SHD / MC Checker

MC1469960 | Microsoft Exchange Online: Review and configure EWSAllowedAppIDs before Exchange Web Services access changes



MC1469960 | Microsoft Exchange Online: Review and configure EWSAllowedAppIDs before Exchange Web Services access changes

Classification preventOrFixIssue
Last Updated 09/09/2026 22:30:27
Start Time 09/09/2026 22:30:08
End Time 07/30/2027 07:00:00
Message Content

[What and why]

As part of the final phase of Exchange Web Services (EWS) retirement, Microsoft is updating how the EWSAllowedAppIDs setting is applied in Exchange Online. This change is designed to help organizations identify and manage applications that still require EWS access while reducing the risk of unexpected service disruption.

Organizations that continue to use EWS should review and maintain their own EWSAllowedAppIDs list. If a tenant administrator has already configured this list, Microsoft will not overwrite or modify it.

Beginning on October 1, 2026, Microsoft will start enabling this updated behavior by cloud as part of the EWS retirement rollout.

[Rollout schedule]

  • Worldwide, GCC, GCC High, DoD: Beginning in early October 2026 and expected to complete by late June 2027

The updated behavior will apply when the rollout reaches your cloud.

[Impact on your organization]

Who is affected

  • Organizations that continue to use Exchange Web Services (EWS)
  • Exchange Online administrators responsible for managing EWS access
  • Tenants with EWSEnabled set to True or Null

Platforms and services

  • Exchange Online
  • Exchange Web Services (EWS)

What will happen

After the updated behavior is enabled in a cloud:

  • EWS will require a configured EWSAllowedAppIDs list when EWSEnabled is set to True.
  • Before enabling the change, Microsoft will ensure that tenants with EWSEnabled already set to True have an EWSAllowedAppIDs list.
  • If a customer-managed list does not exist, Microsoft will generate a list based on EWS application usage observed during the previous 60 days to help reduce the risk of service interruption.
  • Microsoft-generated lists may omit applications that run infrequently and may include applications that no longer require EWS access.
  • If EWSEnabled remains Null, Microsoft will populate EWSAllowedAppIDs only when a customer-managed list does not already exist. This will occur shortly before Microsoft updates EWSEnabled to False as part of the retirement rollout.
  • Microsoft will not modify an EWSAllowedAppIDs list that has already been configured by a tenant administrator.

[Action required and recommendations]

If your organization still relies on EWS, we recommend taking the following actions as soon as possible:

  • Review EWS usage from the previous 60 days and identify all applications that require continued EWS access, including applications with infrequent usage patterns.
  • Configure and validate your EWSAllowedAppIDs list before the rollout reaches your cloud.
  • Ensure EWSEnabled is set to True if continued EWS access is required.
  • Keep the EWSAllowedAppIDs list current as applications are added, removed, or migrated away from EWS.
  • Plan for up to a 24-hour propagation delay after changes are made to the EWSAllowedAppIDs list.

Microsoft’s safeguard helps reduce the risk of service disruption but does not replace customer review and validation of EWSAllowedAppIDs.

We also recommend continuing plans to migrate applications from EWS to Microsoft Graph before EWS retirement is completed.

Learn more

[Compliance considerations]

No compliance considerations identified, review as appropriate for your organization.

Machine Translation

[何となぜ]

Exchange Web Services(EWS)の最終段階の一環として、MicrosoftはExchange OnlineにおけるEWSAllowedAppIDs設定の適用方法を更新しています。この変更は、組織が依然としてEWSアクセスを必要とするアプリケーションを特定し管理しつつ、予期せぬサービス中断のリスクを減らすことを目的としています。

EWSを引き続き使用する組織は、自社の EWSAllowedAppIDs リストをレビューし、管理すべきです。テナント管理者がすでにこのリストを設定している場合、Microsoftはそれを上書きまたは修正しません。

2026年10月1日から、MicrosoftはEWSの定年退職拡大の一環として、この更新されたクラウド動作の有効化を開始します。

[展開スケジュール]

  • 世界規模、GCC、GCCハイ、DoD:2026年10月初旬から始まり、2027年6月下旬までに完了予定です

更新された動作は、ロールアウトがクラウドに届いたときに適用されます。

[組織への影響]

影響を受ける人物

  • Exchange Web Services(EWS)を引き続き利用している組織
  • Exchange Online管理者がEWSアクセスの管理を担当しています
  • EWSEnabledがTrueまたはNullに設定されたテナント

ホームとサービス

  • エクスチェンジ・オンライン
  • Exchange Web Services(EWS)

何が起こるのか

クラウド上で更新された動作が有効化された後:

  • EWSEnabledTrueに設定されている場合、EWSはEWSAllowedAppIDsリストの設定を必要とします。
  • 変更を有効にする前に、 MicrosoftはEWSEnabled すでにTrue に設定されているテナントに EWSAllowedAppIDs リストがあることを確認します。
  • 顧客管理リストが存在しない場合、Microsoftは過去60日間に観察されたEWSアプリケーション使用状況に基づいてリストを作成し、サービス中断のリスクを減らすのに役立ちます。
  • Microsoft生成のリストは、動作頻度の低いアプリケーションを省略したり、EWSアクセスを必要としなくなったアプリケーションを含む場合があります。
  • EWSEnabledNullのままの場合、Microsoftは顧客管理リストが存在しない場合のみEWSAllowedAppIDを入力します。これは、MicrosoftがEWSEnabledをFalseに更新する直前に行われます。
  • Microsoftは、テナント管理者によって既に設定された EWSAllowedAppIDs リストを変更しません。

[行動が必要と提言]

もし御社が依然としてEWSに依存している場合は、できるだけ早く以下の措置を取ることをお勧めします:

  • 過去60日間のEWS利用状況を確認し、継続的なEWSアクセスが必要なすべてのアプリケーションを特定し、使用頻度の低いアプリケーションも含めてください。
  • EWSAllowedAppIDsリストをクラウドに届ける前に設定・検証してください。
  • EWSEnabledが引き続きEWSアクセスを必要とする場合は、必ずTrueに設定されてください。
  • アプリケーションの追加、削除、またはEWSからの移行が行われるたびに、 EWSAllowedAppIDs のリストを最新の状態に保ちましょう。
  • EWSAllowedAppIDsリストの変更後、最大24時間の伝播遅延を想定してください。

Microsoftのセーフガードはサービスの中断リスクを減らすのに役立ちますが、 EWSAllowedAppIDsの顧客レビューや検証に代わるものではありません。

また、EWSの定番終了前にアプリケーションをMicrosoft Graphへ移行する計画を継続することも推奨します。

詳しくはこちら

[コンプライアンスの考慮事項]

コンプライアンス上の懸念事項は特定されず、組織に応じてレビューしてください。