Microsoft begins disabling Exchange Web Services as retirement deadline nears

Phased blocking of EWS in Exchange Online starts October 1, with permanent shutdown set for April 2027

By LineZotpaper
Published
Read Time2 min
Microsoft has begun disabling Exchange Web Services (EWS) in Exchange Online, opening a phased shutdown that will end with the API's permanent retirement on April 1, 2027. The company is directing administrators to move integrations to Microsoft Graph.

Microsoft has started changing tenant-level EWS settings from $null to $false, a move that blocks EWS access for applications in Exchange Online. Administrators who need more time can explicitly set the value to $true and add approved applications to the EwsAllowedAppIDs list, but only until the April 2027 deadline. "There will be no exceptions," the company said.

Introduced with Exchange Server 2007, EWS lets applications read and write mailbox data including email, calendars and contacts. Microsoft said the API "no longer aligns with today's security, scale, or reliability requirements" and recommends Microsoft Graph instead, although some capability gaps remain between the two.

The change affects only Exchange Online. EWS in on-premises Exchange Server is unaffected. Microsoft stopped adding EWS features in 2018 and announced the retirement in 2023, giving administrators years to prepare. Even so, migration is not always straightforward. Markus Müller, global field CTO for API management at Boomi, said identifying every EWS use is one of the biggest challenges. "With rapid integration rollouts and limited documentation, many lack a complete inventory of their EWS dependencies," he said.

Translation layers that convert EWS calls into Graph requests can act as a temporary bridge, Müller said, but they add another component to maintain and do not remove the need to migrate. He argued that organizations should monitor APIs as dependencies throughout their lifecycle rather than waiting for deprecation notices.

Microsoft has not said how many organizations still depend on EWS. Overlooked integrations will likely surface through support tickets as previously reliable workflows stop working when the phased blocking reaches their tenants.

§

Analysis

Why This Matters

  • Existing EWS-based workflows will start failing as Microsoft's phased blocking reaches each tenant, with no extension available beyond April 2027.
  • Many organizations lack a complete inventory of their EWS dependencies, making disruption likely for at least some users.
  • The migration to Microsoft Graph is not a like-for-like swap, since capability gaps remain.

Background

EWS has been part of Exchange since 2007 and became a standard way for third-party applications to handle mailbox data. Microsoft stopped adding features to the Exchange Online version in 2018 and announced the retirement in 2023, so the current shutdown follows several years of notice. The replacement, Microsoft Graph, does not yet cover every scenario EWS supported, which is why Microsoft is allowing a temporary window for applications that have not migrated.

Key Perspectives

IT administrators: They carry the burden of discovering and migrating often poorly documented internal integrations before the deadline, with support teams likely to absorb the fallout. Microsoft: The company argues EWS no longer meets modern security, scale or reliability needs and is holding a firm line, with no exceptions to the retirement date. Markus Müller of Boomi: Translation layers offer a stopgap but are not a permanent fix, and organizations should treat APIs as dependencies to be tracked throughout their lifecycle.

What to Watch

  • The volume of support tickets reporting broken EWS workflows, which will indicate how many organizations were unprepared.
  • Whether Microsoft closes remaining Graph capability gaps that currently block some migrations.
  • The April 1, 2027 deadline, when EWS in Exchange Online is disabled permanently.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.