Sunsetless EWS getting started guide
A migration outline for applications that use the EWS Managed API. Confirm your operations are covered before changing a production app.
Inventory actual EWS calls
Export the Microsoft 365 EWS usage report for a period that includes your application's normal work. Use the private checker for a first pass, then review the full coverage matrix.
Check the library and mailbox scope
This package targets .NET applications using the EWS Managed API or the supported .NET Standard port. Exchange Online calls can use Graph; on-premises Exchange calls continue over EWS. Python, Java, PowerShell and closed third-party applications are outside this package's scope.
Replace the package and configure Graph
Swap the Microsoft package for ours from NuGet.org; your code compiles unchanged. Calls to Microsoft Graph need the licence key you get by email after purchase. Register or update an app in Microsoft Entra ID, grant only the Graph permissions the workload needs, and configure certificate authentication.
dotnet remove package Microsoft.Exchange.WebServices dotnet add package Sunsetless.EwsApplication permissions in Microsoft Graph, by what your app uses:
Autodiscover is answered from Microsoft Graph, because Exchange Online refuses app-only tokens there. Set
SUNSETLESS_AUTODISCOVER=passthroughto send it to Exchange instead.Follow the package README for the exact configuration names and supported framework versions.
Limit mailbox access
Use Exchange Online application RBAC or another supported least-privilege setup to scope app-only access to the required mailboxes. Permission scope is configured in your tenant; the library does not make that security decision for you.
Test real request behavior
Run representative workflows in a non-production environment. Check IDs, paging, sync state, folder types, search, notifications and error handling against the known differences.