SHD / MC Checker

MC1447678 | (Updated) Microsoft Exchange Online: Prepare for Exchange Web Services retirement with EWSAllowedAppIDs



MC1447678 | (Updated) Microsoft Exchange Online: Prepare for Exchange Web Services retirement with EWSAllowedAppIDs

Classification planForChange
Last Updated 08/24/2026 20:19:46
Start Time 08/05/2026 00:24:59
End Time 05/01/2027 07:00:00
Action Required By Date 2026-09-30T07:00:00Z
Message Content

Updated August 24, 2026: We have updated the content. Thank you for your patience. 

[What and why]

Exchange Web Services (EWS) in Exchange Online will begin retirement on October 1, 2026, with full retirement beginning April 1, 2027.

To help organizations prepare, Microsoft has released EWSAllowedAppIDs, a new Exchange Online configuration that allows administrators to create an allow list of application IDs that are permitted to use EWS.

This capability helps administrators identify remaining EWS dependencies, limit EWS access to approved applications, and reduce the risk of service disruption as EWS retirement enforcement begins.

This feature is available today.

[Rollout schedule]

General Availability (Worldwide): Available as of late July 2026

General Availability (GCC): Available as of late July 2026

Retirement milestones:

  • October 1, 2026: Retirement enforcement begins in Exchange Online
  • April 1, 2027: Full retirement begins

[Impact on your organization]

Who is affected

  • Exchange Online administrators
  • Organizations that continue to use applications or services that depend on EWS

Platforms and services

  • Exchange Online
  • Exchange Web Services (EWS)

What will happen

EWSAllowedAppIDs is a tenant-level allow list that enables administrators to explicitly specify which applications can continue using EWS.

Prior to October 2026:

  • If EWSEnabled is not configured (Null), all EWS traffic is allowed.
  • If EWSEnabled=True and no allow list is configured, all EWS traffic is allowed.
  • If EWSEnabled=True and an allow list is configured, only applications included in the allow list and Cross-tenant org relationships can use EWS. If the allow list has no entries, all application can use EWS.
  • If EWSEnabled=False, all EWS traffic is blocked.

Beginning in October 2026:

  • If EWSEnabled=True and no allow list is configured, all EWS traffic except Cross-tenant org relationships will be blocked.
  • If EWSEnabled=False, all EWS traffic will be blocked.
  • Tenants with EWSEnabled not configured (Null) remain subject to Microsoft’s phased retirement process and will have EWS disabled as part of that rollout.

The most important change administrators should understand is that, beginning with retirement enforcement, setting EWSEnabled=True without configuring EWSAllowedAppIDs will no longer permit unrestricted EWS access.

Organizations that require EWS after October 2026 should ensure an EWSAllowedAppIDs allow list is configured and validated before enforcement begins.

Organizations that have EWSEnabled=True and a configured EWSAllowedAppIDs allow list will not have their EWSEnabled setting modified by Microsoft before April 2027.

[Action required and recommendations]

We strongly recommend that Exchange Online administrators begin preparation immediately.

1. Inventory EWS usage

Identify applications and services currently using EWS in your organization.

2. Create and validate an allow list

Create an EWSAllowedAppIDs allow list containing applications that must continue using EWS.

Important considerations:

  • Applications appearing in EWS usage reports that you intend to continue using should be included in the allow list.
  • Microsoft first-party applications that continue to rely on EWS must also be included if they appear in your usage reporting.
  • Setting EWSAllowedAppIDs replaces the existing list. Ensure all required App IDs are included when updating the configuration.

Verify the configured allow list: Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs

The use of RetrieveEwsOperationAccessPolicy is required for performance reasons. The EWSAllowedAppIDs list is only retrieved when explicitly requested. Changes to EWSAllowedAppIDs can take up to 24 hours to take effect. Allow sufficient time after updating the allow list before validating application access or troubleshooting connectivity issues.

3. Prepare for retirement enforcement

Before October 2026:

  • Validate your EWS dependencies.
  • Confirm required applications are included in EWSAllowedAppIDs.
  • Enable EWS only if required for approved applications.

Organizations that complete this work before retirement enforcement begins are less likely to experience service disruption.

Learn more

[Compliance considerations]

Question Answer
Does this change include an admin control? Yes. EWSAllowedAppIDs introduces a new tenant-level administrative control that allows Exchange Online administrators to explicitly define which applications are permitted to access Exchange Web Services (EWS).
Does this change alter how customer data is accessed? Yes. The change modifies how applications are authorized to access Exchange Online data through EWS by requiring administrators to explicitly allow approved application IDs as retirement enforcement begins.
Does this change alter how admins monitor, manage, or demonstrate compliance-related activities? Yes. Administrators must identify EWS dependencies, configure and maintain an EWSAllowedAppIDs allow list, and validate application access as part of preparing for EWS retirement.

