EWS Retirement Enters Its Final Stage: What MigrationWiz Users Should Know

Introduction: Exchange Web Services (EWS) has supported many Exchange Online migration projects for years. Now, Microsoft is moving into the final phase of EWS retirement. For organizations using MigrationWiz with Exchange Online, this change should not be treated as a future concern. Some configuration work is already required.

Microsoft has introduced EWSAllowedAppIDs, which allows Microsoft 365 administrators to decide which applications can continue using EWS. If your MigrationWiz project uses EWS and Exchange Online is involved, the required application ID needs to be allowed. In this guide, we will explain what is changing, what MigrationWiz users need to configure, and how to protect mailbox data before starting a migration.

What Is EWS and Why Is Microsoft 365 EWS Retirement?

Exchange Web Services (EWS) is a Microsoft technology that allows applications to work with Exchange mailbox data. It has been widely used to access emails, calendars, contacts, and other mailbox information. 

Microsoft is gradually moving Exchange Online toward newer APIs and technologies. Because of this change, EWS is being retired in stages rather than being switched off all at once.

The final phase brings tighter control over applications that still need EWS access. Microsoft has introduced EWSAllowedAppIDs to help administrators manage this access. For migration teams, this means EWS settings should now be checked as part of the normal migration preparation process.

What Is EWSAllowedAppIDs?

EWSAllowedAppIDs is an allow list that Microsoft 365 administrators can use to specify which applications are permitted to access EWS. In simple terms, an administrator can identify an approved application by its Application (client) ID and add that ID to the tenant’s EWS allow list.

This is crucial to MigrationWiz users because when performing migrations based on EWS, you might require the application ID used in the authentication of Microsoft 365. It also helps give more control to administrators concerning third-party applications trying to access Exchange Online.

What MigrationWiz Users Need to Do

  1. Set up Modern Authentication fully: Sign in and configure the required Microsoft 365 app needed for migration.
  2. Find the Application (Client) ID: This is the ID for the registered app used for authentication purposes.
  3. Add the App ID to EWSAllowedAppIDs: Add the required application ID to the Microsoft 365 tenant’s EWS allow list.
  4. Check the configuration: Make sure the correct App ID has been added and there are no typing errors.
  5. Wait for some time to get it done: It is better to wait and not make changes before migration.
  6. Test the connection: Run a test before moving the complete set of mailboxes.

Why the October 1, 2026 Deadline Matters

The October 1, 2026 date is an important point in the Exchange Online EWS retirement timeline. Microsoft is introducing stricter EWS access rules for tenants that continue to have EWS enabled but do not configure the required application allow list.

Once the new behavior applies to a tenant, applications that are not included in the allowed list may no longer be able to use EWS. For this reason, migration teams should not wait until the deadline is close. If a migration is planned for the coming months, EWS configuration should be reviewed during the planning stage.

Microsoft has also been communicating the upcoming changes through the Exchange Team. The earlier article Exchange Online EWS, Your Time is Almost Up provides additional background on the retirement.

Allow Time for Microsoft 365 Changes

One point that migration administrators should keep in mind is that configuration changes may not become active immediately. Therefore, adding an App ID just before a migration is not a good idea. After making the change:

  • Verify that the App ID is present.
  • Record the current allow-list configuration.
  • Give Microsoft 365 enough time to apply the change.
  • Test the migration connection.
  • Run a small migration before starting the full project.

Take a Backup Before Starting the Migration

EWS configuration is only one part of migration preparation. In addition to that, it would be prudent to maintain a duplicate copy of the relevant mailbox data before undertaking significant modifications to the Microsoft 365 environment. The backup will come in handy in situations where certain items are skipped during the migration process, or the migration process gets stalled halfway.

The SysInfo Office 365 Backup Tool can be considered as part of a pre-migration backup plan. The tool is designed to back up Office 365 mailbox data and save it in formats such as PST, PDF, EML, MBOX, and CSV. It can be useful for:

  • Support for large Office 365 emails, contacts, and calendars with accuracy.
  • Features like Remove Duplicate, Date Filter, Attachment handling, and more.
  • Secure authentication mode using Modern or Admin Impersonation.
  • Maintains the original email formatting structure and metadata.
  • Highly compatible with all Windows, Mac, or Linux versions.

