Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Dark navy graphic showing a severed connection in a network of nodes, titled Exchange Web Services Is Being Switched Off

Author: Dan Briggs  |  Published: 30 July 2026  |  Reading time: 16 minutes

Executive summary

Microsoft will begin disabling Exchange Web Services (EWS) across Exchange Online tenants on 1 October 2026, and any tenant that has taken no action will have EWS switched off automatically, according to Microsoft’s message centre notice MC1227454, published on 5 February 2026. EWS is the 20-year-old connection method that a surprising number of business tools still use to reach Microsoft 365 mailboxes: email backup and archiving products, CRM calendar sync, meeting-room booking systems, email signature tools and custom scripts among them. When EWS goes dark for your tenant, those tools stop working, and most businesses have no list of which ones they are.

There is a specific deadline buried in Microsoft’s guidance that matters more than the October date. Tenants that set EWSEnabled to True and populate an application allow list before the end of August 2026 are excluded from the 1 October automatic block, per Microsoft’s July 2026 update on the retirement. Miss it, and you find out which systems depended on EWS the hard way, when they fail. The reprieve is temporary either way: EWS is permanently removed on 1 April 2027 with no exceptions and no ability to re-enable it. This whitepaper explains what EWS is, what actually breaks, how to audit your own exposure in under an hour, and the exact steps to take before 31 August.

What EWS is and why Microsoft is retiring it

Exchange Web Services is an API, a doorway that lets software talk to Exchange mailboxes. It dates back to Exchange Server 2007, and for most of two decades it was the standard way for any third-party product to read email, create calendar entries, look up contacts or move messages around in an Exchange environment. If a product from the 2010s advertised that it could integrate with your email, EWS was almost certainly how it did so.

Microsoft announced in September 2023 that it would retire EWS in Exchange Online, and it has spent the years since telling software vendors to move to its replacement, the Microsoft Graph API. The reasons are the same ones behind the retirement of basic authentication: EWS is an older protocol with an older security model, and Microsoft wants every application reaching into Microsoft 365 to go through a single modern front door with OAuth authentication, granular permissions and better auditing. Graph now offers what Microsoft describes as near-complete parity with EWS, including new Export-Import APIs (currently in preview) built specifically for the backup and migration products that were the last major EWS holdouts, per Microsoft’s deprecation documentation.

Three years of warnings later, the enforcement phase has arrived. In June 2026 Microsoft shipped a new tenant-level control called EWSAllowedAppIDs, which lets administrators name the specific applications still permitted to use EWS. That control is the centrepiece of how the switch-off works, and of how you keep critical tools alive through the transition.

Two boundaries are worth stating plainly before going further. First, this retirement applies only to Exchange Online, the hosted email inside Microsoft 365. On-premises Exchange Server is not affected, though as we covered in our recent piece on Exchange 2016 and 2019 security updates ending in October, on-prem Exchange has its own problems this spring. Second, Microsoft’s own clients and services, including Outlook and Teams, are not affected. This change targets third-party and custom applications, which is exactly why it is so easy to underestimate: your email keeps working on 1 October. It is the quiet machinery around your email that stops.

The timeline: three dates that matter

Microsoft’s retirement plan runs in phases, and each phase changes what your options are. The dates below come from Microsoft’s message centre notice MC1227454 and its Exchange team blog updates, the most recent of which was refreshed on 21 July 2026.

Date What happens What it means for you
Now to 31 August 2026 Configuration window. Admins can set EWSEnabled to True and build an allow list of application IDs that may keep using EWS. Tenants that complete this before the end of August 2026 are excluded from the October automatic block. This is the deadline that decides whether the transition is orderly or disruptive.
September 2026 Microsoft pre-populates an allow list for tenants that have not created their own, based on EWS usage it observes in each tenant. A safety net, not a plan. Microsoft’s automation only lists apps it sees actively using EWS; a backup tool that runs monthly, or a tool used only at quarter end, can be missed. Lists created by admins are left untouched.
1 October 2026 Phased disablement begins. Any tenant with EWSEnabled still at its default (Null) is switched to False, blocking all EWS access. Even where EWS stays on, only allow-listed applications can use it. Unprepared tenants have EWS-dependent tools fail. Admins can still re-enable EWS manually, with a brief interruption, but the clock is running.
1 April 2027 Permanent shutdown. EWS is removed from Exchange Online entirely and the tenant-level controls are withdrawn. No exceptions, no re-enablement, no support tickets that fix it. Every tool must be on Graph or retired by this date.

