Back to Blog

Microsoft 365 EWS Retirement: What BDRShield Customers Need to Do Before October 2026

Microsoft is retiring Exchange Web Services (EWS) API. The change will happen in stages, starting in October 2026, with EWS scheduled to be fully disabled in April 2027.
Choose your BDRShield Management Console - Cloud or On-Premise:
Hybrid Storage (Local & Cloud)30-Day Free TrialFull-Feature Access
Not sure which console fits your needs? Request Demo ?
By Praveen E | September 29, 2026

Microsoft is retiring Exchange Web Services (EWS) API. The change will happen in stages, starting in October 2026, with EWS scheduled to be fully disabled in April 2027.

If your organization uses BDRShield to backup and restore Microsoft 365 Exchange Online data, this change requires attention.

BDRShield currently uses EWS for backup and restore of In-Place Archive and Public Folder data. If EWS access is blocked for your Microsoft 365 tenant, these backup operations can stop working.

The good news is that Microsoft provides a way for administrators to explicitly allow required applications to continue using EWS during the transition.

What Is Changing With Microsoft 365 EWS?

Exchange Web Services is an API that applications use to work with Exchange Online data.

Microsoft is moving applications away from EWS toward Microsoft Graph and other supported APIs. As part of this transition, Microsoft is gradually disabling EWS access in Exchange Online.

There are two important dates to keep in mind:

  • October 1, 2026: Microsoft begins disabling EWS for tenants that have not explicitly configured EWS access
  • April 1, 2027: EWS is fully disabled across Exchange Online

The October 2026 date is the beginning of a phased rollout. Microsoft will apply the change to tenants progressively rather than disabling EWS for every tenant on the same day.

For organizations using BDRShield for the affected Exchange Online backup workloads, it is important to review the configuration before the change reaches your tenant.

How Does EWS Retirement Affect BDRShield?

BDRShield currently depends on EWS for In-Place Archive and Public Folder backup and restore.

If EWS access is blocked, these EWS-based backup and restore operations will no longer work until the required access is restored.

This does not mean that your entire Microsoft 365 backup environment will suddenly stop working. The impact described here is specifically related to the BDRShield features that currently depend on EWS.

BDRShield is working toward moving its Exchange Online backup capabilities from EWS to Microsoft Graph and other supported Microsoft APIs.

However, Microsoft Graph does not currently provide every capability required to fully replace EWS for backup applications. Microsoft continues to address these gaps, while some EWS capabilities are not planned for addition to Microsoft Graph.

Until the required functionality is available and validated, EWS access needs to remain available for the affected BDRShield backup operations.

What Microsoft 365 Administrators Need to Check

The first step is to check how EWS is currently configured for your Microsoft 365 organization.

You can check the setting using Exchange Online PowerShell:

Get-OrganizationConfig | Format-List EwsEnabled

The EWS Enabled setting can have three relevant states:

EWS Enabled value Current behavior During Microsoft’s retirement rollout
$true EWS is enabled. If an application allow list exists, only listed applications can use EWS. Applications must be included in the EWS application allow list.
$false EWS is blocked. EWS remains blocked.
$null EWS is currently allowed under the existing configuration. Microsoft will gradually change this to $false as the rollout proceeds.

For organizations that still need EWS for BDRShield, the important point is that leaving the setting at $null is not sufficient for the upcoming enforcement.

Step 1: Enable EWS for Your Organization

If your organization still needs EWS for BDRShield, explicitly enable it:

Set-OrganizationConfig -EwsEnabled $true -EwsAllowedAppIDs “< APPLICATION-ID-1 >,< APPLICATION-ID-2 >“

The application IDs used by BDRShield can be found in the BDRShield console.

Go to:
BDRShield Console → Inventory → SaaS Applications → Microsoft 365 Organization → Application ID column

On the same page, use the View icon under Action to find the additional application IDs listed in the BDRShield configuration wizard.

Make a note of all the application IDs provided for the BDRShield configuration.

Step 2: Add the BDRShield Application IDs to the EWS Allow List

Enabling EWS alone is not enough once Microsoft’s enforcement reaches your tenant.

Microsoft provides the EwsAllowedAppIDs setting to control which applications can access EWS.

When EWS is enabled and an allow list is configured, only the applications included in that list can use EWS.

Add the BDRShield application IDs to the allow list:

Set-OrganizationConfig -EwsAllowedAppIDs “< APPLICATION-ID-1 >,< APPLICATION-ID-2 >“

Use the application IDs shown in your BDRShield configuration.

