Microsoft 365 EWS Retirement

Microsoft 365 EWS Retirement

Microsoft 365 EWS Retirement: Action Required for BDRShield

Microsoft is phasing out Exchange Web Services (EWS) in Exchange Online, switching it off in stages. BDRShield uses EWS to back up and restore In-Place Archive and Public Folder.

To keep Exchange Online backups running without interruption, Microsoft 365 administrators need to check their EWS settings and make sure the BDRShield application is on the EWS application allow list.

Key Dates

    •     1 October 2026: Microsoft starts switching off EWS, one tenant at a time, for tenants that have not explicitly configured EWS access.

    •      1 April 2027: EWS is permanently turned off across Exchange Online.

1 October 2026 is only the start of enforcement. Tenants will be changed one by one rather than all on the same day.

If your organisation still backs up Exchange Online with BDRShield, complete the configuration steps below before enforcement reaches your tenant.

The Challenge

BDRShield currently depends on EWS for In-Place Archive and Public Folder backup and restore. Once a tenant's EWS access is blocked, these EWS-based backups stop working until EWS access is restored and the required application access is set up.

Microsoft's long-term plan is for Exchange Online applications to move from EWS to Microsoft Graph and other supported APIs. However, some EWS capabilities are still missing from Microsoft Graph.

BDRShield's Move to Microsoft Graph

BDRShield is working to move its Exchange Online backup features from EWS to Microsoft Graph and other supported Microsoft APIs.

At present, Microsoft Graph does not offer everything backup applications need to fully replace EWS. Microsoft's parity roadmap lists several remaining gaps, some targeted for Q4 CY2026. Microsoft has also said that some EWS features, such as generic Public Folder create/read/update/delete (CRUD) operations, will never be added to Microsoft Graph.

BDRShield will continue the transition as Microsoft delivers the capabilities needed. Until that functionality is available and validated, EWS access must stay available for the affected Exchange Online backups.

For the latest on Microsoft's EWS-to-Graph work, see Microsoft's EWS retirement documentation and parity-gap roadmap.

Solution

Prerequisite: Exchange Online PowerShell Module

The commands in this article need the Exchange Online PowerShell module. Use these Microsoft guides to set it up:

Step 1: Enable EWS for the Organisation

Check the current EWS setting with this command:

Get-OrganizationConfig | Format-List EwsEnabled


Microsoft describes three possible values for this setting:

EwsEnabled value

Behaviour today

During Microsoft's retirement rollout

$true

EWS is on. If an App ID allow list exists, only listed applications can use EWS.

Applications must appear in the EWS App ID allow list.

$false

EWS is blocked.

EWS stays blocked.

$null

EWS is currently allowed under the existing configuration.

Microsoft will gradually change the value to $false as the rollout proceeds.

Microsoft's documentation confirms that the rollout begins in October 2026 and that tenants still set to $null will be gradually changed to $false.


Action required: If your organisation still needs EWS for BDRShield, set the value explicitly:

Set-OrganizationConfig -EwsEnabled $true -EwsAllowedAppIDs "<APPLICATION-ID-1>, <APPLICATION-ID-2>,.."

You can fetch the Microsoft Entra Application ID by navigation to BDRShield Application console login as mentioned below.

  1. BDRShield Console -> Inventory -> SaaS Applications -> Microsoft 365 Organization -> Application Id

  2.  In same page, under ‘Action’ click view icon to fetch few other Application-id listed in the wizard.

               All the Application IDs collected above should be granted permission to use the EWS API by executing the command mentioned above.
Notes

Note: Setting EwsEnabled to $true is not enough on its own once the new enforcement reaches your tenant. The BDRShield application ID must also be on the EWS App ID allow list.

Step 2: Configure the EWS App ID Allow List

EwsAllowedAppIDs is a new setting that lets administrators list the Microsoft Entra application IDs allowed to use EWS. It can hold multiple values.

When EwsEnabled is $true and the allow list has entries, only the applications on that list can access EWS.

Once Microsoft's October 2026 enforcement reaches your tenant, an organisation with EwsEnabled = $true will need an allow list. If the list is empty, applications will be blocked from using EWS.


InfoImportant: If your organisation already has an allow list, review it before making any changes, and do not overwrite it. Keep every application that still needs EWS, and add the BDRShield application ID alongside them.

Verify Your Settings

After setting up EWS and the allow list, check the EWS setting:

Get-OrganizationConfig | Format-List EwsEnabled

Then check the allowed application IDs:

Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy |

    Format-List EwsAllowedAppIDs

Confirm that:

  1. EwsEnabled is set to $true.

  2. The BDRShield application ID appears in EwsAllowedAppIDs.

  3. No application IDs needed by other workloads were accidentally removed.

Microsoft References

For more information, see Microsoft's official documentation:

If this article does not resolve your issue, or you need more help with BDRShield, please raise a BDRShield Support Ticket at bdr-support@vembu.com