Why You Should Test Before the Migration

A full mailbox migration can involve hundreds or thousands of users. Discovering an Exchange Web Services retirement or authentication problem after the migration has started can cause unnecessary delays. A small test migration gives administrators a chance to check:

  • Microsoft 365 authentication
  • EWS access
  • Application permissions
  • EWSAllowedAppIDs configuration
  • MigrationWiz endpoint settings
  • Mailbox access
  • Folder and message migration

Final Words

Microsoft’s EWS retirement is an important change for organizations planning Exchange Online migrations with MigrationWiz. The introduction of EWSAllowedAppIDs gives administrators a way to control which applications can continue using EWS during the transition. Before starting a migration, review the tenant’s EWS settings, complete the required authentication setup, identify the correct Application ID, configure the allow list where required, and test the connection.

It is also sensible to back up important mailbox data before the full migration begins. A separate backup can provide an extra layer of protection if the migration is interrupted or some data needs to be checked later. Most importantly, do not leave EWS preparation until the migration day. Review the environment early, test with a smaller mailbox set, and keep your configuration documented.

Frequently Asked Questions

Q1. What should MigrationWiz users do before the EWS retirement deadline?

Ans. MigrationWiz users should review their Microsoft 365 EWS settings, complete the required Modern Authentication setup, identify the correct Application (Client) ID, and add it to EWSAllowedAppIDs when required. A test migration should also be completed before moving all mailboxes.

Q2. How long does it take for EWS configuration changes to take effect?

Ans. Microsoft 365 configuration changes may take some time to apply. After updating EWSAllowedAppIDs, administrators should allow sufficient time for the change to take effect and then test the connection before starting the migration.

Q3. Should I test MigrationWiz before migrating all mailboxes?

Ans. A small test migration can help confirm that authentication, EWS access, application permissions, mailbox access, and MigrationWiz endpoint settings are working correctly.

Q4. What Microsoft 365 data should be checked during a MigrationWiz test?

Ans. Check important mailbox data such as emails, folders, contacts, calendars, and other items included in the migration plan. This helps identify missing or incorrectly migrated data before the full migration.

Q5. Does EWS retirement affect all Microsoft 365 tenants?

Ans. The impact depends on how EWS is being used in the tenant and which applications require EWS access. Organizations using applications that depend on EWS should review Microsoft’s retirement requirements and their current tenant configuration.

Q6. What happens if the MigrationWiz application is not added to EWSAllowedAppIDs?

Ans. If EWS access is restricted for the tenant, an application that is not included in the allowed list may be unable to access Exchange Online through EWS. This can prevent or interrupt migration activities that depend on EWS.

Q7. Does changing EWSAllowedAppIDs affect existing mailboxes?

Ans. EWSAllowedAppIDs controls application access to EWS rather than changing mailbox content. However, applications that rely on EWS may be affected if their Application ID is not permitted.

Q8. What should I do if MigrationWiz cannot connect after configuring EWSAllowedAppIDs?

Ans. First, verify that the correct Application (Client) ID was added to the allow list. Then check the authentication method, application permissions, EWS settings, and MigrationWiz endpoint configuration. Running another connection test can help identify the issue.

Q9. What are the risks of starting a migration without testing EWS access?

Ans. Starting without testing can lead to authentication failures, connection problems, incomplete migrations, or unexpected delays. Testing a small number of mailboxes first allows administrators to correct configuration issues before the main migration.

Q10. Do you need to have backups for your Microsoft 365 data before the process of migration via MigrationWiz?

Ans. A backup is not always needed for the migration; however, having a separate backup of your mailbox data is good just in case you want to have another opportunity for recovery.

Q11. Why is Modern Authentication necessary for MigrationWiz?

Ans. Modern Authentication offers a more modern authentication process to access the Microsoft 365 services. Finishing the required authentication process and configuring the application will allow MigrationWiz to gain access to perform the necessary migration.

Rate this post

About The Author:

Simran Bhatia is a technical content writer engaged in writing clear, concise, and SEO-optimized content. With a background in computer science and a passion for writing, I thrive to deliver complex technical content in simple layman terms.

Related Post