EWS guide / Checklist

The EWS retirement checklist for service providers.

Fourteen steps per customer tenant, in the order that avoids rework. It works entirely by hand. Where Impactfold can take a step over, a note says so; where it cannot, the note says that too. Print it, or save it as a PDF for the change record.

Before you touch a tenant

  1. List every customer tenant, with three contacts for each: the person who approves changes, an administrator who can grant or remove consent in Microsoft Entra, and an Exchange administrator.

  2. Record each tenant's current EWSEnabled value and EWSAllowedAppIDs list (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy), including any list Microsoft pre-populated. You need these values for every later decision and for rollback.

  3. Agree with each customer what "done" means for each application: migrated and confirmed working, or retired, with its EWS access removed. Write it down before you start.

Per tenant: actual usage established

  1. Open the EWS usage report (Microsoft 365 admin center → Reports → Usage → Exchange → EWS usage), export it, and match application IDs to the candidates above. Data is aggregated weekly and can take up to 10 days to appear, so an application that runs rarely may be missing.

    Impactfold Not covered. Impactfold observes consent, not usage.

  2. For each application that holds EWS access or appears in the report, ask its owner or vendor whether it still needs EWS, and what its Microsoft Graph path and timeline are.

Per tenant: functional migration confirmed

  1. Move each application to its Graph-based version, or retire it. Have the customer confirm that the functions they rely on still work.

  2. For anything that must keep EWS until 1 April 2027, decide on the allow list with the customer. Treat setting EWSAllowedAppIDs and EWSEnabled as a change: list who is affected, agree a window, keep the values from step 2 for rollback, and allow up to 24 hours for it to take effect.

Per tenant: consent removal verified

  1. Once an application no longer needs EWS, remove its EWS consent in Microsoft Entra, and any EWS role assignment in Exchange, under your own privileged access. Note who did it and when.

    Impactfold Create the task from the finding, assign it, and mark it ready for verification. Impactfold never makes the change.

  2. Wait for the change to settle, then read the tenant again, completely. A read made too soon can still show a removed grant.

    Impactfold A later complete scan closes the finding and the task together, attributed to that scan.

  3. Keep the before, the change and the after, with a timestamp and the person responsible for each. That is what the customer will ask for months later.

    Impactfold Append-only audit trail for every finding.

  4. Re-check each tenant from time to time until 1 April 2027. A newly installed application can bring EWS consent back.

    Impactfold Run a scan again; a returning exposure reopens the finding and its task. Scans are started by an operator, not on a schedule.

Fourteen steps, times every tenant you manage. Impactfold covers the consent steps across all of them.