{"id":71126,"date":"2026-01-27T11:02:10","date_gmt":"2026-01-27T10:02:10","guid":{"rendered":"https:\/\/www.schneider.im\/?p=71126"},"modified":"2026-06-29T16:19:09","modified_gmt":"2026-06-29T14:19:09","slug":"microsoft-exchange-web-services-ews-retires-in-exchange-online","status":"publish","type":"post","link":"https:\/\/www.schneider.im\/lu\/microsoft-exchange-web-services-ews-retires-in-exchange-online\/","title":{"rendered":"Microsoft Exchange Web Services (EWS) retires in Exchange Online"},"content":{"rendered":"<p><strong>Avoid disruptions in mailbox access<\/strong>: Microsoft is <strong>retiring Exchange Web Services (EWS) in Exchange Online<\/strong>. EWS is the old Exchange API that many applications use to access email, calendar, contacts, and mailbox data. As part of this process, starting July 1, 2026, Microsoft will <strong>block EWS access for users whose licenses do not include EWS rights<\/strong>.<\/p>\n<p><span style=\"color: #ff0000;\"><strong>Update 2026-06-29:\u00a0<\/strong>Microsoft is phasing out EWS in stages: license enforcement starts July 1, 2026, Microsoft begins disabling EWS tenant by tenant from October 2026, and EWS in Exchange Online is completely shut down in April 2027.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-large wp-image-56105\" src=\"https:\/\/www.schneider.im\/media\/2025\/03\/SCHNEIDER-IT-MANAGEMENT-2025-03-11-Graphics-Office-People-9152-800x533.jpg\" alt=\"\" width=\"800\" height=\"533\" srcset=\"https:\/\/www.schneider.im\/media\/2025\/03\/SCHNEIDER-IT-MANAGEMENT-2025-03-11-Graphics-Office-People-9152-800x533.jpg 800w, https:\/\/www.schneider.im\/media\/2025\/03\/SCHNEIDER-IT-MANAGEMENT-2025-03-11-Graphics-Office-People-9152-500x333.jpg 500w, https:\/\/www.schneider.im\/media\/2025\/03\/SCHNEIDER-IT-MANAGEMENT-2025-03-11-Graphics-Office-People-9152-150x100.jpg 150w, https:\/\/www.schneider.im\/media\/2025\/03\/SCHNEIDER-IT-MANAGEMENT-2025-03-11-Graphics-Office-People-9152-768x512.jpg 768w, https:\/\/www.schneider.im\/media\/2025\/03\/SCHNEIDER-IT-MANAGEMENT-2025-03-11-Graphics-Office-People-9152-1536x1024.jpg 1536w, https:\/\/www.schneider.im\/media\/2025\/03\/SCHNEIDER-IT-MANAGEMENT-2025-03-11-Graphics-Office-People-9152-2048x1365.jpg 2048w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2>Who is affected?<\/h2>\n<p>Users with the following assigned licenses will lose access:<\/p>\n<ul>\n<li>Exchange Online Kiosk<\/li>\n<li>Microsoft 365 F1 \/ Office 365 F1<\/li>\n<li>Microsoft 365 F3 \/ Office 365 F3<\/li>\n<\/ul>\n<p>These licenses <em>never<\/em> included EWS rights, but Microsoft has not enforced the restriction until now.<\/p>\n<p>Starting July 1, 2026, EWS calls from these users will return <strong>HTTP 403 (Forbidden)<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<h2>Does this matter to my organization?<\/h2>\n<p>If you have <strong>applications, integrations, scripts,<\/strong> or <strong>tools<\/strong> that still <strong>rely on EWS, they may stop working for these users after July 1, 2026<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<h2>Background: EWS &#8211; End of Life?<\/h2>\n<p>In 2018, Microsoft announced that <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/exchange\/upcoming-changes-to-exchange-web-services-ews-api-for-office-365\/608055\">Exchange Web Services (EWS) will no longer receive functionality updates<\/a>. Starting <strong>October 1, 2026<\/strong>, Microsoft will <a href=\"https:\/\/devblogs.microsoft.com\/microsoft365dev\/retirement-of-exchange-web-services-in-exchange-online\/\">begin <strong>blocking all EWS requests from non\u2011Microsoft applications<\/strong> to Exchange Online<\/a>.<\/p>\n<p><span style=\"color: #ff0000;\"><strong>Complete shutdown in April 2027<\/strong><\/span><\/p>\n<p><span style=\"color: #ff0000;\">Microsoft will fully retire EWS in Exchange Online in April 2027. After this date, EWS is no longer available in Exchange Online, and every remaining EWS-based application, integration, or script must already run on Microsoft Graph.<\/span><\/p>\n<p><strong>Important:<\/strong><\/p>\n<ul>\n<li>This retirement applies <strong>only to Microsoft 365 and Exchange Online<\/strong>.