Cisco Unity Connection with Exchange Online: options after EWS

Cisco Unity Connection before Release 15 SU4 works with Microsoft 365 mailboxes through Exchange Web Services. For mailboxes in Exchange Online, EWS ends on April 1, 2027, and Cisco’s only fix is the upgrade to 15 SU4.

What stops

Unified Messaging is the part of Unity Connection that works with Exchange mailboxes. With Microsoft 365 it synchronizes voice messages between Unity Connection and the mailbox of each user (single inbox), reads email over the phone with text-to-speech, and gives access to calendars and contacts.

Up to Release 15 SU3, all of this goes through EWS. Cisco’s field notice FN74365 covers every version of Release 14 and every version of Release 15 before SU4, and says that once Microsoft blocks EWS, “Cisco Unity Connection will not sync voicemail with Microsoft 365”.

Release 12.5 is not in the notice. Its support ended on August 31, 2025, and it reaches Exchange Online through EWS like the later releases.

Unity Connection with Exchange Server is not affected. Cisco states that the integration with Exchange 2016 and Exchange 2019 continues to use EWS.

The dates

Cisco’s notice names October 1, 2026 as the day Microsoft starts blocking EWS for applications such as Unity Connection. Microsoft’s own schedule has more steps, and they decide how long an older release keeps working:

  • October 10, 2026: a tenant in Microsoft’s worldwide cloud that has EWSEnabled set to True needs an EWSAllowedAppIDs list. An application that is not on the list loses EWS.
  • Later, after a 7-day warning in Message Center: Microsoft turns EWS off in tenants that never set EWSEnabled.
  • April 1, 2027: Microsoft removes EWS from Exchange Online for every application, listed or not.

On Cisco’s side, software maintenance for Release 14 ended on April 7, 2026, and its last date of support is April 30, 2027.

Keep unified messaging working until the retirement

Unity Connection signs in to Exchange Online with an app registration that you created in Microsoft Entra ID. Its application (client) ID is the value in the Application (Client) ID field of the unified messaging service, and it is the ID that Microsoft checks against the list.

The field notice and the release notes do not mention the list. An administrator of the Microsoft 365 tenant can put the ID on it:

Set-OrganizationConfig -EwsEnabled $true -EwsAllowedAppIDs "<Unity Connection app ID>,<other app IDs>"

The command stores the whole list, so include every application that should keep EWS. A change to the list can take up to 24 hours to apply. With the ID on the list, an older release keeps its EWS connection until April 1, 2027 and loses it on that day.

Your EWS app list explains the list, and EWS returns 403 in Exchange Online covers the other settings that can block the connection.

The route Cisco offers: Release 15 SU4

From Release 15 SU4, Unity Connection reaches Microsoft 365 through Microsoft Graph. Cisco’s release notes call Graph “the only supported option for Office 365 integration”, and the field notice says that upgrading is the only way to keep unified messaging.

Before the upgrade

  • Add the Microsoft Graph application permissions to the app registration first: Mail.ReadWrite and Mail.Send, plus Calendars.ReadWrite and Contacts.ReadWrite for calendar and contact access. The upgrade then moves the existing services to Graph.
  • Cisco documents a direct upgrade to Release 15 from 12.5.1 and from 14, with COP files that may have to be installed first. From 11.5 it requires an intermediate release.
  • Cisco lists ESXi 7.0 U3 and 8.0 U1 for Release 15, and from 15 SU3 the virtual machine needs a CPU mode that supports AVX. The smallest virtual machine listed for Release 15 has 2 vCPUs and 10 GB of memory, where Release 14 lists machines with 4 GB.
  • Licenses from before Cisco Smart Software Licensing have to be migrated to it before the upgrade.
  • An unrestricted version cannot be upgraded to a restricted one.

What changes after it

  • Subfolders are not synchronized. Synchronization covers the Inbox, Junk Email and Deleted Items, and a voice message that a user or an Outlook rule moves to another folder is treated as deleted in Unity Connection. Cisco recommends moving messages from subfolders to the Inbox before the upgrade.
  • Forwarded voice messages cannot be played in ViewMail and have to be downloaded as WAV files.
  • Synchronization can lag by up to 3 minutes, and after the upgrade the unified messaging service can take up to 4 hours to become stable.
  • A Cisco employee’s announcement in the Cisco Community says that after the upgrade you have to install the COP file ciscocm.cuc.V15SU4_CSCgraph_C0282-1.zip. It fixes three defects that delay synchronization or stop delivery to Microsoft 365, and installing it interrupts service on each server.

Routes that keep part of it

  • Unity Connection can relay each voice message to an SMTP address, or keep its own copy and relay another one (“Accept and Relay the Message”). The user gets the message as an email, with no connection through EWS or Graph. This needs an SMTP smart host, relayed messages cannot be transcribed, and the copy in the mailbox is not synchronized with Unity Connection.
  • Unity Connection also serves voice messages over IMAP, so a mail client can open the Unity Connection mailbox as a separate account. Cisco calls this integrated messaging, and the class of service has to allow it.

An EWS endpoint we can build for you

One more route would leave an older release as it is: an EWS endpoint inside your network that accepts the calls of Unity Connection and carries them out in Exchange Online through Microsoft Graph. We have not built or tested one yet, and it would be outside what Cisco supports: Cisco’s older interface reference describes a setting that names the server of an Office 365 service instead of searching for it, and a Cisco tech note calls that setting unsupported for Office 365.

Sunsetless EWS is a .NET library that replaces the EWS Managed API in code you compile yourself, so it cannot help Unity Connection on its own. The endpoint would do the same translation from EWS to Graph as a separate service that you host yourself.

Tell us about your Unity Connection

If you run a release before 15 SU4 with Microsoft 365 and cannot upgrade before April 1, 2027, write to us. We build the endpoint for the calls your Unity Connection makes, and you try it on your own system before you rely on it.

The first organizations to get in touch pay a low, fixed price, because their setups decide what we build first. We agree everything by email, and a few lines are enough to start:

  • The release you run, and roughly how many mailboxes use single inbox
  • What you use: voice message synchronization only, or text-to-speech, calendars and contacts as well
  • What stands in the way of the upgrade: hardware, the ESXi version, licenses, a change freeze
  • When you have to decide

What to record while it still works

Whichever route you take, write down what the current setup does before it changes:

  • the unified messaging services, and which users and classes of service use each;
  • the application (client) ID and the permissions of the app registration;
  • whether users or Outlook rules move voice messages to subfolders;
  • which features you use: single inbox, text-to-speech, calendars, contacts.

Sources

More guides