Your EWS app list: what to do with each application
The EWS usage report and the allow list name applications by ID. Each application is one of five kinds, and each kind has a different owner and a different way off EWS.
Where the list comes from
Three places name the applications that call EWS in your tenant. Use all three, because each misses something.
- The EWS usage report in Microsoft 365 admin center (Reports, Usage, Exchange, EWS usage). Look at 90 days. New activity can take days to appear.
- The allow list itself. A list that Microsoft created holds only the applications seen in the previous 60 days, so a job that runs once a quarter can be missing.
- The sign-in logs in Microsoft Entra admin center, filtered by the resource Office 365 Exchange Online, for both user and service principal sign-ins.
This command shows the setting and the list:
Connect-ExchangeOnline
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsEnabled, EwsAllowedAppIDsAn application ID is a GUID. To put a name to it, search for the ID under Enterprise applications in Microsoft Entra admin center, with the application type filter cleared. An ID you cannot find there usually belongs to Microsoft or to a vendor. Public lists of known IDs help, for example the list kept by LazyAdmin ↗.
The five kinds of application
| Kind | Who fixes it | What you do now |
|---|---|---|
| Microsoft applications, such as Outlook and Office | Microsoft, through updates | Keep the clients updated. Put the ID on the list if the application shows up in your usage report. |
| A vendor’s product: backup, archiving, CRM sync, room panels, mail clients | The vendor | Ask for the Microsoft Graph version and its date. Keep the ID on the list until you have it. |
| Your own .NET code built on the EWS Managed API | Your developers | Keep the ID on the list. Then rewrite the code for Microsoft Graph or swap the package. |
| Your own scripts, such as PowerShell that loads the EWS library | The owner of the script | Keep the ID on the list. Rewrite the script. |
| Your own code in other languages: Python, Java, raw SOAP | Your developers | Keep the ID on the list. Rewrite the code for Microsoft Graph. |
The allow list keeps an application running until April 1, 2027. After that day EWS in Exchange Online is gone for every application, listed or not.
Microsoft applications
Microsoft moves its own applications off EWS, and you get the change by installing updates. Until a client is updated it still calls EWS and needs its ID on the list like any other application. The retirement guide has the details and the dates.
A vendor’s product
To find out where the product stands, send the vendor these questions and keep the answers with your list:
- Does the product still call EWS in Exchange Online, and from which version does it stop?
- Which application IDs have to be on our EWSAllowedAppIDs list until then?
- When does the Microsoft Graph version ship, and what do we have to do to move to it: an upgrade, new permissions, admin consent?
- Does anything the product does today have no Microsoft Graph API, such as public folders?
The last question matters most for backup and archiving products. Where Microsoft Graph has no API for a feature, the vendor has nothing to move to, and the feature ends with EWS.
Your own .NET code
Code that references the Microsoft.Exchange.WebServices package (the EWS Managed API) has three routes:
- Stay on the allow list. This works only until April 1, 2027.
- Rewrite the EWS calls for Microsoft Graph. A small integration that sends mail or reads one inbox is often quickest to rewrite. In larger code the work is in the testing: item IDs, paging, search and notifications behave differently. See what changes when EWS code moves to Microsoft Graph.
- Keep the code and swap the package. Sunsetless EWS is a build of the EWS Managed API that sends the same calls to Microsoft Graph. Compare the two routes, or run the usage report of the application through the usage checker to see what is covered.
The swap is for code on the Microsoft package. It does not cover the community .NET Standard port with the async API, and it cannot help with public folders or online archives, which Microsoft Graph has no API for today.
Scripts and other languages
A PowerShell script that loads Microsoft.Exchange.WebServices.dll calls EWS like any other application and stops with it. Rewrite it with the Microsoft Graph PowerShell SDK or with Exchange Online PowerShell, depending on what it does.
Code built on exchangelib (Python), the EWS Java API or hand-written SOAP has to be rewritten for Microsoft Graph. A .NET package cannot help there.
What to record for each application
For every application on the list, write down four things: who owns it, what it does, which route it takes, and the date it will be off EWS. When nobody can explain an ID, ask around before October 10, 2026 instead of leaving it on the list for good.