Skip to main content

Microsoft Exchange Web Services (EWS) change and impact on mailbox migrations

Explains the EWS deprecation, how it will affect ShareGate Migrate, and how to avoid disruptions with Copy mailbox

Two separate Microsoft changes affect how ShareGate Migrate uses Exchange Web Services (EWS) for mailbox migrations with Copy mailboxes, and both take effect around the same time in 2026.

  • A tenant-wide EWS block. Starting October 1, 2026, Microsoft blocks EWS by default in every Exchange Online tenant that hasn't opted in, with a full, permanent shutdown on April 1, 2027.

  • A license-based restriction for Kiosk, F1, and F3 mailboxes. These licenses never included EWS access rights, and starting October 1, 2026, Microsoft will begin enforcing that restriction regardless of your tenant's allow list status.

Note: These are separate mechanisms with separate fixes. Configuring your tenant's EWS allow list, described below, only addresses the tenant-wide block. If your migration includes mailboxes on a Kiosk, F1, or F3 license, you also need to complete the license fix described in this article below.

To avoid disruptions to your mailbox migrations, configure your tenant's EWS allow list before August 31, 2026, and update the licenses for any Kiosk, F1, or F3 mailboxes before migrating them.

What's changing

Microsoft's timeline

August 31, 2026

Deadline to configure your tenant to keep EWS enabled for the tenant-wide block.

Tenants that set EWSEnabled to True and have an EWS allow list configured before this date, will be excluded from the automatic October 1 block.

This deadline doesn't apply to the Kiosk, F1, and F3 license restrictions. That restriction has no opt-out grace period.

Note: If you're reading this after August 31, 2026, you can still configure your tenant's EWS allow list now, using the steps below. Microsoft may have already added an automatically generated application ID list to your tenant based on recent usage, but a list you configure yourself takes precedence over that automatic one at any time before October 1, 2026.

October 1, 2026

Both changes take effect on this date.

The tenant-wide block: EWS is blocked by default in any Exchange Online tenant that hasn't opted in. Microsoft sets EWSEnabled to False for these tenants.

The license restriction: EWS requests from mailboxes on a Kiosk, F1, or F3 license return an HTTP 403 error, regardless of your tenant's allow list status.

Tenant administrators can still re-enable EWS after this date, but there will be a service interruption until the re-enablement is complete.

April 1, 2027

EWS is permanently shut down in Exchange Online. Re-enablement will not be possible after this date.

ShareGate Migrate's plan

ShareGate Migrate currently uses EWS for Copy mailboxes only.

For all other migration scenarios, this change has no impact.

What you need to do

Depending on your migration, you may need to complete one or both of the following actions before October 1, 2026.

1. Configure your tenant's EWS allow list

Once ShareGate Migrate is allow-listed, the EWS retirement warning banner in ShareGate Migrate disappears automatically.

Note: These steps must be performed in both your source and destination tenants.

What you'll need

Add ShareGate Migrate to your EWS allow list

Add ShareGate Migrate's application ID to your tenant's EwsAllowedAppIDs allow list. This is Microsoft's application ID-based method for controlling EWS access, and the method on which Microsoft's own automatic enforcement relies.

Note: Setting EwsAllowedAppIDs replaces your tenant's entire allow list each time you run the command. It doesn't support adding entries incrementally, so include every application ID your tenant needs when you run it.

Run the following command, using ShareGate Migrate's application ID for Copy mailboxes:

Set-OrganizationConfig -EwsEnabled $true -EwsAllowedAppIDs "ce9858bf-0093-4723-9742-3af3b3c5e25a"

To confirm the change was applied, run:

Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs

Other options

If you prefer not to configure an allow list right away, two other options are available. Both involve service interruptions after October 1, 2026.

Keep EWS enabled without an allow list

Run Set-OrganizationConfig -EWSEnabled $true to enable EWS without configuring an allow list. This works now, but Microsoft will block EWS for tenants that have not configured an allow list on October 1, 2026.

Do nothing until October 1, 2026

If EWSEnabled is currently $null, EWS will continue to work until October 1, 2026. On that date, Microsoft will automatically set it to False. To re-enable EWS after that, run Set-OrganizationConfig -EWSEnabled $null. Setting the value back to $null restores the same unrestricted access you had before October 1, 2026, since Microsoft treats $null as enabled without allow-list enforcement.

You will still need to configure an allow list before April 1, 2027.

Important: This configuration is temporary. After April 1, 2027, Microsoft will permanently disable EWS in Exchange Online regardless of tenant settings.

We are working with Microsoft to ensure ShareGate Migrate no longer requires EWS.

2. Update licenses for Kiosk, F1, and F3 mailboxes

Exchange Online Kiosk and Microsoft 365 F1 and F3 licenses (including Office 365 F3, formerly Kiosk K1) never included EWS access rights.

Starting October 1, 2026, Microsoft enforces this restriction: EWS requests from mailboxes on only these licenses return an HTTP 403 error.

Note: Adding ShareGate to your tenant's EWS allow list does not fix this. That solution only addresses the tenant-wide block.

Assign a license that includes EWS access rights, such as Exchange Online Plan 1, Exchange Online Plan 2, or a Microsoft 365 or Office 365 E3 or E5 plan, to affected mailboxes before migrating them.

You can reassign the original frontline license once the migration is complete.

Note: This must be done in both your source and destination tenants.

Find and license affected mailboxes in ShareGate Migrate

To find and license affected mailboxes in your destination tenant:

  1. Go to Copy identities (see Copy identities overview).

  2. In the identity planning view, use the Filter button to filter by source license, then select the Kiosk, F1, and F3 licenses your organization uses.

  3. Select the affected identities, then use Bulk Edit > Assign licenses to apply a destination license that includes EWS access to all of them at once.

Note: Copy identities assigns licenses in your destination tenant only. If your source tenant also needs a temporary license change, for example, if you're running Copy mailboxes before decommissioning the source, assign it directly in the Microsoft 365 admin center.

For details on filtering and bulk-assigning licenses, see Copy identities overview.

Did this answer your question?