Dynamics 365 on-premises with Exchange Online: options after EWS

Dynamics 365 Customer Engagement (on-premises) reads and writes mailboxes through Exchange Web Services. For mailboxes in Exchange Online, that ends on April 1, 2027, and Microsoft’s documentation says the connection gets no further updates.

What stops

Server-side synchronization is the part of the Dynamics 365 server that connects to mailboxes directly. With Exchange it synchronizes email, appointments, contacts and tasks in both directions, and queues receive and send their email through it. It reaches Exchange through EWS, in Exchange Online and in Exchange Server alike.

When EWS is removed from Exchange Online, the server can no longer reach mailboxes there. It stops bringing incoming email into the CRM and sending email written in the CRM, and appointments, contacts and tasks stop synchronizing.

Dynamics 365 App for Outlook depends on it too: Microsoft requires server-side synchronization to be set up before users can have the app. Queue mailboxes have no other supported route, because the legacy Outlook add-in is not available for queues and Microsoft no longer supports the Email Router.

The dates

  • October 1, 2025: Microsoft stopped updating the connection and stopped connecting new tenants to it.
  • May 25, 2026: end of support for version 8.0 with Exchange Online.
  • October 1, 2026: Microsoft’s recommended deadline for moving to Dynamics 365 (online), or for keeping EWS allowed in the tenant so that the connection works until the retirement.
  • April 1, 2027: end of support for version 9 with Exchange Online. This is the day Microsoft removes EWS from Exchange Online.

The CRM stays in support after that day. Mainstream support for version 9.1 runs until January 12, 2029 and extended support until January 9, 2031.

Keep the connection working until the retirement

From October 10, 2026, a tenant in Microsoft’s worldwide cloud that has EWSEnabled set to True also needs an EWSAllowedAppIDs list, and an application that is not on the list loses EWS. Microsoft’s own applications have to be listed like any other: if one shows up in your usage report and you want to keep it, it goes on the list.

Microsoft’s documentation for this connection does not name the application ID it uses. The setup script attaches your certificate to the service principal 00000007-0000-0000-c000-000000000000, which Microsoft lists as Dataverse, so that is the first ID to look for. Confirm it in your own tenant: the EWS usage report in the Microsoft 365 admin center lists the application IDs that call EWS, and Which applications still use EWS in your tenant has a script that puts names to them.

Three things can stop the connection before the retirement:

  • The ID is missing from the list. Microsoft filled the lists it created with the applications seen in the previous 60 days, and a change to the list takes effect after 24 hours.
  • EWSEnabled was never set in the tenant. Microsoft turns EWS off for those tenants later, after a 7-day warning in Message Center.
  • Baseline Security Mode has “Disable organization-wide access to Exchange Web Services (EWS)” turned on. Microsoft’s notes on that setting say that server-side sync between Dynamics on-premises and Exchange Online does not work with it.

Your EWS app list explains the list and the command that shows it.

The two routes Microsoft offers

Move the CRM to Dynamics 365 (online)

This is the route Microsoft recommends for keeping server-side synchronization. Microsoft says it is removing the EWS dependencies from its own products, Dynamics 365 among them, so in the online service the change is Microsoft’s work. For you it is a migration of the whole CRM, with its customizations and integrations.

Move the mailboxes to Exchange Server

EWS is not being retired in Exchange Server, and the CRM connects to an Exchange server through an email server profile of its own. This route means running Exchange Server and moving the synchronized mailboxes to it.

Check the version before you plan around it. Microsoft’s table of supported configurations for the on-premises CRM names Exchange Server 2010 to 2019. Support for Exchange Server 2019 ended on October 14, 2025, and the table does not mention Exchange Server Subscription Edition. Ask Microsoft or your partner whether the CRM is supported with it.

Routes that keep part of it

  • The legacy Dynamics 365 for Outlook add-in synchronizes email, appointments, contacts and tasks from each user’s Outlook, and Microsoft lets on-premises customers keep using it. It is a COM add-in, and the new Outlook for Windows does not support COM add-ins, so users need classic Outlook. It is not available for queues. Microsoft’s documentation does not say whether the EWS removal affects it, so test it with an Exchange Online mailbox before you count on it.
  • A POP3 and SMTP email server profile carries email only. Appointments, contacts and tasks are not supported with it. Microsoft tested these profiles with Gmail, Yahoo! Mail, MSN, Outlook.com and Windows Live Mail, and says other systems were not tested and are not supported. Exchange Online no longer accepts Basic authentication for POP and IMAP, and the on-premises documentation describes OAuth only for Gmail.
  • Third-party synchronization products and custom integrations on Microsoft Graph replace server-side synchronization with their own. Before you choose one, list what you use today (tracking, queues, appointments, the Outlook app), then ask which of these the replacement covers and where your mail goes on the way.

An EWS endpoint of your own

One more route would keep the CRM’s own synchronization: an EWS endpoint inside your network that accepts the calls of the CRM and carries them out in Exchange Online through Microsoft Graph. The email server profile lets you enter the address of the Exchange server by hand, so in principle the CRM can be pointed at such an endpoint.

Sunsetless EWS is a .NET library that replaces the EWS Managed API in code you compile yourself. The Dynamics 365 server is not your code to recompile, so the library cannot help it. We have not tested such an endpoint with Dynamics 365. We would build it as a separate product that you host yourself, and whether we do depends on what people running the CRM tell us.

If you run Dynamics 365 Customer Engagement (on-premises) with mailboxes in Exchange Online, write to [email protected] and tell us:

  • the version of the CRM, and roughly how many mailboxes and queues it synchronizes;
  • what you synchronize: email only, or appointments, contacts and tasks as well;
  • whether your users work with Dynamics 365 App for Outlook, the legacy add-in, or neither;
  • which route you plan to take today, and when you have to decide.

What to record while it still works

Whichever route you take, you need to know what it has to cover, and that is easier to read off a working system than to reconstruct afterwards. Write down:

  • the email server profiles, and which mailboxes and queues use each;
  • the synchronization method of each mailbox for incoming email, outgoing email, and appointments, contacts and tasks;
  • which users have Dynamics 365 App for Outlook;
  • the application ID that the connection shows in the EWS usage report.

Sources

More guides