Recommended Free Tools
Microsoft’s Exchange Online Admin API is a Preview REST interface for a limited set of Exchange administration tasks. It exposes selected cmdlets and parameters through POST-only endpoints; it is not a complete replacement for Exchange Online PowerShell or a universal replacement for EWS. To use it, administrators must configure Microsoft Entra app permissions and consent, assign Exchange RBAC roles, and obtain an OAuth token.
What is the Exchange Online Admin API?
Microsoft describes the Exchange Online Admin API as “a REST-based administrative surface that enables a focused set of Exchange cmdlets and parameters as POST-only endpoints.” In practical terms, it lets supported applications make HTTP requests for certain administrative operations rather than invoking PowerShell cmdlets. Microsoft Learn’s overview describes its purpose and current limitations.
This is a focused interface, not a general Exchange resource model like Microsoft Graph. Its operations use POST requests, and only documented scenarios and parameters are in scope. The API remains in Preview: it may not be available in every organization, and Microsoft may change its behavior.
Which Exchange Online Admin API endpoints are available?
Microsoft’s endpoint reference currently groups supported operations into these families:
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- AcceptedDomain
- DistributionGroupMember
- DynamicDistributionGroupMember
- Mailbox
- MailboxFolderPermission
- OrganizationConfig
These families cover selected tasks such as viewing organization configuration—including accepted domains, MailTips configuration, and mailbox limits—managing distribution-group membership, and working with mailbox or folder permissions. The family names are not a promise that every operation or parameter in the corresponding PowerShell area is available. Check the current endpoint reference for supported operations, parameters, and response fields before building an integration.
How do you authenticate to the Exchange Online Admin API?
Authentication requires more than adding a permission string to an app. Microsoft documents both delegated access, which acts in the context of a signed-in user, and app-only access for a service principal. In either case, API permission consent and Exchange RBAC authorization are separate requirements: the Entra permission enables the app to request access, while the Exchange role assignment limits what it can administer.
Rank #2
- Register an application. Create an app registration in Microsoft Entra ID and decide whether the integration needs delegated or app-only access.
- Request the matching Exchange permission. Use delegated
Exchange.ManageV2or app-onlyExchange.ManageAsAppV2, as appropriate for the flow documented by Microsoft. - Obtain organization admin consent. A tenant administrator must grant consent for the requested permission.
- Assign appropriate Exchange RBAC roles. Grant the user or service principal roles that cover only the objects and actions the integration needs. Consent alone does not confer the necessary Exchange administrative rights.
- Acquire an OAuth access token. Use the applicable delegated or app-only flow, then send the token with API requests. Protect tokens as credentials and avoid logging them.
- Set the tenant and request context. Follow Microsoft’s getting-started guidance for the tenant context and API base URL. It also covers pagination and the
X-AnchorMailboxrouting header, where applicable.
Microsoft’s authentication and authorization guidance and getting-started instructions provide the implementation details. Use least privilege for both the app permission and Exchange role assignment.
Does the Admin API replace Exchange Online PowerShell?
No. Microsoft explicitly distinguishes the API’s focused set of supported tasks from the broader Exchange Online PowerShell management surface. The API may suit an application or HTTP-based workflow when its required operation is documented, but an administrator should not assume that an existing script or cmdlet has an equivalent endpoint. Check each required operation and parameter against the endpoint reference; use PowerShell when the task falls outside that documented scope.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Is the Exchange Online Admin API a replacement for EWS?
Not across the board. Microsoft presents the API as a REST-based option for selected administrative scenarios that organizations may have handled through EWS. That supports evaluating it for a specific task, not assuming that it provides complete EWS parity. Map the EWS-dependent operation to a documented Admin API endpoint before planning a migration. The available documentation cited here does not establish an EWS retirement date or coverage for every EWS workload.
Preview behavior also matters for migration work: Microsoft’s announcement says responses may contain extra properties, but only properties documented for each endpoint are expected to be available at general availability. Build against documented fields rather than relying on additional preview-only properties, and allow for changes as the API evolves. See Microsoft’s public preview announcement.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Is the Exchange Online Admin API generally available?
No. Microsoft’s documentation identifies it as a Preview feature. Availability may vary by organization, and preview endpoints, behavior, or response properties may change. Treat it as a feature to evaluate against a concrete supported use case, not as a stable, universally available production contract.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

