Microsoft is retiring Exchange Web Services (EWS) in Exchange Online in two phases — a controlled, tenant-by-tenant disablement starting October 1, 2026, and a full, permanent shutdown on April 1, 2027 (MC1227454, MC1447678).
If EWS is left on with no AppID Allow List configured, all EWS traffic gets blocked automatically once enforcement begins. Kiosk, F1, and F3 licensed mailboxes lose EWS entirely regardless of any allow list (MC1191578).
The fix: configure EWSAllowedAppIDs and set EWSEnabled=True before September 30, 2026, or accept the block.
EWS is a nearly 20-year-old protocol that no longer meets Microsoft's current security bar, and the January 2024 Midnight Blizzard nation-state attack accelerated its shutdown. Microsoft first flagged EWS as deprecated back in 2018, and in 2023 set October 2026 as the disablement date. The Midnight Blizzard security incident in January 2024 involved EWS and widened the retirement's scope from third-party applications to Microsoft's own products too, including Outlook, Office, Teams, and Dynamics 365. Microsoft Graph has since reached near-complete feature parity with EWS for the vast majority of scenarios, per the official deprecation page.
Importantly, this retirement applies only to Exchange Online and Microsoft 365. There are no changes to EWS in on-premises Exchange Server.
There are two hard dates: October 1, 2026 for phased disablement, and April 1, 2027 for full, permanent shutdown with no admin override.
Microsoft sets out the phased disablement process and final shutdown in its Exchange Team announcement, Exchange Online EWS, Your Time is Almost Up.
The behaviour of EWSEnabled and the AppID Allow List flips from permissive to restrictive on October 1, 2026 — the same settings produce a different outcome depending on the date.
| EWSEnabled Value | AppID Allow List State | Behaviour Before October 2026 | Behaviour From October 2026 |
|---|---|---|---|
| Null (default) | Ignored | All EWS traffic allowed | Changes to False automatically — all EWS traffic blocked, unless you've already set True |
| True | Empty or null | All EWS traffic allowed | All EWS traffic blocked |
| True | Populated | Only listed App IDs allowed | Only listed App IDs allowed |
| False | Any | All EWS traffic blocked | All EWS traffic blocked |
For the AppID-based access model and hybrid considerations, see Microsoft’s EWSAllowedAppIDs guidance. The PowerShell settings are documented in Microsoft Learn: Control access to EWS in Exchange.
One nuance worth flagging: cross-tenant Organization Relationship traffic — the mechanism behind Free/Busy, MailTips, and calendar sharing between tenants — isn't gated by the AppID Allow List either side of October 2026. That traffic is moving separately onto Cross-Tenant Access Policy, with worldwide completion targeted for September 1, 2026.
Not every organisation hits the same wall at the same time — licence tier, hybrid topology, and whether you've built your own allow list all change the outcome.
(This is exactly the kind of tenant-specific nuance that gets missed in a generic Message Center scan — ChangePilot tracks items like MC1447678 and MC1469960 against your tenant's actual configuration, not just the headline announcement.)
Inventory who's using EWS, build your own AppID Allow List rather than waiting for Microsoft's, and set EWSEnabled=True before the deadline.
Microsoft 365 admin center → Reports → Usage → Exchange → EWS usage, or go directly via EWS Usage Reports.Set-OrganizationConfig -EwsAllowedAppIDs "11111111-2222-3333-4444-555555555555,aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee"
Set-OrganizationConfig -EwsEnabled $true
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs
If EWSEnabled is still Null, Microsoft switches it to False as part of the rollout and blocks all EWS access. Microsoft separately builds an allow list from your last 60 days of usage (MC1469960), but only for tenants that haven't created their own, and it can miss occasional-use apps.
Yes. Admins can set EWSEnabled back to True (or Null, before full enforcement) at any point up to April 1, 2027, but expect a service interruption for affected apps while access is re-established.
No. The retirement applies only to Exchange Online and Microsoft 365. EWS is not being retired in Exchange Server.
Yes. Those licence tiers lose EWS entirely from October 1, 2026 regardless of any AppID Allow List (MC1191578). A licence upgrade is the only fix.
These already run on EWS behind the scenes. Microsoft is migrating them onto Cross-Tenant Access Policy-based Organization Relationships, targeting worldwide completion by September 1, 2026 — they aren't gated by your AppID Allow List.
No. Microsoft has confirmed there will be no exceptions past the final shutdown date.
Use these Microsoft resources to check the retirement guidance and plan your tenant’s next steps.
EWS's retirement isn't an isolated headline — it's one of dozens of Message Center items landing every month, each with its own tenant cohort, deadline, and required action. Missing one is how outages happen.
ChangePilot surfaces every M365 change that matters, tailored specifically to your tenant profile.
Not on the free newsletter yet? Sign up to the ChangePilot Bulletin here.