<\/li>\n<li><strong>Exchange Server (on\u2011premises)<\/strong> is <strong>not affected<\/strong>; EWS continues to <strong>function normally on<\/strong>:\n<ul>\n<li>Exchange Server 2016<\/li>\n<li>Exchange Server 2019<\/li>\n<li>Future Exchange Server subscription editions<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2><span style=\"color: #ff0000;\">How to keep EWS apps running after October 2026<\/span><\/h2>\n<p><span style=\"color: #ff0000;\">From October 2026, Microsoft begins disabling EWS in Exchange Online tenant by tenant. From that point, EWS-based apps only keep working if your Microsoft 365 admins keep EWS enabled in the tenant and define an AppID Allow List that specifies exactly which applications may still use EWS. Apps that are not on the allow list are blocked.<\/span><\/p>\n<p><span style=\"color: #ff0000;\">Admins can check the organization-wide setting in PowerShell with Get-OrganizationConfig | select EWSEnabled and enable it with Set-OrganizationConfig -EwsEnabled:$true. A blank (Null) value counts as enabled only until September 2026- from October 1, 2026 Microsoft treats Null as disabled.<\/span><\/p>\n<p><span style=\"color: #ff0000;\">This is a bridge, not a fix: it only buys time until the April 2027 shutdown. Use the window to migrate the affected apps to Microsoft Graph.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2>How does EWS work in Exchange Online?<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-71132\" src=\"https:\/\/www.schneider.im\/media\/2026\/01\/SCHNEIDER-IT-MANAGEMENT-2026-01-27-Update-Microsoft-EWS-explained.png\" alt=\"\" width=\"400\" height=\"657\" srcset=\"https:\/\/www.schneider.im\/media\/2026\/01\/SCHNEIDER-IT-MANAGEMENT-2026-01-27-Update-Microsoft-EWS-explained.png 400w, https:\/\/www.schneider.im\/media\/2026\/01\/SCHNEIDER-IT-MANAGEMENT-2026-01-27-Update-Microsoft-EWS-explained-304x500.png 304w, https:\/\/www.schneider.im\/media\/2026\/01\/SCHNEIDER-IT-MANAGEMENT-2026-01-27-Update-Microsoft-EWS-explained-91x150.png 91w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/><\/p>\n<p><strong>Exchange Web Services (EWS)<\/strong> lets applications connect securely to <strong>Exchange Online<\/strong> to access mailbox data such as email, calendar, contacts, and folders. The EWS app sends HTTPS\/SOAP requests that pass through authentication, load balancers, and the Client Access Server layer. Autodiscover then tells the app where the mailbox is located, and the EWS service retrieves or updates data from the mailbox servers. In short, EWS is the API that applications use to read and modify <strong>Exchange Online mailbox content<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<h2>How does Microsoft Graph work?<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-71136\" src=\"https:\/\/www.schneider.im\/media\/2026\/01\/SCHNEIDER-IT-MANAGEMENT-2026-01-27-Update-Microsoft-Graph-explained.png\" alt=\"\" width=\"760\" height=\"580\" srcset=\"https:\/\/www.schneider.im\/media\/2026\/01\/SCHNEIDER-IT-MANAGEMENT-2026-01-27-Update-Microsoft-Graph-explained.png 760w, https:\/\/www.schneider.im\/media\/2026\/01\/SCHNEIDER-IT-MANAGEMENT-2026-01-27-Update-Microsoft-Graph-explained-500x382.png 500w, https:\/\/www.schneider.im\/media\/2026\/01\/SCHNEIDER-IT-MANAGEMENT-2026-01-27-Update-Microsoft-Graph-explained-150x114.png 150w\" sizes=\"(max-width: 760px) 100vw, 760px\" \/><\/p>\n<p><strong>Microsoft Graph<\/strong> is the <strong>unified API<\/strong> that applications use to <strong>access Microsoft 365 data across services like Teams, Planner, OneDrive, and SharePoint<\/strong>. A third\u2011party app authenticates through Microsoft Entra ID using OAuth2, then sends HTTPS\/JSON requests to the Microsoft Graph API gateway. Graph routes these requests to the correct service and returns the required data. In short, Microsoft Graph is the <strong>single, modern API<\/strong> that <strong>connects apps securely to all Microsoft 365 services.<\/strong><\/p>\n<p>&nbsp;<\/p>\n<h2>Why is Microsoft retiring EWS in Exchange Online?