Do not overwrite an existing allow list

Before making changes, check whether your organization already has applications in the EWS allow list.

If an allow list already exists, do not replace it with only the BDRShield application IDs.

Other applications in your Microsoft 365 environment may still require EWS access.

Keep the existing application IDs and add the required BDRShield application IDs alongside them.

This is an important step because replacing the existing list could unintentionally prevent other applications from accessing EWS.

How to Verify the Configuration

After configuring EWS and the application allow list, verify the settings.

First, check whether EWS is enabled:

Get-OrganizationConfig | Format-List EwsEnabled

Then check the allowed application IDs:

Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs

Confirm the following:

  1. EwsEnabled is set to $true
  2. The required BDRShield application IDs are present in EwsAllowedAppIDs
  3. Existing application IDs required by other workloads have not been removed

This gives you a clear way to confirm that the Microsoft 365 tenant is configured to allow the required BDRShield EWS operations.

Why You Should Check This Before October 2026

The important point is that October 1, 2026 is the start of Microsoft’s enforcement rollout, not a single date when every tenant will be changed.

Microsoft will progressively change tenants that have not explicitly configured EWS access.

If your organization relies on BDRShield for Exchange Online In-Place Archive or Public Folder backup and restore, reviewing the configuration before enforcement reaches your tenant can help avoid an interruption to those EWS-based operations.

It is also a good opportunity to review which other applications in your Microsoft 365 environment still depend on EWS.

What About the Move From EWS to Microsoft Graph?

Microsoft is moving Exchange Online applications toward Microsoft Graph and other supported APIs.

BDRShield is also working on this transition.

However, moving a backup application from one API to another is not simply a matter of changing the connection method. Backup and restore operations require the APIs to provide the capabilities needed to protect and recover the required data.

Microsoft continues to address the remaining gaps between EWS and Microsoft Graph. The available Microsoft documentation also notes that some EWS capabilities will not be added to Microsoft Graph.

For BDRShield, the transition will continue as the required Microsoft capabilities become available and are validated.

Until then, the required EWS access should remain available for the affected Exchange Online backup operations.

A Simple Checklist for Microsoft 365 Administrators

If your organization uses BDRShield for Microsoft 365 backup, review these items:

  1. Confirm whether your organization still uses BDRShield for Exchange Online backup
  2. Check the current EwsEnabled setting
  3. Set EwsEnabled to $true if EWS is required
  4. Find the BDRShield application IDs in the BDRShield console
  5. Check whether an existing EWS application allow list is already configured
  6. Keep existing application IDs that are still required
  7. Add the required BDRShield application IDs
  8. Verify EwsEnabled after making the change
  9. Verify EwsAllowedAppIDs
  10. Confirm that other required applications have not been removed from the allow list

Keep Your Microsoft 365 Backups Ready

Microsoft 365 administrators need to account for changes to the services and APIs that their backup applications depend on.

The upcoming EWS retirement is one such change.

For BDRShield customers, the immediate action is straightforward: review the EWS configuration, make sure EWS is explicitly enabled where required, and ensure the required BDRShield application IDs are included in the EWS allow list.

BDRShield will continue its transition toward Microsoft Graph and other supported Microsoft APIs as the required capabilities become available and validated.

For now, keeping the required EWS access in place is important for the affected Exchange Online backup and restore operations.

Microsoft References

For detailed information about Microsoft 365 EWS retirement and Exchange Online configuration, refer to the following Microsoft documentation:

Deprecation of Exchange Web Services in Exchange Online
Control access to EWS in Exchange
Set-OrganizationConfig – Exchange PowerShell
Exchange Online EWS, Your Time is Almost Up
Introducing EWSAllowedAppIDs: Preparing for the Final Phase of EWS Retirement

These Microsoft resources provide the latest information about EWS retirement, EWS access controls, and the Exchange Online PowerShell commands used to manage the configuration.

Need Help With Your BDRShield Configuration?

If you have reviewed your Microsoft 365 configuration and need help with BDRShield, contact the BDRShield Support team at bdr-support@vembu.com.

Follow our Twitter and Facebook feeds for new releases, updates, insightful posts and more.

Rate this post
Avatar for Praveen E

Praveen E

I’m working as a Marketing Associate. Implementing brand awareness initiatives for BDRSuite and writing blogs about the Backup and Disaster Recovery industry are my responsibilities.

Chat Icon
Go to Top