Machine Translation

2026年8月24日更新:内容を更新しました。ご辛抱ありがとうございます。 

[何となぜ]

Exchange OnlineにおけるExchange Web Services(EWS)は 2026年10月1日に廃止を開始し、 完全な廃止は2027年4月1日から始まります。

組織の準備を支援するために、Microsoftは EWSAllowedAppIDsという新しいExchange Online構成をリリースしました。これにより、管理者はEWSの使用が許可されているアプリケーションIDの許可リストを作成できます。

この機能は、管理者が残存するEWS依存関係を特定し、承認されたアプリケーションへのEWSアクセスを制限し、EWSの退職執行開始時にサービス中断のリスクを減らすのに役立ちます。

この機能は本日利用可能です。

[展開スケジュール]

一般公開(世界中): 2026年7月下旬現在で入手可能

一般稼働(GCC): 2026年7月下旬時点で利用可能

退職の節目:

  • 2026年10月1日:Exchange Onlineで退職措置が開始
  • 2027年4月1日:完全退職開始

[組織への影響]

影響を受ける人物

  • Exchange Online管理者
  • EWSに依存しているアプリケーションやサービスを引き続き使用する組織

ホームとサービス

  • エクスチェンジ・オンライン
  • Exchange Web Services(EWS)

何が起こるのか

EWSAllowedAppIDs はテナントレベルの許可リストで、管理者がどのアプリケーションをEWSを継続できるかを明示的に指定できます。

2026年10月以前:

  • EWSEnabledが設定されていない(Null)場合、すべてのEWSトラフィックが許可されます。
  • EWSEnabled=Trueで許可リストが設定されていなければ、すべてのEWSトラフィックが許可されます。
  • EWSEnabled=Trueで許可リストが設定されている場合、許可リストに含まれるアプリケーションおよびテナント間組織関係のみがEWSを使用できます。許可リストにエントリがなければ、すべてのアプリケーションがEWSを使用できます。
  • EWSEnabled=Falseの場合、すべてのEWSトラフィックはブロックされます。

2026年10月から:

  • EWSEnabled=Trueで許可リストが設定されていない場合、クロステナント組織関係を除くすべてのEWSトラフィックがブロックされます。
  • EWSEnabled=Falseの場合、すべてのEWSトラフィックはブロックされます。
  • EWSEnabledが設定されていない(Null)のテナントは、Microsoftの段階的廃止プロセスの対象となり 、その導入の一環としてEWSが無効化されます。

管理者が理解すべき最も重要な変更は、リタイアメントの強制から始まると、 EWSEnabled=True を設定せずに EWSAllowedAppIDs を設定すると、EWSへのアクセスが制限されなくなるということです。

2026年10月以降にEWSを必要とする組織は、施行開始前に EWSAllowedAppIDs の許可リストを設定し、検証しておくべきです。

EWSEnabled=Trueで、EWSAllowedAppIDsの許可リストが設定されている組織は、2027年4月以前にはMicrosoftによってEWSEnabled設定の変更は行われません。

[行動が必要と提言]

Exchange Onlineの管理者には直ちに準備を開始することを強くお勧めします。

1. 在庫EWSの使用

組織内で現在EWSを使用しているアプリケーションやサービスを特定しましょう。

2. 許可リストの作成と検証

EWSAllowedAppIDsの許可リストを作成し、EWSを使い続けなければならないアプリケーションを含みます。

重要な考慮事項:

  • EWSの使用報告書に表示され、今後も使用を続ける予定のアプリケーションは許可リストに含まれるべきです。
  • EWSに依存し続けているMicrosoftのファーストパーティアプリケーションも、使用報告に表示される場合は必ず含めなければなりません。
  • EWSAllowedAppIDsを設定すると、既存のリストを置き換えます。設定を更新する際には、必要なすべてのApp IDが含まれていることを確認してください。

設定された許可リストを確認してください: Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy |Format-List EwsAllowedAppIDs

パフォーマンス上の理由から RetrieveEwsOperationAccessPolicy の使用が必要です。 EWSAllowedAppIDs のリストは明示的に要求された場合にのみ取得されます。 EWSAllowedAppIDの変更 は最大24時間かかることがあります。許可リストを更新した後は、アプリケーションアクセスの検証や接続問題のトラブルシューティングを行うまでに十分な時間を確保してください。

3. 退職執行の準備

2026年10月以前:

  • EWSの依存関係を検証しましょう。
  • 必要な申請が EWSAllowedAppIDsに含まれているか確認してください。
  • 承認された申請に必要であれば、EWSを有効にしてください。

退職執行開始前にこの作業を完了した組織は、サービスの中断を経験する可能性が低くなります。

詳しくはこちら

[コンプライアンスの考慮事項]

質問 回答
この変更には管理者の管理も含まれますか? はい。EWSAllowedAppIDsは、Exchange Online管理者がどのアプリケーションがExchange Web Services(EWS)にアクセスできるかを明示的に定義できるテナントレベルの管理制御を導入します。
この変更は顧客データのアクセス方法に影響しますか? はい。この変更は、退職執行開始時に管理者が承認されたアプリケーションIDを明示的に許可することを義務付けることで、EWSを通じてアプリケーションがExchange Onlineのデータにアクセスする方法を変更します。
この変更は管理者がコンプライアンス関連の活動を監視、管理、または示す方法に変化をもたらしますか? はい。管理者はEWS依存関係を特定し、EWSAllowedAppIDsの許可リストを設定し維持し、アプリケーションアクセスの検証を行い、EWSの退職準備の一環として必要です。