Microsoft has also flagged that it may run what it calls scream tests before October: short, deliberate EWS outages designed to surface dependencies that nobody documented, per MC1227454. If an integration in your business fails oddly for an hour in the coming weeks and then recovers, that may be why. Treat it as the free warning it is, and write down what broke.

What actually breaks in a typical business

The frustrating part of this change is that EWS is invisible to the people who depend on it. Nobody in your office opens an EWS client in the morning. They open tools that quietly use it underneath, and the categories below cover most of what we find when we audit a tenant.

Email backup and archiving

Third-party mailbox backup, journaling and archive products were built on EWS because for years it was the only API that could read an entire mailbox with full fidelity. Vendors have been migrating to Graph at very different speeds, and some capabilities are being discontinued outright rather than rebuilt. Mimecast, widely deployed among the Australian businesses we support, has published a candid list: its EWS retirement service update confirms that Sync & Recover Restore will be discontinued, that Simply Migrate Archive Mailbox and several Synchronization Engine features (mailbox storage management, managed folders, folder and calendar replication) are being permanently retired, and that Threat Remediation and Continuity customers must move to new Graph connectors. If any part of your retention or recovery story runs through tools like these, you need to know before October which functions survive.

CRM and practice management sync

Calendar, contact and email sync between Microsoft 365 and CRM or practice management platforms is a classic EWS workload, especially in versions deployed more than four or five years ago. Modern releases have generally moved to Graph, but the sync connector configured in 2019 and untouched since is still doing what it was built to do. Law firms, accounting practices, brokers and real estate agencies are the heaviest users of this pattern in our client base, and it is where filing an email against a matter or client record silently stops working.

Meeting rooms, boardroom panels and scheduling tools

Room booking panels outside boardrooms, desk booking systems, and scheduling scripts that query room mailboxes for availability frequently authenticate over EWS. So do some visitor management systems that create calendar invites. These devices are installed, mounted on a wall and forgotten, which makes them prime candidates for a surprise failure on a Thursday morning in October.

Custom scripts and line-of-business glue

Any in-house PowerShell script built on the EWS Managed API, any workflow that sends daily reports into a shared mailbox, any legacy application that files inbound orders or invoices from an email address into a database: these are the dependencies with no vendor to email you a migration guide. If a developer built it, a developer needs to rebuild it against Graph before April 2027 at the latest.

Migration and tenant-to-tenant tools

Mailbox migration products have historically used EWS for bulk data transfer. If you have a merger, acquisition or tenant consolidation planned for late 2026 or 2027, confirm your migration tooling supports Graph now, because an EWS-based migration scheduled for November is a project plan with a hole in it.

What is not affected

Outlook on Windows, Mac, web and mobile keeps working, as do Teams and other Microsoft services. On-premises Exchange Server keeps EWS. And the multifunction printers and scan-to-email devices in your office are a separate issue entirely: those use SMTP, which has its own switch-off coming, covered in our guide to Microsoft disabling basic authentication for scan-to-email in December. It is an unhelpful coincidence that both changes land within weeks of each other, but they are different plugs being pulled from different sockets.

Why Australian SMBs are more exposed than they think

Across the client environments we audit in Sydney, Brisbane, Melbourne and the Central West, a consistent pattern shows up: the businesses carrying the most EWS debt are the ones that moved to Microsoft 365 earliest. A firm that migrated in 2016 or 2017 bought its integrations, backup tools and CRM connectors in a world where Graph barely existed, so everything it bolted on spoke EWS. A business that came to the cloud in 2023 mostly missed the problem by accident. Early adopters are being punished for their punctuality, and many of them have no idea.

