does EWS Access Change Before and After October 2026?
The behaviour of EWSEnabled and the AppID Allow List flips from permissive to restrictive on October 1, 2026 — the same settings produce a different outcome depending on the date.
| EWSEnabled Value | AppID Allow List State | Behaviour Before October 2026 | Behaviour From October 2026 |
|---|---|---|---|
| Null (default) | Ignored | All EWS traffic allowed | Changes to False automatically — all EWS traffic blocked, unless you've already set True |
| True | Empty or null | All EWS traffic allowed | All EWS traffic blocked |
| True | Populated | Only listed App IDs allowed | Only listed App IDs allowed |
| False | Any | All EWS traffic blocked | All EWS traffic blocked |
For the AppID-based access model and hybrid considerations, see Microsoft’s EWSAllowedAppIDs guidance. The PowerShell settings are documented in Microsoft Learn: Control access to EWS in Exchange.
One nuance worth flagging: cross-tenant Organization Relationship traffic — the mechanism behind Free/Busy, MailTips, and calendar sharing between tenants — isn't gated by the AppID Allow List either side of October 2026. That traffic is moving separately onto Cross-Tenant Access Policy, with worldwide completion targeted for September 1, 2026.
Why Do Some Tenants See Different EWS Deadlines? (MC1191578, MC1469960)
Not every organisation hits the same wall at the same time — licence tier, hybrid topology, and whether you've built your own allow list all change the outcome.
- Standard tenants follow the general MC1227454 / MC1447678 timeline and can keep specific apps working past October 2026 via EWSAllowedAppIDs.
- Tenants that take no action by end of September 2026 get an AppID Allow List built for them automatically, based on the tenant's own EWS usage from the last 60 days (MC1469960). It's a safety net, not a substitute — apps that only call EWS occasionally can fall outside that 60-day window and get left off the list.
- Kiosk, F1, and F3 licensed mailboxes lose EWS access entirely from October 1, 2026, and no AppID Allow List changes that (MC1191578). The only remediation is a licence upgrade to a plan with EWS access rights.
- Hybrid tenants aren't off the hook either. On-premises mailboxes can keep using EWS indefinitely, but cloud mailboxes must move to Graph. Only Exchange SE supports Graph-based Rich Coexistence for hybrid calls into Exchange Online, so hybrid customers on older on-premises versions need to move to Exchange SE, or add their dedicated hybrid app to EWSAllowedAppIDs as a bridge before April 1, 2027.
(This is exactly the kind of tenant-specific nuance that gets missed in a generic Message Center scan — ChangePilot tracks items like MC1447678 and MC1469960 against your tenant's actual configuration, not just the headline announcement.)
What Should Admins Do Before September 30, 2026?
Inventory who's using EWS, build your own AppID Allow List rather than waiting for Microsoft's, and set EWSEnabled=True before the deadline.
- Pull your tenant's EWS usage:
Microsoft 365 admin center → Reports → Usage → Exchange → EWS usage, or go directly via EWS Usage Reports. - Identify every App ID showing usage, and match unfamiliar ones back to a real application — Microsoft's own notes from the field on finding EWS app usage is a good starting point.
- Build your own allow list using Microsoft’s documented EwsAllowedAppIDs command rather than relying on Microsoft's automatic one:
Set-OrganizationConfig -EwsAllowedAppIDs "11111111-2222-3333-4444-555555555555,aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee" - Turn EWS on for the allow-listed apps:
Set-OrganizationConfig -EwsEnabled $true - Confirm what’s actually configured using Microsoft’s EWS configuration checks:
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs - Do steps 3–5 before September 30, 2026 — MC1447678's own act-by date — so your tenant is excluded from the automatic October 1 switch to EwsEnabled=False.
- For Kiosk, F1, or F3 mailboxes still relying on EWS, budget for a licence upgrade now; there is no allow-list workaround.
- For Exchange Hybrid, confirm your path to Exchange SE for Graph-based Rich Coexistence, or register your dedicated hybrid app in EWSAllowedAppIDs as an interim bridge.
- Start migrating remaining EWS-dependent code using the EWS to Graph API mappings and the EWS Analyzer tool — most workloads use only a handful of EWS operations and migrate faster than expected.
- Flag this to any vendors or ISVs whose products still integrate with Exchange via EWS; they need their own migration plan, not just yours.
EWS Retirement: Frequently Asked Questions
What happens if I do nothing before October 1, 2026?
If EWSEnabled is still Null, Microsoft switches it to False as part of the rollout and blocks all EWS access. Microsoft separately builds an allow list from your last 60 days of usage (MC1469960), but only for tenants that haven't created their own, and it can miss occasional-use apps.
Can I turn EWS back on if it gets blocked?
Yes. Admins can set EWSEnabled back to True (or Null, before full enforcement) at any point up to April 1, 2027, but expect a service interruption for affected apps while access is re-established.
Does this affect on-premises Exchange Server?
No. The retirement applies only to Exchange Online and Microsoft 365. EWS is not being retired in Exchange Server.
Are Kiosk, F1, and F3 mailboxes treated differently?
Yes. Those licence tiers lose EWS entirely from October 1, 2026 regardless of any AppID Allow List (MC1191578). A licence upgrade is the only fix.
What about Free/Busy, MailTips, and cross-tenant calendar sharing?
These already run on EWS behind the scenes. Microsoft is migrating them onto Cross-Tenant Access Policy-based Organization Relationships, targeting worldwide completion by September 1, 2026 — they aren't gated by your AppID Allow List.
Is there any extension past April 1, 2027?
No. Microsoft has confirmed there will be no exceptions past the final shutdown date.
Microsoft Sources and Further Reading
Use these Microsoft resources to check the retirement guidance and plan your tenant’s next steps.
- Retirement timeline and disablement process
- EWSAllowedAppIDs and temporary application access
- EWS access restrictions for Kiosk and frontline licences
- EWS access controls and PowerShell configuration
- EWS usage reports in the Microsoft 365 admin center
- Finding and remediating EWS application usage
- EWS deprecation overview and Microsoft Graph parity roadmap
Stay Ahead of Retirements Like This One
EWS's retirement isn't an isolated headline — it's one of dozens of Message Center items landing every month, each with its own tenant cohort, deadline, and required action. Missing one is how outages happen.
ChangePilot surfaces every M365 change that matters, tailored specifically to your tenant profile.
Not on the free newsletter yet? Sign up to the ChangePilot Bulletin here.
Comments