Exchange Online has been blocking EWS since 1 October 2026, and Apple Mail on the Mac now depends on the AppID allow list
Microsoft is retiring Exchange Web Services (EWS) in Exchange Online, and since 1 October 2026 it has been happening for real. According to the Exchange Team Blog (updated 9 September 2026), every tenant whose EWSEnabled setting is still at the default value Null gets switched to False as the rollout reaches it. That blocks EWS for every application in the tenant. Final shutdown follows on 1 April 2027, and Microsoft's wording is "no exceptions past April 2027". The Register confirmed the 1 October start and notes that Microsoft has not said how many organisations still depend on EWS.
The companies that will notice first are those whose staff use Apple Mail and Calendar on a Mac. Those apps talk to Exchange Online through EWS only, and Apple has not yet shipped its move to Microsoft Graph.
What Microsoft changes in the tenant setting
EWSEnabled has three values. False blocks EWS, before and after October. Null used to allow everything and becomes False from October 2026. With True, Exchange Online from October only admits applications whose AppID is on the EWSAllowedAppIDs list. If the list exists but is empty, the blog says no EWS traffic gets through at all. Traffic from cross-tenant organisation relationships stays allowed in both cases.
Anyone who still needs EWS has two options. The first is EWSEnabled set to True plus a maintained AppID list, configured through Baseline Security Mode or Exchange Online PowerShell. The second is to set the value back to Null with PowerShell, which reopens EWS without restriction until the final shutdown and ignores the AppID list. The Learn page on access control gives the commands: Set-OrganizationConfig -EwsEnabled:$true and Set-OrganizationConfig -EwsAllowedAppIDs "<id1>,<id2>". Its example is the Teams AppID, cc15fd57-2c6c-4117-a88c-83b1d56b4bbe. Tenants that also run the older EwsApplicationAccessPolicy with a user-agent allow list need connections to pass both checks.
For tenants that have not built their own list, Microsoft pre-populates the AppID list from the tenant's past usage. The blog warns that this can put apps on the list the admin did not know about. Switching back to True after the block restores EWS, though Microsoft says there will be a service interruption. The deadline for avoiding the switch altogether was the end of September 2026. Earlier versions of the blog said August; Microsoft changed that on 9 September.
Apple Mail, Calendar and Contacts on the Mac
Apple's Exchange deployment guide maps the protocols plainly: Exchange ActiveSync for iPhone, iPad and Apple Vision Pro, EWS for the Mac. On Graph, Apple writes that it is working with Microsoft to move Mail, Calendar, Contacts, Notes and Reminders to the Graph API in a future macOS 27 update, including a declarative configuration for MDM systems. Apple gives no date. heise online reported on 30 September that macOS 27.0.1 appears to lack the support, that the release notes of the macOS 27.2 beta do not mention Graph, and that Apple has announced nothing for older macOS versions. heise also mentions first user reports of sync trouble with Apple Mail before the deadline.
None of the sources read for this post names the AppID of the Mac apps. For the inventory, Microsoft points to the EWS usage reports in the Microsoft 365 admin center. Michael Tsai has collected the criticism of both sides on his blog: of Apple, because the deadline had been public for years, and of Microsoft, because the new Outlook for Mac lacks features and the promised AppleScript support was cancelled.
Which clients and integrations are affected
The table only lists what the cited sources explicitly assign.
| Client or integration | Protocol today | What to do |
|---|---|---|
| Apple Mail, Calendar, Contacts, Notes, Reminders on the Mac | EWS | put the AppID on the list and set EWSEnabled to True, or move to Outlook; Graph per Apple only with a macOS 27 update |
| Mail and Calendar on iPhone and iPad | Exchange ActiveSync | nothing |
| Thunderbird with an EWS account on Microsoft 365 | EWS | from version 154 create a new account using Graph; ESR 153 has no Graph, and Graph covers mail only so far (Thunderbird) |
| Office web add-ins on Windows | partly EWS | Office build 16.0.19725 or later (Microsoft) |
| Teams panels on Windows | partly EWS | Teams app 1449/1.0.97.2025120101 or later (Microsoft) |
| Dynamics 365 on-premises, server-side sync with Exchange Online | EWS | set the connection up again following Microsoft's Customer Engagement guide |
| Archive and backup tools that import or export archive, group or public folder mailboxes | EWS | Graph replacement targeted for Q4 2026 per Microsoft; until then, AppID on the list |
| Tools with generic read and write access to public folders or group mailboxes | EWS | Microsoft says no Graph replacement is coming |
| Exchange Server on premises | EWS | no change; per the Exchange team, hybrid mailboxes need Exchange SE for Graph calls to Exchange Online |
The Microsoft rows come from the Baseline Security Mode page, where the organisation-wide EWS block is one of the settings. Microsoft says the build numbers apply to the Win32 versions only. For the gaps in Graph, Microsoft keeps a roadmap with target dates on Learn and adds that anyone who does not find an EWS capability listed there should not plan on a Graph equivalent arriving before EWS is fully disabled.
Recommendation for tenants with Macs
Check the current value of EWSEnabled today and open the EWS usage report in the admin center. If the value is False and staff use Apple Mail on a Mac, the fastest fix is True plus an AppID list that holds only the applications that actually show up in the report and are needed. Review a list that Microsoft pre-populated before relying on it. In parallel, settle on a path for 1 April 2027 that does not depend on Apple's schedule: Outlook for Mac, Thunderbird 154 or later for mail-only use, or a tested macOS update with Graph if Apple ships it in time. If you are sorting tenant deadlines anyway, the data residency choice due by 14 December is a second one this autumn.
Further sources
- Microsoft Exchange Team Blog: Exchange Online EWS, Your Time is Almost Up, rollout process, EWSEnabled values, FAQ, updated 9 Sep 2026
- Microsoft Learn: Deprecation of Exchange Web Services in Exchange Online, timeline and roadmap of Graph gaps
- Microsoft Learn: Control access to EWS, PowerShell commands for EwsEnabled and EwsAllowedAppIDs
- Microsoft Learn: Baseline Security Mode settings, build requirements for Office add-ins and Teams
- Microsoft Learn: EWS usage reports, inventory in the admin center
- Apple Platform Deployment: Exchange integration, EWS on the Mac, ActiveSync on iPhone and iPad, Graph announcement
- heise online, 30 Sep 2026, macOS 27.0.1 without Graph, first sync problems
- The Register, 1 Oct 2026, start of the block, no figure for affected tenants
- Thunderbird Blog, 2 Sep 2026, Graph support from version 154
- Michael Tsai: The End of EWS in Mail and AppleScript in Outlook, collected criticism of Apple and Microsoft
How do I tell whether my tenant is already blocked?+
Look at EWSEnabled in the organisation config. If it reads False, EWS is blocked for every application. Since 1 October 2026 Microsoft has been moving every tenant that still had Null to False, step by step. According to Microsoft, tenants that set the value to True themselves before that step are left alone.
Does Apple Mail on the iPhone keep working?+
Yes. Apple's deployment guide says iPhone and iPad connect to Exchange Online through Exchange ActiveSync; only Mail and Calendar on the Mac use EWS. The shutdown therefore only hits the Mac.
Can I keep EWS open for individual apps after 1 April 2027?+
No. From 1 April 2027 Microsoft takes the EWSEnabled setting away from tenant admins and disables EWS in Exchange Online completely. The Exchange team FAQ says there will be no exceptions past April 2027. Exchange Server in your own data centre keeps EWS.
senn-tech