NewsSoftware & systems

Microsoft 365's October email change: check your connected apps

Microsoft's EWS retirement reaches a new stage on 10 October. Ask your IT provider which email-connected apps need changes before they stop working.

Halftone envelope marked EWS beside a disconnected plug and socket with a yellow 10 OCT tag on an emerald background.
Illustration: Digital Advisors

An email connection inside another piece of software can be easy to overlook until it stops working. Microsoft 365 customers have a reason to ask about theirs this week.

Microsoft’s 1 October announcement, updated the following day, sets out the next stage of retiring Exchange Web Services, usually shortened to EWS. From 10 October, its worldwide cloud starts requiring an application allow-list for tenants explicitly configured with EWSEnabled=True.

For an owner or office manager, the useful question is straightforward: does any software our business relies on still use this connection, and who is making sure it keeps working?

Which businesses need to check?

EWS lets applications work with Exchange data, including mail, calendars and contacts. Microsoft’s app-discovery guidance tells customers to look for business applications, third-party tools and automation that still depend on it.

The retirement applies to Microsoft 365 and Exchange Online. Microsoft’s background announcement explicitly excludes EWS in on-premises Exchange Server. Businesses with a mixture of server and cloud mailboxes need their provider to identify which connections reach the cloud.

This does not mean all Microsoft 365 email stops on 10 October. It means an application using the retiring connection may need an update, a replacement connection or temporary administrator action. Our Microsoft 365 Business plan comparison explains the broader subscriptions; this week’s check concerns the software connected to your email account.

What happens in October

The latest timetable initially covers Microsoft’s multi-tenant worldwide cloud. Other clouds will receive their own communications and dates through Message Center. Ask your administrator which applies to your organisation.

The new requirement is an app-specific permission list, technically called EWSAllowedAppIDs. For tenants explicitly configured with EWSEnabled=True, that setting alone will no longer be sufficient once the change reaches the account.

Microsoft plans to create lists on 8–9 October, end of day Pacific Time, for certain tenants captured on 2 October: those with EWS explicitly enabled but no list. It will use their previous 60 days of app activity. Administrators who enable EWS after that capture must populate the list themselves.

A subsequent phase switches off EWS for tenants whose setting remains untouched and which have no list. Selected tenants get seven days’ warning in Message Center. That is another reason to have someone responsible for reading those notices.

Ask for an inventory, then a plan

Start with whoever administers Microsoft 365. Microsoft’s discovery guidance points them to the EWS usage report, where available, and Message Center notices headed Update active Exchange Web Services Applications. The next job is identifying the applications, their owners and the mailboxes they use.

Our recommendation is to turn that into a short business list. For each connection, record what staff use it for, who supplies the software and who can test it. A report that names an application is only useful to the office manager once someone explains which task depends on it.

Then ask each supplier whether an update removes the EWS dependency, when it is available and what needs changing. Microsoft recommends moving integrations to supported alternatives, typically Microsoft Graph. Its guidance also recommends validating the result end-to-end.

For example, if a supplier confirms an affected calendar connection, our recommendation is to test that specific booking workflow after the change. Checking that Outlook opens would not answer the same question. This is an illustrative test, not a report of a particular booking product being affected.

A temporary setting needs an end date

Microsoft’s retirement plan says the final shutdown starts 1 April 2027, with no extensions. An administrator’s temporary permission list buys migration time; it does not remove that deadline.

There is room for mistakes in the settings too. Microsoft’s testing guide, updated on 2 October, distinguishes the new EWSAllowedAppIDs list from the older EWSAllowList property. They are different controls. It also warns that allow-list changes need up to 24 hours to propagate. Leave the configuration to the administrator and allow time for testing.

Our recommendation is to arrange the check before Microsoft’s 10 October rollout, rather than wait for a failed connection. Get a named owner and a migration date for anything still dependent on EWS. That gives the business a task it can follow through, instead of a technical warning it cannot interpret.

Checklist

  • Book an EWS check with your Microsoft 365 administrator before the 10 October rollout. Ask them to confirm your cloud’s timetable and review Message Center notices and the usage report, where available.
  • Record each affected business task. Have the administrator identify the connected application, supplier, owner and mailboxes it uses.
  • Confirm any temporary access settings with your administrator. Ask whether the EWSAllowedAppIDs list is needed and correctly configured for the affected applications; allow at least 24 hours for list changes to take effect.
  • Get a migration date from each affected supplier. Plan the move away from EWS before Microsoft’s final shutdown starts on 1 April 2027.
  • Test each affected workflow after the change. Have its business owner check the actual email or calendar task with the supplier or administrator.