Digital Checkmark Business Security

On October 1 Your Microsoft 365 Looks Normal. Your Backup Quietly Stops.

Small network backup appliance with status lights on a shelf in a dim office at night, closed laptop out of focus behind it

On October 1 your staff will open Outlook and nothing will look different. Mail will arrive. Calendars will sync. Teams will work.

The things that may stop are the ones that run at night, unattended, that nobody watches until the day somebody needs them.

What Microsoft is switching off

Exchange Web Services is a twenty year old interface that other software uses to reach Microsoft 365 mailboxes. It is not something a person opens. It is the plumbing your backup product, your archiving service, your signature tool and your CRM calendar sync use to talk to Exchange Online.

Microsoft announced in 2023 that it would start blocking EWS requests from non-Microsoft apps to Exchange Online on October 1, 2026. EWS is then permanently shut down on April 1, 2027.

The deprecation has been running since 2018, but one event moved it from housekeeping to urgent. The Midnight Blizzard intrusion in January 2024 involved EWS, and Microsoft’s own documentation says the incident “elevated the urgency of the EWS deprecation effort” and widened its scope to include Microsoft’s own applications as well as third party ones.

This affects Exchange Online only. Exchange Server on premises is not part of it.

The default that catches everyone

Microsoft controls this with a tenant setting called EWSEnabled. Most organisations have never touched it, so it sits at Null, which has meant “allowed” for as long as it has existed.

That is what changes. Microsoft’s guidance states that as the phased rollout starts, tenants still on Null “will have EWS disabled (EWSEnabled set to False) as part of the staged shutdown process.”

Nobody has to do anything wrong for this to happen. Doing nothing is what triggers it.

The switch that reverses meaning

This is the part worth reading twice, because it will catch administrators who did try to prepare.

Alongside the on/off setting there is an allow list, EwsAllowedAppIDs, naming the applications permitted to keep using EWS. Today, if you set EWSEnabled to True and leave that list empty, everything is allowed through.

From October, the same configuration means the opposite. In Microsoft’s words, “setting EWSEnabled=True without an AppID allow list effectively becomes a block-all configuration.”

So an administrator who hears about the deadline, turns EWS on to be safe, and stops there, has not protected anything. They have blocked everything, and they will believe they are covered. Changes to the list also take up to 24 hours to take effect, so testing at 5pm on September 30 is not a plan.

What actually uses EWS in a small business

Almost nothing a person clicks. Which is the whole problem.

Some of this will not have a replacement in time. Microsoft has confirmed that generic public folder operations, generic Microsoft 365 Group mailbox operations and legacy discovery mailbox access are not coming to Microsoft Graph at all. If a product of yours depends on those, migrating is not the answer, replacing it is.

How to find out where you stand

You do not have to guess. Microsoft added EWS Usage Reports to the Microsoft 365 admin centre, under Reports and then Usage. It lists the applications in your tenant that are actually making EWS calls, with names and application IDs.

That report is the entire investigation. If it is empty, you have nothing to do and you can stop reading. If it lists three applications, those are your three phone calls to make, and the question for each vendor is narrow: are you off EWS before October 1, and if not, what is your application ID so it can be allow listed.

Ask now rather than in the last week. Microsoft’s own guidance is blunt about the timing: administrators who wait until they are already affected “will have a much smaller remediation window.”

What this is not

This is not a reason to panic about your email. Outlook, Teams and the rest of Microsoft’s own applications are not what breaks here, because Microsoft has been moving them off EWS for years. Nobody is going to lose access to their mailbox on October 1.

It is also not urgent for every business. Plenty of small companies use Microsoft 365 with nothing bolted onto it, and for them this deadline passes without consequence. The report tells you which group you are in, in about ten minutes.

And allow listing is a delay, not a fix. Everything stops on April 1, 2027 regardless of what is on the list.

Where to start

Open the EWS usage report and read the list. Then work out, for each application, whether its vendor has a date. That is the whole job before October 1.

The wider lesson is the one worth keeping: the integrations that run without anyone watching are exactly the ones that fail without anyone noticing. A backup that stopped running in October and gets discovered in February is not a backup. If you want to check the other half of your mail setup while you are in there, our free email health check audits what your domain is publishing to the world today.

Found this useful? The next one can come to you.

We write now and then: practical security for a small business, the month's ransomware figures in plain language, and new free tools when they land. No spam, and one click to leave.