Sunsetless EWS getting started guide

A migration outline for applications that use the EWS Managed API. Confirm your operations are covered before changing a production app.

  1. Inventory actual EWS calls

    Export the Microsoft 365 EWS usage report for a period that includes your application's normal work. Use the private checker for a first pass, then review the full coverage matrix.

  2. Check the library and mailbox scope

    This package targets .NET applications using the EWS Managed API or the supported .NET Standard port. Exchange Online calls can use Graph; on-premises Exchange calls continue over EWS. Python, Java, PowerShell and closed third-party applications are outside this package's scope.

  3. Replace the package and configure Graph

    Swap the Microsoft package for ours from NuGet.org; your code compiles unchanged. Calls to Microsoft Graph need the licence key you get by email after purchase. Register or update an app in Microsoft Entra ID, grant only the Graph permissions the workload needs, and configure certificate authentication.

    dotnet remove package Microsoft.Exchange.WebServices
    dotnet add package Sunsetless.Ews

    Application permissions in Microsoft Graph, by what your app uses:

    • Mail.ReadWrite, Mail.Send: mail, folders, search folders, conversations, sync and notifications
    • Calendars.ReadWrite: calendars, meetings, availability and delegates
    • Contacts.ReadWrite (or Contacts.Read for read-only use): contacts and FindPeople in contact folders
    • Tasks.ReadWrite.All: tasks
    • MailboxSettings.ReadWrite: out-of-office, inbox rules, categories and working hours
    • User.Read.All, Group.Read.All: ResolveNames, ExpandDL, FindPeople in the directory, user photos and GetPasswordExpirationDate
    • Place.Read.All: room lists
    • Optional: MailboxFolder.Read.All (folders of all kinds from the mailbox root; Notes and Journal items), MailboxItem.Read.All (contact groups and full task properties), MailboxItem.ImportExport.All (moving and copying contacts, tasks and calendar items; creating posts), ProfilePhoto.ReadWrite.All (SetUserPhoto), Domain.Read.All (Autodiscover GetDomainSettings and GetAppMarketplaceUrl)

    Autodiscover is answered from Microsoft Graph, because Exchange Online refuses app-only tokens there. Set SUNSETLESS_AUTODISCOVER=passthrough to send it to Exchange instead.

    Follow the package README for the exact configuration names and supported framework versions.

  4. Limit mailbox access

    Use Exchange Online application RBAC or another supported least-privilege setup to scope app-only access to the required mailboxes. Permission scope is configured in your tenant; the library does not make that security decision for you.

  5. Test real request behavior

    Run representative workflows in a non-production environment. Check IDs, paging, sync state, folder types, search, notifications and error handling against the known differences.

Do not switch on an action-name match alone. The usage report does not include request parameters, mailbox folder types or unexercised paths.