The problem is sharpest in regional areas. In Orange, Bathurst and Dubbo we regularly take over environments that were set up by an integrator who has since closed, retired or moved on, leaving no documentation of which applications were ever connected to the tenant. The room panel vendor was paid once in 2018. The backup product renews on a credit card nobody checks. When we run an EWS audit on tenants like these, we almost always find at least one active dependency the business could not name, and in professional services firms it is usually the one doing email filing or mailbox backup, which are precisely the functions you cannot afford to lose quietly.

The shape of a typical audit result is worth sharing. In a mid-sized professional services tenant we commonly find four to six distinct application IDs making EWS calls: a backup or archiving product, a CRM or practice management connector, a room booking service, and one or two entries nobody recognises. The unrecognised ones usually turn out to be a trial installed years ago that kept its mailbox permissions, or a tool belonging to a former staff member’s workflow. Those abandoned entries matter beyond October planning, because an application with standing access to every mailbox in the business is a security exposure in its own right. The EWS retirement is, in that sense, a useful forcing function: the same audit that keeps your backups running is the one that finally revokes access nobody should still have.

October 2026 also happens to be a crowded month to be an Australian business running older Microsoft infrastructure. The same month EWS starts switching off, security updates for Exchange Server 2016 and 2019 stop, and the first year of Windows 10 Extended Security Updates runs out. None of these is individually unmanageable. Landing together, in the quarter that includes Christmas trading for hospitality and retail clients, they argue strongly for doing the EWS work in August rather than adding it to an October pile. Our State of IT for Australian SMBs in 2026 report goes deeper on this cluster of end-of-support deadlines and what they mean for planning.

How to find your EWS dependencies in under an hour

You do not need to guess whether this affects you. Microsoft 365 records exactly which applications are using EWS in your tenant, and there are three places to look.

The EWS usage report. In the Microsoft 365 admin centre, the usage reports section includes an Exchange EWS usage view showing which applications have made EWS calls, per Microsoft’s July 2026 guidance. This is the fastest first pass and requires nothing more than admin access and ten minutes.

Entra sign-in logs. For a more forensic view, the Entra admin centre’s sign-in logs can be filtered for EWS activity, showing the application IDs, service principals and accounts involved. Practical walkthroughs, including a ready-made script for extracting the list, are available from the Office 365 for IT Pros team’s guide to finding active EWS apps in Microsoft 365. The application IDs this surfaces are exactly what you need for the allow list.

PowerShell. Checking your tenant’s current posture takes one line in Exchange Online PowerShell: Get-OrganizationConfig | Format-List EwsEnabled. If that returns blank (Null), your tenant is on the default track and will be switched off automatically on 1 October.

Then match what the logs show against reality. For every application you find, ask the vendor three questions in writing: has this product fully migrated to Microsoft Graph; if not, what is the date; and what do we need to change on our side before October 2026. A vendor that cannot answer in a fortnight is telling you something useful too. Remember the September caveat: Microsoft’s auto-generated allow list is built from observed usage, so anything that connects infrequently, like a quarterly reporting tool or an annual archive job, can be absent from it. Your own audit catches what Microsoft’s automation cannot see.

It helps to know what a reassuring vendor answer looks like, because you will receive some vague ones. A good answer names the product version or release that uses Microsoft Graph, tells you whether you need to upgrade or reconfigure anything, gives you the application ID the product uses so you can confirm it in your own sign-in logs, and commits to a date. A worrying answer talks about a roadmap without dates, suggests you simply enable the allow list and revisit later, or assures you the product is unaffected without explaining how it connects to your mailboxes. Vendors have had since September 2023 to do this work; three years in, an inability to answer these questions in writing is a finding in itself, and worth weighing when the product next comes up for renewal.

The action plan before 31 August

Here is the sequence we are running for managed clients, in the order that protects you fastest.

