Microsoft starts disabling EWS tenant by tenant on October 1, 2026, and finishes in April 2027. Any tenant that never explicitly set the EWS setting is switched off automatically. This metric lists every app in the tenant that has been granted an EWS permission. Backup, security, and mail tools that still depend on EWS may stop working when a tenant is switched off. Holding the permission doesn't prove an app still calls EWS, so check with the vendor. This metric doesn't cover user mail clients like Apple Mail or Outlook Classic.
What is EWS?
Exchange Web Services (EWS) is Microsoft's older API that apps use to read and manage Exchange mailbox data, such as email, calendars, and contacts. Many backup, security, and mail tools still depend on it, and it stops working in a tenant once Microsoft disables it. Microsoft's EWS deprecation details →https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/deprecation-of-ews-exchange-online
List query:
EnterpriseAppConsentPermissions[?claimValue=='full_access_as_app' || claimValue=='EWS.AccessAsUser.All'].{App: enterpriseApplicationName, Publisher: applicationPublisher, AppId: applicationId, Permission: claimValue, Type: type, GrantedThrough: grantedThrough}
Count query (for alerting):
length(EnterpriseAppConsentPermissions[?claimValue=='full_access_as_app' || claimValue=='EWS.AccessAsUser.All'])