Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use the app registration’s Application (client) ID GUID—not its Directory (tenant) ID. Find it in Microsoft Entra, then compare it with Exchange Online’s configured list using Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy.

Find the app’s Application (client) ID

  1. Sign in to the Microsoft Entra admin center with access to the tenant that contains the app registration.
  2. Confirm that the selected tenant is the one used by the Exchange Online integration.
  3. Open App registrations, find and select the application that connects to Exchange Online through EWS, and go to its Overview page.
  4. Copy Application (client) ID. It is a GUID that identifies the application. Do not use Directory (tenant) ID, which identifies the tenant. Microsoft’s app registration guidance distinguishes these two values.

Check the configured EwsAllowedAppIDs list

Connect to Exchange Online PowerShell with an appropriately authorized administrator account, then run:

Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs

The -RetrieveEwsOperationAccessPolicy switch retrieves the configured app IDs. Compare the output GUIDs with the client ID from the app registration. Exchange Online’s Set-OrganizationConfig reference documents the parameter and retrieval switch.

This is a read-only lookup. Do not change organization configuration until you have confirmed the application and tenant used by the integration. For multiple app IDs, Microsoft documents comma-separated GUID values; setting the parameter to $null removes the configured IDs and stops restricting access by app ID, so that is a configuration change, not a lookup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Understand what the setting controls

EwsAllowedAppIDs is an Exchange Online organization setting for application IDs. Its effect depends on EwsEnabled:

  • When EwsEnabled is $true, only applications listed by ID can use EWS.
  • When EwsEnabled is $false, EWS access is blocked regardless of the app ID list.
  • When EwsEnabled is $null, the app ID parameter has no effect.

The app-ID restriction applies to direct EWS SOAP connections. It does not apply to Microsoft Graph API requests or the REST endpoint, according to Microsoft’s EWS access-control guidance.

If the correct app ID is still blocked

Check whether the tenant also enforces an EWS user-agent allow list. Exchange evaluates the app-ID and user-agent policies for each connection; both must allow it. The user-agent policy uses a string rather than an app ID, and its scope can include EWS and REST. It is a separate check, not another place to enter the client ID.

Microsoft’s example explains that allowing the Teams app ID without retaining the required Teams Calendar user agent can block Teams Calendar. For an integration that remains blocked, verify both the application ID and the connection’s user-agent against the policies configured for the tenant.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Account for EWS retirement

Finding the ID can help diagnose an existing EWS integration, but it does not change EWS’s retirement schedule. Microsoft’s EWS access-control article, updated September 30, 2026, says the way EWSEnabled operates will change in October 2026. Microsoft’s Exchange Online cross-tenant authentication guidance, updated August 15, 2026, describes phased EWS retirement beginning in October 2026, with complete retirement by April 2027. For the specific Power Platform cross-tenant email synchronization scenario, that page says the transition from EWS to Graph is planned by April 2027. Check Microsoft’s latest retirement guidance before planning a deployment or migration.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.