Exchange Online Drops EWSEnabled=True Fallback on October 10

Microsoft will require explicit EWSAllowedAppIDs entries starting October 10, ending automatic support for legacy application access.

The change

Microsoft is enforcing the EWSAllowedAppIDs requirement for Exchange Online on October 10. Administrators must now list specific application IDs or lose access for any Exchange Web Services calls that previously relied on the EWSEnabled=True setting. The change removes the prior fallback behavior that allowed broad access when the flag was set.

Background and timeline

The update follows a Microsoft message center notice numbered MC1485116. Until now, organizations could keep EWSEnabled=True and continue using applications without listing each one. After October 10 that option disappears. Any app not present in the allowed list will be blocked, creating the possibility of sudden outages for scripts, monitoring tools, and third-party services that depend on EWS.

The policy applies strictly to Exchange Online. On-premises servers retain their existing behavior. Administrators must therefore audit every workload that touches EWS before the deadline and record the corresponding application IDs. Failure to complete the list leaves services exposed to abrupt disconnection rather than a gradual deprecation path.

What administrators must do

The policy change forces tenant administrators to identify every application that still uses EWS and add its ID to the EWSAllowedAppIDs list. Microsoft is ending the automatic acceptance that EWSEnabled=True once provided. No grace period or additional fallback is mentioned in the notice. Organizations that miss an application ID will see those connections fail immediately after the cutoff date.

Preparation requires a complete inventory of EWS clients. This includes internal scripts, monitoring agents, migration utilities, and any third-party tools that connect through Exchange Web Services. Each one must have its application ID extracted and added to the allowed list ahead of the October 10 enforcement. Without that step, the previous broad permission disappears and blocked calls produce immediate failures.

Operational impact

The requirement applies only to Exchange Online. On-premises servers retain their existing behavior. Administrators must therefore audit every workload that touches EWS before the deadline and record the corresponding application IDs. Failure to complete the list leaves services exposed to abrupt disconnection rather than a gradual deprecation path.

Teams that have not maintained an up-to-date record of EWS-dependent applications face the highest risk. Connections that worked under the old flag will stop without further notice once the date passes. The shift places the full responsibility for compatibility on each tenant rather than preserving any automatic allowance.

Why it matters

This enforcement shifts the burden of compatibility onto every tenant that still runs EWS-dependent code. Teams that treated the old flag as a permanent safety net now face a hard stop that can interrupt monitoring, migration tools, and custom integrations without warning. The move reduces the attack surface by limiting which applications can reach Exchange Online, yet it also raises the risk of operational surprises for organizations that have not maintained an inventory of their EWS clients. Administrators who delay the audit until after October 10 will discover the impact only when services stop working.

The change forces a one-time but non-trivial review of every integration path that still touches Exchange Web Services. Organizations with complex environments will spend time mapping application IDs, testing the updated list, and verifying that nothing critical is omitted. Those that complete the work before the deadline avoid outages. Those that do not will encounter hard failures that surface only in production. The policy therefore rewards proactive inventory work and penalizes any assumption that legacy settings will continue to function.

---

Sources:

{
  "sources": [
    {
      "publisher": "Neowin",
      "title": "MC1485116: Exchange Online enforces EWSAllowedAppIDs requirement on October 10",
      "url": "https://www.neowin.net/news/mc1485116-exchange-online-enforces-ewsallowedappids-requirement-on-october-10/?utm_source=rss",
      "published_at": "2026-10-03T11:04:02.000Z",
      "summary": "Microsoft ends fallback support for EWSEnabled=True, forcing administrators to explicitly whitelist required application IDs or risk sudden service outages."
    }
  ]
}

No comments yet