To allow an application to access Exchange Web Services (EWS) in Exchange Online, add its application ID GUID to the organization-level EwsAllowedAppIDs setting. EWS must also be enabled, and any separate user-agent policy must allow the connection. The commands below set those controls; replace the example placeholders with the app’s actual ID.
What EwsAllowedAppIDs controls
EwsAllowedAppIDs is an Exchange Online organization setting that identifies application IDs permitted to use EWS. It is an access filter, not a way to register an application, grant mailbox permissions, or enable EWS by itself. Microsoft documents the setting in its EWS access-control guidance.
- When
EwsEnabledis$true, only applications on the ID allow list can access EWS. - When
EwsEnabledis$false, EWS access is blocked regardless of the IDs listed. - When
EwsEnabledis$null(not configured), the application-ID setting has no effect.
The setting accepts application ID GUIDs separated by commas and does not support wildcards. To remove the ID restriction, set EwsAllowedAppIDs to $null, as described in Microsoft’s Set-OrganizationConfig reference.
Configure the allow list
- Connect to Exchange Online PowerShell using your organization’s approved administrative process.
- Find the application ID GUID for the intended app in its application registration. Confirm the GUID carefully: this change applies at the organization level.
- If EWS is meant to be available, enable it and set the allowed IDs. Replace the placeholders with real GUIDs; do not enter the angle brackets shown here:
Set-OrganizationConfig -EwsEnabled $true Set-OrganizationConfig -EwsAllowedAppIDs "<app-guid-1>,<app-guid-2>"
Use a single GUID if you are allowing one app. The commands configure the organization-wide EWS state and app-ID filter; they do not grant that application access to a mailbox or configure its authentication.
#1 Best Overall
- Designed for Your Windows and Apple Devices | Install premium Office apps on your Windows laptop, desktop, MacBook or iMac. Works seamlessly across your devices for home, school, or personal productivity.
- Includes Word, Excel, PowerPoint & Outlook | Get premium versions of the essential Office apps that help you work, study, create, and stay organized.
- 1 TB Secure Cloud Storage | Store and access your documents, photos, and files from your Windows, Mac or mobile devices.
- Premium Tools Across Your Devices | Your subscription lets you work across all of your Windows, Mac, iPhone, iPad, and Android devices with apps that sync instantly through the cloud.
- Easy Digital Download with Microsoft Account | Product delivered electronically for quick setup. Sign in with your Microsoft account, redeem your code, and download your apps instantly to your Windows, Mac, iPhone, iPad, and Android devices.
Check for a user-agent policy
Exchange can evaluate an EWS user-agent policy alongside EwsAllowedAppIDs. Microsoft says both checks must pass for a connection to be allowed. An app whose ID is listed can therefore still be blocked if a separate EwsApplicationAccessPolicy:EnforceAllowList policy does not allow its user-agent string.
Microsoft gives Teams Calendar as an example: if allowing the Teams app ID cc15fd57-2c6c-4117-a88c-83b1d56b4bbe, the user-agent list must retain Teams CalendarSkypeSpaces/1.0a$*+ for Teams Calendar to work. These are example values for that case, not values to add to every tenant. Review existing policy before changing it: Microsoft notes that user-agent blocking can also affect REST/Graph API connections.
Rank #2
Verify the organization setting and troubleshoot blocks
Microsoft identifies Get-OrganizationConfig as the organization-level getter. Its documentation does not establish a parameter-specific retrieval command for reliably displaying EwsAllowedAppIDs, so check the current Exchange Online PowerShell reference or your connected shell before relying on a particular switch.
- EWS is unavailable for all apps: Check the organization’s
EwsEnabledstate. A value of$falseblocks EWS regardless of the allow list;$nullleaves the app-ID setting ineffective. - The app is still denied: Confirm the exact application ID, then check whether a user-agent allow-list or block-list also applies. Both the app-ID and user-agent checks must pass when both controls are configured.
- You want to stop filtering by app ID: Set
EwsAllowedAppIDsto$null. This removes the app-ID restriction; it does not override an EWS-disabled state or a separate user-agent policy.
Account for the October 2026 EWS change
Microsoft Learn’s “Control access to EWS in Exchange” page, last updated September 30, 2026, warns that the behavior of EWSEnabled will change in October 2026 due to EWS deprecation. The procedure above reflects the documented configuration, but administrators making changes after that transition should check Microsoft’s current guidance before applying it.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallQuick Recap
Best Value
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

