Purpose
Microsoft is retiring Exchange Web Services in Exchange Online. This article explains what happens on the retirement dates, what ENow has already done about it, what you need to do, and what to do if you cannot upgrade before the deadline.
The dates
- October 2026 — Microsoft begins disabling EWS globally for all organizations, blocking EWS requests from non-Microsoft applications to Exchange Online.
- April 2027 — EWS is fully disabled.
Two things worth being clear about, because both catch people out:
October is a rollout, not a single switch. Microsoft disables EWS progressively across organizations from October 2026. If nothing breaks for you in the first week of October, that does not mean your tenant is exempt — it means your turn has not come yet.
April 2027 is not your deadline. October is. By April there is nothing left to migrate, because it will already have stopped working.
This is about Exchange Online only
Worth stating plainly, because hybrid customers reasonably worry about it: the retirement applies to Exchange Online. Exchange Server on-premises is unaffected. Microsoft does not support Graph against on-premises mailboxes, so on-premises monitoring continues to use EWS and will keep doing so.
If you run hybrid, only the Exchange Online side of your monitoring is affected.
What ENow has done
The Exchange Online monitoring tests in the ENow Management System have been migrated from EWS to Microsoft Graph. They keep running with EWS disabled in your tenant, and your thresholds, baselines, alert rules and historical latency data are preserved — there is nothing to reconfigure after you upgrade, and no gap in your trend history. The underlying API changed; the measurements did not.
Some tests were renamed
The migration changed what several tests actually do, so their names changed to match:
| Was | Now |
| EWS Logon | Mailbox Sign-In |
| OWA Logon | OWA Reachability |
| Collaboration (MAPI Client) | Mailbox Functions |
The OWA test changed in substance as well as name: it no longer signs in, reads no mailbox and uses no token, so it now works for customers using a stored MFA token credential. Its latency threshold is correspondingly renamed. Mailbox Sign-In still requires a password.
Read-receipt and RTF sub-tests have been removed.
Test name enums, result types, threshold names, latency keys, alert categories and page URLs are unchanged, so integrations and saved links keep working. It is the display names you will notice.
What you need to do
1. Upgrade to the current GA release
Upgrade the ENow Management System to the current GA release. The Graph-based tests are included there.
If you are several versions behind, check the upgrade path before you start — a stepped upgrade through an intermediate release may be required rather than going straight to the latest. ENow supports the current GA release and the two releases before it; see ENow Version Support Policy, and Windows Server Compatibility.
2. Re-consent the Exchange Online Tester app registration
After upgrading, the Exchange Online Tester app registration needs to be re-consented so that it is granted the new Microsoft Graph permissions. The upgrade adds the permission requirements; the consent has to be granted in your tenant.
This step is required. Without it the tests have the code path but not the permissions, and they will fail once EWS stops answering.
3. Run Verify Credential
In the Admin Console, run Verify Credential to confirm the test account is working against the new permissions. A 403 indicates a missing permission and asks you to re-run this check after granting it.
A successful verification is your confirmation that the migration is complete for your environment. Do not treat the upgrade alone as sufficient — run the check.
If you cannot upgrade before October
There is an interim measure. Microsoft's block applies to applications that have not been allow-listed in your tenant, so you can keep EWS working for ENow specifically while you schedule the upgrade.
Add ENow's application ID to the allowed list in Exchange Online PowerShell:
Set-OrganizationConfig -EwsAllowedAppIDs @{Add="1babc55c-ccea-49de-83a0-fa69178cdbc6"} -EwsEnabled $true
Do this before 1 October 2026. Treat it as a bridge, not a solution — it buys time until the upgrade, and it stops working entirely when EWS is removed in April 2027.
Confirming you are ready
- You are on the current GA release.
- The Exchange Online Tester app registration has been re-consented since that upgrade.
- Verify Credential passes in the Admin Console.
If tests start failing
If Exchange Online tests begin failing around or after the October 2026 rollout, work through the three checks above before anything else — in the great majority of cases the missing item is the re-consent in step 2, because an upgrade can complete successfully without it and nothing fails until EWS stops answering.
If all three check out and tests are still failing, open a case and say explicitly that you have completed the Graph migration steps and that Verify Credential passes. That rules out the common cause immediately.
Government and national clouds
The Graph-based Exchange Online tests do not currently cover GCC tenants, and other national clouds are out of scope. If you operate in a government cloud, raise a case to discuss your options rather than assuming the migration path above applies to you.
References
- Microsoft Learn — Deprecation of Exchange Web Services in Exchange Online, for the current retirement timeline.
Comments
0 comments
Please sign in to leave a comment.