<\/h2>\n<p>Microsoft is retiring EWS in Exchange Online because it is an <strong>outdated, insecure legacy protocol<\/strong>, and they want all developers to <strong>move to the more secure, modern Microsoft Graph API<\/strong>, especially after <strong>EWS was used in the <\/strong><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2024\/01\/25\/midnight-blizzard-guidance-for-responders-on-nation-state-attack\/\"><strong>Midnight Blizzard attack in 2024<\/strong><\/a>.<\/p>\n<p>&nbsp;<\/p>\n<h2>Why Microsoft Graph Is Better Than EWS?<\/h2>\n<p><strong>Microsoft Graph replaces EWS<\/strong> because it is <strong>more secure, more modern, and works across all Microsoft 365 services<\/strong> &#8211; <strong>not just Exchange<\/strong>. Graph uses <strong>OAuth2<\/strong> with Microsoft Entra ID, while EWS relied on outdated authentication methods like Basic Auth. Graph provides one <strong>unified API<\/strong> for accessing Teams, Planner, OneDrive, SharePoint, Exchange and more, whereas EWS could only access Exchange mailbox data. <strong>Graph continues to receive updates, new features, and improvements,<\/strong> while EWS is deprecated and will be fully disabled in Exchange Online.<\/p>\n<p>&nbsp;<\/p>\n<h2>What you should do now<\/h2>\n<ol>\n<li>Identify any <strong>applications still using EWS<\/strong>\n<ul>\n<li>Legacy mailbox tools, scripts, calendar sync, reporting, monitoring, etc.<\/li>\n<\/ul>\n<\/li>\n<li>Check which <strong>users<\/strong> have Kiosk or Frontline licenses\n<ul>\n<li>These users will lose EWS access unless you change their license.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Assign<\/strong> a license that includes EWS rights (if needed)<\/li>\n<\/ol>\n<p>Options include:<\/p>\n<ul>\n<li>Exchange Online Plan 1 or Plan 2<\/li>\n<li>Microsoft 365 E3 or E5<\/li>\n<li>Office 365 E3 or E5<\/li>\n<\/ul>\n<ol start=\"4\">\n<li>Plan your long-term <strong>migration to Microsoft Graph<\/strong>\n<ul>\n<li>Microsoft Graph is the supported API going forward.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<ul>\n<li><span style=\"color: #ff0000;\">If you must keep EWS apps running past October 2026, keep EWS enabled and maintain an AppID Allow List for those apps \u2013 and treat it as a temporary bridge until the April 2027 shutdown.<\/span><\/li>\n<\/ul>\n<h2>Need help reviewing EWS usage or choosing the right licenses?<\/h2>\n<p><strong>Our Microsoft licensing experts at SCHNEIDER IT MANAGEMENT help you identify affected users, evaluate dependencies, and move to the correct licensing. <\/strong><a href=\"https:\/\/www.schneider.im\/contact\/\"><strong>Contact us<\/strong><\/a><strong> now to keep your operations running.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Avoid disruptions in mailbox access: Microsoft is retiring Exchange Web Services (EWS) in Exchange Online. EWS is the old Exchange API that many applications use to access email, calendar, contacts, and mailbox data. As part of this process, starting July 1, 2026, Microsoft will block EWS access for users whose licenses do not include EWS [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":33016,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[585,614,551],"tags":[],"class_list":["post-71126","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-entra","category-microsoft-exchange-online","category-microsoft-graph"],"_links":{"self":[{"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/posts\/71126","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/comments?post=71126"}],"version-history":[{"count":4,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/posts\/71126\/revisions"}],"predecessor-version":[{"id":74707,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/posts\/71126\/revisions\/74707"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/media\/33016"}],"wp:attachment":[{"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/media?parent=71126"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/categories?post=71126"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.schneider.im\/lu\/wp-json\/wp\/v2\/tags?post=71126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}