What is changing?

Exchange Web Services can allow an application to work with email messages, calendars, appointments, contacts, mailbox folders, meeting information and shared mailbox content. EWS has existed since Exchange Server 2007. Microsoft stopped adding new functionality to EWS in Exchange Online several years ago and now recommends Microsoft Graph for supported cloud integrations.

Microsoft's current timetable states that EWS starts to be disabled globally across Exchange Online organisations in October 2026 and will be fully disabled in April 2027. This is a staged retirement rather than every Microsoft 365 tenant being affected on one day, but organisations should not assume they can safely wait until April 2027.

The change applies to Exchange Online. Microsoft Graph is not a replacement for applications accessing an entirely on premises Exchange Server.

Which applications could be affected?

The retirement does not mean that Exchange Online or ordinary Microsoft 365 mailboxes are closing. The risk concerns applications and integrations that still use EWS to communicate with them.

An application may use EWS in the background without displaying the term to its users. Do not assume a product is unaffected merely because staff use it through a website or a familiar desktop interface.

Microsoft is removing EWS dependencies from its own applications. Keeping Microsoft 365 applications current is therefore important, but third party and internally developed integrations still need to be identified and checked.

  • Customer relationship management systems
  • Helpdesk and ticketing platforms
  • Email archiving or migration products
  • Backup applications
  • Room and appointment booking systems
  • Document and case management platforms
  • Bespoke business applications
  • Automated mailbox processing tools
  • Older calendar and contact synchronisation products
  • School management, safeguarding, communications, room booking and reporting systems that connect to staff mailboxes or calendars

Check your Microsoft 365 EWS usage report

Microsoft has introduced an EWS usage report within the Microsoft 365 admin centre. An authorised administrator can open Reports, select Usage, choose Exchange and then open the EWS usage tab. Review the longest available period, normally 90 days, and export the results for further investigation.

The report shows active application IDs, the EWS actions being used, call volumes and the last recorded activity date. Usage information is collected weekly and can take up to ten days to appear.

A report showing no recent calls is useful evidence, but it should not be treated as absolute proof that EWS is unused. Some applications may operate only at month end, during termly processes or when a particular task is requested.

If an application ID is unfamiliar, check it against the enterprise applications listed in Microsoft Entra. Record the application owner, supplier, purpose and affected mailboxes before making configuration changes.

Ask suppliers the right questions

Do not settle for a general assurance that a product supports Microsoft 365. Ask specifically whether the version you use accesses Exchange Online through EWS.

Where software was developed internally, the developer should review Microsoft's EWS to Microsoft Graph migration guidance. Microsoft says Graph provides more granular permission controls than the broad access traditionally associated with some EWS configurations.

Avoid granting wide mailbox permissions simply to make a replacement integration work. The permissions requested should be documented and limited to the application's actual purpose.

  • Does our current product or version use Exchange Web Services?
  • Has it been updated to use Microsoft Graph or another supported method?
  • Is an application update, licence change or configuration change required?
  • Are all existing features available after migration?
  • What testing does the supplier recommend?
  • Will users need to sign in or grant consent again?
  • Does the replacement request only the mailbox permissions it genuinely needs?
  • What is the supplier's supported completion date?

Update and test before relying on the replacement

Installing an update is only part of the work. The complete business process should be tested, using a test account or non critical mailbox where possible. Record the expected result, the actual result and any permissions granted during testing.

Where an application supports important operational, financial or safeguarding work, agree a temporary manual procedure before making the change. This gives staff a clear alternative if the updated integration does not behave as expected.

  • Read and process an incoming email
  • Create or update an appointment
  • Access the correct shared mailbox
  • Synchronise a contact
  • Send an automated notification
  • Archive or recover a test message
  • Process an attachment
  • Confirm that staff can still complete the normal task

Practical EWS retirement checklist

  • Open the Microsoft 365 EWS usage report.
  • Review and export the longest available reporting period.
  • Identify every reported application ID.
  • Match each application to an owner, supplier and business purpose.
  • Check for systems that may run less frequently than the report period.
  • Ask suppliers whether the installed version uses EWS.
  • Obtain supported upgrade or migration instructions.
  • Review the mailbox permissions requested by replacement applications.
  • Update Microsoft applications and supported third party products.
  • Test each important email, calendar and contact workflow.
  • Document a temporary manual process for critical functions.
  • Remove obsolete applications and unnecessary mailbox permissions.
  • Monitor the service after migration.
  • Complete the work well before EWS is fully disabled in April 2027.

How Bury I.T. Support can help

Bury I.T. Support Ltd can review Exchange Online usage, identify applications still using EWS and coordinate the required updates with software suppliers.

Official sources and further reading

These primary sources were checked when this article was last reviewed.

Written by

Christopher Lomax

Director of Bury I.T. Support Ltd, with more than 20 years of hands-on experience supporting business IT, Microsoft 365, networks, servers and cyber security.

About the team