Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Starting October 10, 2026, enabling Exchange Web Services (EWS) with EwsEnabled = $true will no longer be sufficient for affected Exchange Online tenants. Administrators must also configure EwsAllowedAppIDs with the application IDs permitted to use EWS. Applications absent from the list may lose access. Microsoft’s Message Center notice, reproduced in an archive, says the rollout spans Worldwide, GCC, GCC High, and DoD tenants, starting in early October 2026 and expected to finish by early July 2027.

What changes on October 10, 2026?

When an organization has EWS enabled, only the Azure application IDs in EwsAllowedAppIDs will be permitted to access EWS under the change described in MC1485116. Having EwsEnabled = $true without an appropriate app-ID list will no longer be enough; applications not included may lose access. Microsoft Learn defines the parameter as identifying the applications allowed to access EWS when EwsEnabled is $true (Microsoft’s Exchange PowerShell reference).

The rollout details and dates below are from an archived reproduction of Microsoft Message Center notice MC1485116 (MC1485116 archive), not from a live Message Center tenant notice.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Worldwide tenant milestones

  • October 2, 2026: Microsoft identifies affected Worldwide tenants. After this date, tenants that enable EWS must configure their own app-ID list.
  • October 8–9, 2026: Microsoft creates and populates lists for qualifying tenants using EWS activity observed during the preceding 60 days.
  • October 10, 2026: The allow-list requirement takes effect for EWS-enabled tenants; applications missing from the list may lose access.

The notice says the wider rollout across Worldwide, GCC, GCC High, and DoD tenants begins in early October 2026 and is expected to complete by early July 2027. The October 2–10 milestones above are specifically given for Worldwide tenants.

Which EWS settings and tenant states are affected?

The interaction between the organization-level EWS switch and the app-ID list determines access. Microsoft documents the following behavior:

EwsEnabled state Effect of EwsAllowedAppIDs
$true Only applications whose IDs are on the list are allowed under the documented policy. Unlisted applications are blocked.
$false All EWS access is blocked, regardless of the list.
$null The app-ID list has no effect. The separate phased EWS retirement process still applies.

These behaviors are documented in Microsoft’s Exchange PowerShell reference. The archived notice also says tenants with EWS enabled and an already configured app-ID list will not have that EWS-enabled setting modified by Microsoft before April 2027. It separately states that cross-tenant organization relationships are not affected by this allow-list requirement.

How to inspect and maintain the app-ID list

Retrieve the configured IDs

Use Exchange Online PowerShell to display the organization’s current value:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy |
Format-List EwsAllowedAppIDs

The retrieval switch is included in the notice’s command. Confirm the output against your organization’s current application inventory and usage reporting.

Preserve every required application when changing the list

The archived notice describes EwsAllowedAppIDs as a replacement list. When you update it, include every application ID that must retain access; do not assume a new value simply adds one ID to the existing list. Microsoft documents the IDs as GUIDs and multiple values as a comma-separated list in the parameter reference.

Allow time for changes to take effect

The archived notice estimates up to 24 hours for app-ID list changes to take effect and about one hour for changes to EwsEnabled. These are notice estimates and are not stated in the retrieved Microsoft parameter reference.

Why automatic population may not be a complete inventory

For qualifying Worldwide tenants, the notice says Microsoft will use EWS activity seen in the previous 60 days to populate the list on October 8–9, 2026. That makes the generated list a useful starting point, not proof that every required integration has been captured: infrequently run jobs or seasonal processes may have no activity in that observation window. The notice leaves validation and ongoing maintenance to each organization.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review application IDs alongside usage reporting and operational knowledge. Pay particular attention to workloads whose cadence makes recent activity an unreliable indicator of future need, and ensure the IDs for those integrations are retained before relying on the enforced list.

Applications and scenarios to review

MC1485116 names several Microsoft products and scenarios that can generate EWS traffic. The notice does not establish that every named workload is affected in every tenant; check your own usage and deployment versions.

  • Outlook for Windows
  • Classic Outlook for Mac: The notice distinguishes it from new Outlook for Mac and says to include the Office app ID when Classic Outlook for Mac remains in use.
  • Excel Power Query and Power BI
  • Exchange Server hybrid scenarios

Use those examples as prompts for tenant-specific verification, not as a universal list of required IDs.

Do not confuse the two allow-list settings

EwsAllowedAppIDs uses Azure application IDs. Microsoft also documents EwsAllowList, a separate application-access policy based on user-agent strings. EwsAllowList does not replace the app-ID list required by MC1485116; see the distinction in Microsoft’s parameter reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Plan for EWS retirement beyond this milestone

The October 2026 app-ID requirement is a control on EWS access, not a cancellation of the broader retirement. Microsoft Learn says EWS will begin to be disabled globally in Exchange Online in October 2026 and is planned to be fully disabled in April 2027. Microsoft recommends identifying EWS use by internal and third-party applications and planning migration (Microsoft’s EWS retirement guidance).

Do not assume Microsoft Graph offers a one-to-one replacement for every EWS workflow. Microsoft’s retirement documentation identifies capabilities without a Microsoft Graph equivalent in the documentation, including generic Public Folder CRUD, generic Microsoft 365 Group mailbox CRUD, and legacy Discovery Mailbox access. Map each dependency to its actual workflow and verify the supported migration path.

Skype for Business Server hybrid has separate prerequisites and dates. Microsoft’s workload-specific guidance says eligible deployments must configure EWS and the required app IDs to keep legacy calls working during the transition, then install a planned server update that replaces those calls with Microsoft Graph before full EWS retirement. If Skype for Business Server is in scope, follow that guidance rather than treating its timeline as identical to the general allow-list milestone (Microsoft’s Skype for Business Server hybrid guidance).

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.