Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs
🚨 The Signal: Exchange Web Services (EWS) will require explicit application IDs for access by October 2026. This change enhances security by limiting EWS to approved applications, reducing attack surface, and forcing organisations to identify and manage EWS dependencies.
The Impact
Exchange Online administrators are affected, facing a risk of application service disruption if EWSAllowedAppIDs are not configured.
- Exchange Online administrators: Risk of service outages for unlisted EWS applications.
- Organisations using EWS: Potential loss of access for critical applications if not whitelisted.
- Security teams: Improved control over application access to Exchange Online.
- Compliance teams: Enhanced auditability of EWS application usage.
The Action
- Identify all applications currently using Exchange Web Services (EWS) in your tenant.
- For each identified application, determine its AppID (Client ID) from Entra ID.
- Configure the EWSAllowedAppIDs property for your Exchange Online tenant using PowerShell to whitelist these applications.
- Regularly review and update the EWSAllowedAppIDs list as applications are added or removed.
- Plan for migration away from EWS for applications where modern authentication methods are available.
Domain: Exchange · Impact: high · Workload: Exchange Online · Essential Eight: Application Control · ISM: ISM-0843, ISM-1490, ISM-1544, ISM-1582, ISM-1656, ISM-1657, ISM-1658, ISM-1659, ISM-1660, ISM-1870, ISM-1871