# Action Who When
1 Pull the EWS usage report and sign-in log data; build the list of applications still using EWS in your tenant IT provider or internal admin This week
2 Classify each app: business-critical, replaceable, or unknown/abandoned Business owner with IT First week of August
3 Contact every vendor on the critical list for their Graph migration status and dates, in writing IT provider First week of August
4 Set EWSEnabled to True and populate the allow list with the application IDs that must keep working IT provider or internal admin Before 31 August 2026
5 Migrate or upgrade the apps with a Graph path available (for example Mimecast connector migrations); retire the abandoned ones IT provider with vendors September to December 2026
6 Rebuild custom scripts against Microsoft Graph; test and decommission their EWS versions Developer or IT provider Before 1 April 2027
7 Diarise a final check that the allow list is empty of anything you still need, before the permanent shutdown IT provider February 2027

Step 4 deserves emphasis because it is cheap insurance. Configuring the allow list before the end of August does not commit you to anything; it simply guarantees that nothing in your business stops on 1 October while the slower migrations play out. The allow list buys you until 1 April 2027, and not a day more, so steps 5 and 6 still need dates against them.

If you miss the deadline

Suppose it is 2 October, the boardroom panel is blank, mailbox backups failed overnight and email filing to the CRM has stopped. What then? The recovery path exists, but it is uncomfortable. An administrator can manually set EWSEnabled back to True after the automatic block, and Mimecast’s guidance notes there will be a brief service interruption while the change takes effect. You will still need the allow list populated for the affected applications, which means doing the audit described above under pressure instead of on a quiet afternoon in August.

The harder failure mode is the silent one. A blank room panel announces itself; a backup job that stops running does not. If nobody is monitoring backup completion, an October EWS block can mean discovering in December, when you need a restore, that you have two months of missing history. That scenario, not the visible outage, is the one that should push this onto this week’s agenda. And whatever happens in October, the April 2027 date is absolute: Microsoft has been explicit that after 1 April 2027 there is no re-enablement under any circumstances.

How All IT Services can help

We are running EWS exposure audits for businesses across Sydney, Brisbane, Melbourne and Central West NSW: a review of your tenant’s actual EWS traffic, a plain-English list of which of your tools are affected and what each vendor’s migration path looks like, the allow-list configuration done before the August cut-off, and a managed plan for the migrations that need to follow. For most SMB tenants the audit is a small, fixed piece of work, and it is considerably cheaper than reconstructing a backup chain or rebuilding a CRM integration after it fails. Call us on 1300 425 548 or get in touch online and we will tell you, before the end of August, exactly where you stand.

Frequently asked questions

Does the EWS retirement affect on-premises Exchange servers?

No. The retirement applies only to Exchange Online, the hosted email service inside Microsoft 365. EWS on Exchange Server 2016 and 2019 keeps working, although those products stop receiving security updates in October 2026, which is a separate and arguably bigger problem.

What happens if we do nothing before 1 October 2026?

If your tenant has never had its EWSEnabled setting configured, Microsoft switches it to False during the October rollout and every application still using EWS in your tenant stops working. An administrator can re-enable it afterwards, with a short interruption, but only until 1 April 2027, when EWS is removed permanently.

Will Outlook or Teams stop working when EWS is disabled?

No. Microsoft states that its own clients and services, including Outlook and Teams, are not affected by this change. The retirement targets third-party and custom applications that connect to Exchange Online mailboxes, such as backup tools, CRM sync connectors, room booking systems and in-house scripts.

How do we find out which of our apps still use EWS?

Check the EWS usage report in the Microsoft 365 admin centre, review Entra sign-in logs for EWS activity, and run Get-OrganizationConfig in Exchange Online PowerShell to see your current EWSEnabled setting. Then confirm the Graph migration status of each application you find with its vendor. An IT provider can run this whole audit in a few hours.

Can we keep using EWS after October if we need more time?

Yes, temporarily. Setting EWSEnabled to True and adding your applications to the allow list before the end of August 2026 keeps EWS working for those apps and excludes your tenant from the October automatic block. That extension runs until 31 March 2027 at the latest. From 1 April 2027 EWS is shut down permanently with no exceptions.