Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To allow an application to access Exchange Web Services (EWS) in Exchange Online, add its application ID GUID to the organization-level EwsAllowedAppIDs setting. EWS must also be enabled, and any separate user-agent policy must allow the connection. The commands below set those controls; replace the example placeholders with the app’s actual ID.

What EwsAllowedAppIDs controls

EwsAllowedAppIDs is an Exchange Online organization setting that identifies application IDs permitted to use EWS. It is an access filter, not a way to register an application, grant mailbox permissions, or enable EWS by itself. Microsoft documents the setting in its EWS access-control guidance.

  • When EwsEnabled is $true, only applications on the ID allow list can access EWS.
  • When EwsEnabled is $false, EWS access is blocked regardless of the IDs listed.
  • When EwsEnabled is $null (not configured), the application-ID setting has no effect.

The setting accepts application ID GUIDs separated by commas and does not support wildcards. To remove the ID restriction, set EwsAllowedAppIDs to $null, as described in Microsoft’s Set-OrganizationConfig reference.

Configure the allow list

  1. Connect to Exchange Online PowerShell using your organization’s approved administrative process.
  2. Find the application ID GUID for the intended app in its application registration. Confirm the GUID carefully: this change applies at the organization level.
  3. If EWS is meant to be available, enable it and set the allowed IDs. Replace the placeholders with real GUIDs; do not enter the angle brackets shown here:
    Set-OrganizationConfig -EwsEnabled $true
    Set-OrganizationConfig -EwsAllowedAppIDs "<app-guid-1>,<app-guid-2>"

Use a single GUID if you are allowing one app. The commands configure the organization-wide EWS state and app-ID filter; they do not grant that application access to a mailbox or configure its authentication.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Microsoft 365 Personal | 12-Month Subscription | 1 Person | Premium Office Apps: Word, Excel, PowerPoint and more | 1TB Cloud Storage | Windows Laptop or MacBook Instant Download | Activation Required
  • Designed for Your Windows and Apple Devices | Install premium Office apps on your Windows laptop, desktop, MacBook or iMac. Works seamlessly across your devices for home, school, or personal productivity.
  • Includes Word, Excel, PowerPoint & Outlook | Get premium versions of the essential Office apps that help you work, study, create, and stay organized.
  • 1 TB Secure Cloud Storage | Store and access your documents, photos, and files from your Windows, Mac or mobile devices.
  • Premium Tools Across Your Devices | Your subscription lets you work across all of your Windows, Mac, iPhone, iPad, and Android devices with apps that sync instantly through the cloud.
  • Easy Digital Download with Microsoft Account | Product delivered electronically for quick setup. Sign in with your Microsoft account, redeem your code, and download your apps instantly to your Windows, Mac, iPhone, iPad, and Android devices.

Check for a user-agent policy

Exchange can evaluate an EWS user-agent policy alongside EwsAllowedAppIDs. Microsoft says both checks must pass for a connection to be allowed. An app whose ID is listed can therefore still be blocked if a separate EwsApplicationAccessPolicy:EnforceAllowList policy does not allow its user-agent string.

Microsoft gives Teams Calendar as an example: if allowing the Teams app ID cc15fd57-2c6c-4117-a88c-83b1d56b4bbe, the user-agent list must retain Teams CalendarSkypeSpaces/1.0a$*+ for Teams Calendar to work. These are example values for that case, not values to add to every tenant. Review existing policy before changing it: Microsoft notes that user-agent blocking can also affect REST/Graph API connections.

Verify the organization setting and troubleshoot blocks

Microsoft identifies Get-OrganizationConfig as the organization-level getter. Its documentation does not establish a parameter-specific retrieval command for reliably displaying EwsAllowedAppIDs, so check the current Exchange Online PowerShell reference or your connected shell before relying on a particular switch.

  • EWS is unavailable for all apps: Check the organization’s EwsEnabled state. A value of $false blocks EWS regardless of the allow list; $null leaves the app-ID setting ineffective.
  • The app is still denied: Confirm the exact application ID, then check whether a user-agent allow-list or block-list also applies. Both the app-ID and user-agent checks must pass when both controls are configured.
  • You want to stop filtering by app ID: Set EwsAllowedAppIDs to $null. This removes the app-ID restriction; it does not override an EWS-disabled state or a separate user-agent policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Account for the October 2026 EWS change

Microsoft Learn’s “Control access to EWS in Exchange” page, last updated September 30, 2026, warns that the behavior of EWSEnabled will change in October 2026 due to EWS deprecation. The procedure above reflects the documented configuration, but administrators making changes after that transition should check Microsoft’s current guidance before applying it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.