Skip to main content

Microsoft 365: EWS to Be Phased Out Starting in October 2026 – What Admins Need to Know Now

Microsoft 365: EWS Will Be Phased Out Starting in October 2026 – What Admins Need to Know Now

Modern cloud security requires constant adaptation. To keep interfaces future-proof, high-performing, and resilient against attacks, Microsoft is phasing out outdated protocols. Specifically, this affects Exchange Web Services (EWS): Microsoft will disable standard access via EWS in Exchange Online as of October 1, 2026. For IT departments, this means action is needed – especially regarding third-party tools, legacy scripts, and older email clients. Learn everything about the Microsoft 365 EWS shutdown in this blog post.

The Timeline at a Glance

  • October 1, 2026: EWS will be disabled by default for all tenants. Applications that have not been migrated will lose access to mailboxes unless an explicit exception is configured
  • Through March 31, 2027 (transition phase): Administrators can selectively extend EWS access via PowerShell, but must strictly limit the permitted applications
  • April 1, 2027 (hard cutoff): EWS will be permanently and completely decommissioned in Exchange Online, with no exceptions

Transitional Solution: Exception List for Essential Programs

To prevent business-critical legacy tools from being shut down overnight, Microsoft provides a temporary control mechanism: Admins can reactivate access via Exchange Online PowerShell, but must maintain an allowlist with specific app IDs (EwsAllowedAppIDs). This allows access to be restricted specifically to selected programs until no later than the end of March 2027. Microsoft provides further details and syntax examples in the Exchange Team Blog post on the EWS shutdown.

Pitfall: Legacy Outlook for Mac

A particularly tricky special case concerns macOS environments: The well-known “Legacy Outlook for Mac” is based entirely on the deprecated EWS interface. Since Microsoft excludes this client from the administrative exception lists, synchronization is at risk of stopping immediately as early as October 1, 2026. The old Outlook for Mac therefore does not benefit from the extension option through 2027.

Affected users must migrate to the “New Outlook for Mac” (switch in the upper-right corner of the app) before October 2026. This client communicates via modern interfaces such as Microsoft Graph. For more information, see the Microsoft support article: End of Support for Legacy Outlook for Mac.

To-Do List for IT

To avoid any unpleasant surprises with your email flows or connections starting in October 2026, it’s worth conducting an early assessment. Follow these steps to ensure your environment is on the safe side in time:

  1. Check in the M365 Admin Center: Microsoft lists active connections directly in the M365 Admin Center (under Reports > Usage > Exchange > EWS Usage). Carefully check which application IDs are still accessing EWS. These must be added to the `EwsAllowedAppIDs` if no replacement using the Graph API is available.
  2. Inventory Mac clients: Check the rollout status of the new Outlook for Mac in your device management system (for example, via Intune or Jamf) and migrate affected users in a timely manner.
  3. Contact developers & vendors: Plan the migration of in-house applications to the Microsoft Graph API and promptly request Graph-compatible updates from your third-party vendors.
  4. Prepare an exception list: Define the necessary app IDs for EwsAllowedAppIDsin case you are unable to migrate individual systems by October 2026.

Share this post