August 18, 2026
Action Required: EWS Configuration for Exchange Online Migrations Starts Now
Exchange Web Services (EWS) retirement is entering its final phase, and Microsoft 365 administrators need to take action now to ensure their MigrationWiz projects continue to run without interruption.
Microsoft is introducing EWSAllowedAppIDs, a tenant-level allow list that lets Exchange Online administrators explicitly control which applications can continue accessing EWS. As part of the transition, MigrationWiz users must configure EWS access before starting migrations that use EWS for Exchange Online endpoints.
This requirement applies when either the source, destination, or both endpoints are Exchange Online (Microsoft 365).
As of August 6, 2026, MigrationWiz users must follow the EWS configuration steps outlined in the MigrationWiz guide for their specific migration scenario before beginning their migration.
What MigrationWiz Users Need to Do
Before running an Exchange Online migration that uses EWS, administrators must complete the steps in the applicable MigrationWiz migration guide under:
Enable EWS Access in Exchange Online and Scoping EWS Access Before Retirement Using EWSAllowedAppIDs
Administrators must also complete the Modern Authentication app registration steps described in the MigrationWiz Authentication Methods for Microsoft 365 (All Products) Migrations article.
The Application (client) ID generated during that registration process is the App ID that administrators must add to the EWSAllowedAppIDs allow list.
This configuration is now a required part of preparing MigrationWiz migrations that use EWS with Exchange Online.
What Is EWSAllowedAppIDs?
EWSAllowedAppIDs gives Microsoft 365 administrators greater control over applications that access Exchange Web Services.
Rather than allowing broad EWS access across a tenant, administrators can create an explicit allow list containing the Application IDs of approved applications.
For MigrationWiz customers, this means the Application ID associated with their MigrationWiz authentication configuration must be included in the tenant’s EWSAllowedAppIDs list for EWS-based migrations to continue operating.
Microsoft is using this capability as part of its broader transition away from unrestricted EWS access.
The October 1 Deadline Is Approaching
The timeline is important.
Starting October 1, 2026, Microsoft will block EWS traffic for tenants where EWSEnabled is set to True at the organization or user level but no EWSAllowedAppIDs list has been configured.
See the Help Center article here.
Only applications whose App IDs appear in the configured allow list will be permitted to use EWS.
For MigrationWiz users, waiting until October to address this configuration could put upcoming migration projects at risk.
If you have an Exchange Online migration planned, complete the required configuration before you begin your migration and well ahead of your testing and cutover dates.
Allow Time for Microsoft 365 to Apply Changes
There is an important operational consideration when configuring EWSAllowedAppIDs.
In September Microsoft will set your Allow List for your tenant. However, it is advisable to check the list to make sure they have added all the applications you will need.
Changes to the allow list can take up to 24 hours to take effect because Exchange Online servers refresh their in-memory configuration cache approximately once every 24 hours.
That means administrators should not add an App ID immediately before starting a migration and assume that the change will be available instantly.
Instead, add the required App IDs well ahead of your migration testing and project start date.
After making any change to the Allow List, run the appropriate verification command to confirm that the App ID has been added or removed correctly.
Do not assume that a successful command execution means the change has already propagated throughout Exchange Online.
Be sure to always check your app list. And record the list for future reference.
Prepare Before You Migrate
For MigrationWiz users, EWS retirement adds another important step to migration planning.
Before starting an applicable migration, make sure you have:
- Completed the required Modern Authentication app registration.
- Identified the Application (client) ID associated with your MigrationWiz configuration.
- Added the App ID to the EWSAllowedAppIDs allow list.
- Verified that the allow list contains the correct App ID.
- Allowed sufficient time for the configuration to propagate.
- Tested the configuration before beginning the migration.
These steps should become part of your standard migration preparation process for applicable Exchange Online projects.
BitTitan Is Preparing for the Next Generation of Mailbox Migration
While Microsoft prepares to retire EWS, BitTitan’s product team has been focused on the next iteration of the MigrationWiz Mailbox migration workload, scheduled for release this fall.
The next generation of Mailbox migration is part of BitTitan’s continued investment in MigrationWiz as Microsoft evolves the underlying technologies that power Exchange Online.
For MSPs and enterprise IT teams, this means MigrationWiz continues to evolve alongside Microsoft 365, helping customers maintain a reliable and predictable migration experience as the platform changes.
Don’t Let EWS Configuration Become a Migration Roadblock
EWS retirement is no longer something to plan for later.
The transition is already underway, and the required EWSAllowedAppIDs configuration is now part of preparing applicable MigrationWiz migrations involving Exchange Online.
If you have migrations planned for the coming months, don’t wait until the October 1 deadline.
Configure and verify your EWS access now, allow time for Microsoft 365 changes to propagate, and validate your migration configuration before your project begins.
For complete instructions, follow the EWS configuration steps in the MigrationWiz migration guide for your specific migration scenario and review Microsoft’s guidance on EWSAllowedAppIDs: Preparing for the Final Phase of EWS Retirement.
The sooner your environment is prepared, the less likely EWS retirement will become a last-minute obstacle to your migration.
Important Reminder
If your MigrationWiz migration uses EWS and either your source, destination, or both endpoints are Exchange Online (Microsoft 365), complete the required EWS access and EWSAllowedAppIDs configuration before starting your migration.

