-
Written By
Simran Bhatia -
Approved By
Sonika Rawat -
Updated on
August 21st, 2026 -
Read Time
8 minutes
Introduction: Exchange Web Services (EWS) has supported many Exchange Online migration projects for years. Now, Microsoft is moving into the final phase of EWS retirement. For organizations using MigrationWiz with Exchange Online, this change should not be treated as a future concern. Some configuration work is already required.
Microsoft has introduced EWSAllowedAppIDs, which allows Microsoft 365 administrators to decide which applications can continue using EWS. If your MigrationWiz project uses EWS and Exchange Online is involved, the required application ID needs to be allowed. In this guide, we will explain what is changing, what MigrationWiz users need to configure, and how to protect mailbox data before starting a migration.
Exchange Web Services (EWS) is a Microsoft technology that allows applications to work with Exchange mailbox data. It has been widely used to access emails, calendars, contacts, and other mailbox information.
Microsoft is gradually moving Exchange Online toward newer APIs and technologies. Because of this change, EWS is being retired in stages rather than being switched off all at once.
The final phase brings tighter control over applications that still need EWS access. Microsoft has introduced EWSAllowedAppIDs to help administrators manage this access. For migration teams, this means EWS settings should now be checked as part of the normal migration preparation process.
EWSAllowedAppIDs is an allow list that Microsoft 365 administrators can use to specify which applications are permitted to access EWS. In simple terms, an administrator can identify an approved application by its Application (client) ID and add that ID to the tenant’s EWS allow list.
This is crucial to MigrationWiz users because when performing migrations based on EWS, you might require the application ID used in the authentication of Microsoft 365. It also helps give more control to administrators concerning third-party applications trying to access Exchange Online.
The October 1, 2026 date is an important point in the Exchange Online EWS retirement timeline. Microsoft is introducing stricter EWS access rules for tenants that continue to have EWS enabled but do not configure the required application allow list.
Once the new behavior applies to a tenant, applications that are not included in the allowed list may no longer be able to use EWS. For this reason, migration teams should not wait until the deadline is close. If a migration is planned for the coming months, EWS configuration should be reviewed during the planning stage.
Microsoft has also been communicating the upcoming changes through the Exchange Team. The earlier article Exchange Online EWS, Your Time is Almost Up provides additional background on the retirement.
One point that migration administrators should keep in mind is that configuration changes may not become active immediately. Therefore, adding an App ID just before a migration is not a good idea. After making the change:
EWS configuration is only one part of migration preparation. In addition to that, it would be prudent to maintain a duplicate copy of the relevant mailbox data before undertaking significant modifications to the Microsoft 365 environment. The backup will come in handy in situations where certain items are skipped during the migration process, or the migration process gets stalled halfway.
The SysInfo Office 365 Backup Tool can be considered as part of a pre-migration backup plan. The tool is designed to back up Office 365 mailbox data and save it in formats such as PST, PDF, EML, MBOX, and CSV. It can be useful for:
A full mailbox migration can involve hundreds or thousands of users. Discovering an Exchange Web Services retirement or authentication problem after the migration has started can cause unnecessary delays. A small test migration gives administrators a chance to check:
Microsoft’s EWS retirement is an important change for organizations planning Exchange Online migrations with MigrationWiz. The introduction of EWSAllowedAppIDs gives administrators a way to control which applications can continue using EWS during the transition. Before starting a migration, review the tenant’s EWS settings, complete the required authentication setup, identify the correct Application ID, configure the allow list where required, and test the connection.
It is also sensible to back up important mailbox data before the full migration begins. A separate backup can provide an extra layer of protection if the migration is interrupted or some data needs to be checked later. Most importantly, do not leave EWS preparation until the migration day. Review the environment early, test with a smaller mailbox set, and keep your configuration documented.
Ans. MigrationWiz users should review their Microsoft 365 EWS settings, complete the required Modern Authentication setup, identify the correct Application (Client) ID, and add it to EWSAllowedAppIDs when required. A test migration should also be completed before moving all mailboxes.
Ans. Microsoft 365 configuration changes may take some time to apply. After updating EWSAllowedAppIDs, administrators should allow sufficient time for the change to take effect and then test the connection before starting the migration.
Ans. A small test migration can help confirm that authentication, EWS access, application permissions, mailbox access, and MigrationWiz endpoint settings are working correctly.
Ans. Check important mailbox data such as emails, folders, contacts, calendars, and other items included in the migration plan. This helps identify missing or incorrectly migrated data before the full migration.
Ans. The impact depends on how EWS is being used in the tenant and which applications require EWS access. Organizations using applications that depend on EWS should review Microsoft’s retirement requirements and their current tenant configuration.
Ans. If EWS access is restricted for the tenant, an application that is not included in the allowed list may be unable to access Exchange Online through EWS. This can prevent or interrupt migration activities that depend on EWS.
Ans. EWSAllowedAppIDs controls application access to EWS rather than changing mailbox content. However, applications that rely on EWS may be affected if their Application ID is not permitted.
Ans. First, verify that the correct Application (Client) ID was added to the allow list. Then check the authentication method, application permissions, EWS settings, and MigrationWiz endpoint configuration. Running another connection test can help identify the issue.
Ans. Starting without testing can lead to authentication failures, connection problems, incomplete migrations, or unexpected delays. Testing a small number of mailboxes first allows administrators to correct configuration issues before the main migration.
Ans. A backup is not always needed for the migration; however, having a separate backup of your mailbox data is good just in case you want to have another opportunity for recovery.
Ans. Modern Authentication offers a more modern authentication process to access the Microsoft 365 services. Finishing the required authentication process and configuring the application will allow MigrationWiz to gain access to perform the necessary migration.
About The Author:
Simran Bhatia is a technical content writer engaged in writing clear, concise, and SEO-optimized content. With a background in computer science and a passion for writing, I thrive to deliver complex technical content in simple layman terms.
Related Post