Exchange Web Services Retirement: Action Plan for Admins
Share on LinkedIn!
#SimpleSharepoint #ExchangeOnline #Microsoft365 #TenantAdmin #DataGovernance #Compliance #eDiscovery #MicrosoftUpdates #ITGovernance #EnterpriseIT
Allow List Setup, Cross-Tenant Migration, and Graph API Cutover
The Exchange Web Services retirement enforcement phase begins October 1, 2026, leading to a permanent shutdown on April 1, 2027.
Microsoft introduced EWSAllowedAppIDs to let administrators build an explicit allow list of approved applications before Exchange Web Services (EWS) enforcement starts. Setting EWSEnabled to $true activates this policy enforcement. Consequently, only registered Application IDs retain access, while unlisted integrations receive an HTTP 403 error. Furthermore, legacy cross-tenant Free/Busy, MailTips, and Calendar Sharing rely on the Microsoft 365 Cross-Tenant Access Policy moving forward.
Core Milestones and System Configuration Rules
To help manage your cutover from EWS to Microsoft Graph, keep these timeline rules in mind:
- App ID enforcement: Only applications explicitly registered in
EWSAllowedAppIDsmaintain connectivity after October 1, 2026. - Cross-tenant migration: Cross-tenant Free/Busy and Calendar Sharing shift to Cross-Tenant Access Policies between September and October 2026.
- Scope boundaries: The Exchange Web Services retirement applies exclusively to Exchange Online; hybrid on-premises mailboxes fall outside this scope.
Action Plan for Exchange Online Administrators
Because unlisted applications will face access blocks, administrators should execute three critical steps:
- Audit EWS usage: Pull tenant EWS usage reports to build an inventory of dependent scripts and third-party integrations.
- Configure allow lists: Register necessary Application IDs within
EWSAllowedAppIDsto prevent service disruptions. - Rebuild cross-tenant sharing: Transition organization relationships to Microsoft 365 Cross-Tenant Access Policies.
How our team helps you prepare:
- EWS Application Auditing: We identify hidden scripts, line-of-business apps, and third-party tools relying on legacy EWS calls.
- Microsoft Graph Migration: We refactor custom EWS code and rebuild integrations using modern Microsoft Graph endpoints.
- Cross-Tenant Policy Configuration: We configure Cross-Tenant Access Policies to keep cross-tenant sharing working uninterrupted.
Need help verifying your legacy integrations before enforcement begins? We can help audit your environment and map your migration to Microsoft Graph.



