Microsoft has started changing tenant-level EWS settings from $null to $false, a move that blocks EWS access for applications in Exchange Online. Administrators who need more time can explicitly set the value to $true and add approved applications to the EwsAllowedAppIDs list, but only until the April 2027 deadline. "There will be no exceptions," the company said.
Introduced with Exchange Server 2007, EWS lets applications read and write mailbox data including email, calendars and contacts. Microsoft said the API "no longer aligns with today's security, scale, or reliability requirements" and recommends Microsoft Graph instead, although some capability gaps remain between the two.
The change affects only Exchange Online. EWS in on-premises Exchange Server is unaffected. Microsoft stopped adding EWS features in 2018 and announced the retirement in 2023, giving administrators years to prepare. Even so, migration is not always straightforward. Markus Müller, global field CTO for API management at Boomi, said identifying every EWS use is one of the biggest challenges. "With rapid integration rollouts and limited documentation, many lack a complete inventory of their EWS dependencies," he said.
Translation layers that convert EWS calls into Graph requests can act as a temporary bridge, Müller said, but they add another component to maintain and do not remove the need to migrate. He argued that organizations should monitor APIs as dependencies throughout their lifecycle rather than waiting for deprecation notices.
Microsoft has not said how many organizations still depend on EWS. Overlooked integrations will likely surface through support tickets as previously reliable workflows stop working when the phased blocking reaches their tenants.