MSFC

----

Exchange Web Services enters the final stretch before Microsoft pulls access

LongbridgeAII'm LongbridgeAI, I can summarize articles.

Microsoft is beginning the phased disabling of Exchange Web Services (EWS) in Exchange Online, with full retirement scheduled for April 1, 2027. Starting October 1, tenant-level settings defaulting to null will be set to false, blocking EWS access unless explicitly allowed. Microsoft cites security and reliability concerns, recommending migration to Microsoft Graph. While on-premises EWS remains unaffected, organizations face challenges in identifying all dependencies, risking workflow disruptions as the deprecation proceeds.

Microsoft begins disabling Exchange Web Services (EWS) in Exchange Online today, ahead of the API's permanent retirement on April 1, 2027.

Introduced with Exchange Server 2007, EWS allows applications to access mailbox data including email, calendars, and contacts. Microsoft says the service "no longer aligns with today's security, scale, or reliability requirements" and recommends moving integrations to Microsoft Graph, although some capability gaps remain.

Beginning October 1, Microsoft will start changing tenant-level EwsEnabled settings left at $null to $false, blocking EWS. Administrators needing temporary continuity can explicitly set the value to $true and add approved applications to the EwsAllowedAppIDs list. Applications not on that list will be blocked.

That buys time only until April 1, 2027, when Microsoft will disable EWS permanently. The company was unequivocal: "There will be no exceptions."

The retirement applies only to EWS in Exchange Online. EWS in on-premises Exchange Server is unaffected.

Microsoft stopped adding features to EWS in Exchange Online in 2018 and announced its retirement in 2023. Administrators have therefore had years to prepare, but moving away from a deeply embedded API is not necessarily straightforward.

Markus Müller, global field CTO for API management at Boomi, said one of the biggest migration challenges was identifying every use of EWS.

"With rapid integration rollouts and limited documentation, many lack a complete inventory of their EWS dependencies," he said.

Translation layers that convert EWS calls into Microsoft Graph requests may offer a temporary bridge, Müller added, but create another component to maintain and do not remove the need to migrate. He argued that organizations should monitor APIs as dependencies throughout their lifecycle rather than waiting for deprecation notices to expose them.

Microsoft has not said how many organizations or processes still depend on EWS in Exchange Online. Any overlooked integrations will begin revealing themselves as the phased blocking reaches their tenants – most likely through support tickets reporting that previously reliable workflows have suddenly stopped. ®

Login to unlock1,707characters for free

Due to copyright restrictions, please log in to your Longbridge account to view this content.
Thank you for your understanding and support of licensed content.