Exchange Online · EWS retirement

Know which applications still depend on EWS — and what to do about each one, tenant by tenant.

A fixed-scope, independent audit for Microsoft 365 service providers. It turns consented EWS evidence into a reviewable decision pack: what is actually calling EWS, how that compares to the current allow list, who owns each application, and what you would change — with every row traceable back to its source.

Local-firstNo hosted upload
No credentialsWe never hold tenant access
Written onlyNo calls at any stage
EUR 500–1,500Fixed before any file is accepted
What Microsoft has published

The dates that actually apply

Below is Microsoft’s published sequence, with the primary source for each step. It is an operational timeline, not a prediction about your estate: no one can tell you the day a specific tenant is switched.

End of Aug 2026
Optional proactive configuration

A tenant that sets EwsEnabled to true and defines its own App ID allow list is excluded from the automatic switch. Microsoft's newest notices phrase this as “before 1 October”; the explicit end-of-August wording is in the Skype for Business hybrid guidance.

21 days from this page build
Sep 2026
Microsoft populates unconfigured lists

For tenants that have not configured a list, Microsoft plans to populate one based on observed usage. An administrator-created list is not planned to be changed. Reviewing whatever list results remains the administrator's responsibility.

51 days from this page build
1 Oct 2026
Phased disablement begins

Exchange Online begins gradually disabling EWS. Tenants without a timely explicit opt-in are progressively set to EwsEnabled = false. Access after that point depends on the allow list.

52 days from this page build
1 Apr 2027
EWS fully disabled

EWS in Exchange Online is disabled completely. Microsoft states no exceptions after this date, and EwsEnabled stops being a workaround.

234 days from this page build

Sources were last re-read on 7 August 2026. Microsoft has revised this guidance more than once, most recently to note that Organization Relationships traffic is not governed by the allow-list state. Every engagement re-reads the primary sources and your tenant’s Message Center before any recommendation is made. The full breakdown — state matrix, the September auto-population, how to read the usage report and the write trap that removes App IDs silently — is in the MSP guide, free and without a form.

The gap

The report tells you what happened. It does not tell you what to do.

Microsoft’s usage report and your existing inventory are both real inputs. Neither of them, alone, answers the question your client is going to ask.

01

Usage is not the same as permission

An application holding EWS permissions may never call EWS. An application calling EWS may not appear in the inventory you already keep. Deciding what to allow requires reconciling observed SOAP-action usage against the current configuration — two different sources, per tenant.

02

The allow list is written by full replacement

There is no documented incremental add or remove. Setting the list writes it whole, so any existing App ID missing from the new value is removed. A proposal therefore has to state the complete prospective set, the delta and the read-before-write precondition — not just the additions.

03

The bottleneck is ownership, not discovery

The hard part across dozens of tenants is not producing a list of GUIDs. It is knowing who owns each application, what happens if it stops working, who signs off on the change, and being able to show a client the evidence behind each decision.

Scope

Two scopes, and an honest boundary between them

The scope is decided before any file is accepted, because the two differ by one input — and that input is what separates an inventory from a proposal.

Usage inventory

What you supply

  • One consented EWS Usage export per tenant, with a stated report window.

What you receive

  • Normalised portfolio summary and per-tenant findings.
  • Normalised application and SOAP-action usage, each row traceable to its source row.
  • Keep / migrate / remove / investigate decision register with owner and target date.
  • Unknown-evidence and unknown-owner queues, with the limitations stated explicitly.
  • Deterministic run manifest: input hashes, artefact hashes and workbench version.
A usage export alone cannot prove your current allow list. Without a configuration snapshot, configuration is reported as UNKNOWN and no allow-list comparison or proposal is produced.

Full reconciliation

What you supply

  • Everything above, plus a separately consented read-only snapshot of EwsEnabled, EwsAllowedAppIDs and the relevant current configuration.

What you receive

  • Everything in Usage inventory.
  • Current configuration compared against observed usage, per tenant.
  • Enforcement-state modelling based on Microsoft's published behaviour, with the publication date recorded.
  • Reviewable allow-list proposal: current set, prospective full set, delta, blockers, warnings and mandatory review preconditions.
  • Explicit CANNOT_DETERMINE rows wherever the supplied evidence cannot support a safe decision.
The output is a proposal for your change control. It never applies an Exchange setting and never emits a ready-to-run mutation script.
How it runs

Six steps, and you can stop at any of them

01   Written scoping
A short set of questions answered by email: portfolio size, what evidence you can actually obtain, which scope applies, and who owns change control on your side. You get a written answer, including a plain “this is not a fit” where that is the honest one. Answers usually arrive within one working day.
02   Fixed scope and order
Price, delivery date, retention window and deletion deadline are written down before any file is accepted. Scope changes are re-quoted, not absorbed silently.
03   Consented intake
You export from your own admin centre. The file arrives through an agreed encrypted channel, is quarantined and hashed before it is opened, and is mapped to the normalised contract on a reviewable worksheet. Ambiguity pauses the engagement instead of being guessed.
04   Analysis and your decisions
The workbench runs offline. Reconciliation is mechanical; the keep / migrate / remove / investigate calls are yours, recorded with owner, rationale and target date.
05   Evidence pack and written findings
The deterministic pack — portfolio summary, per-tenant client-safe evidence, decision register and the review-only allow-list proposal — with a written findings summary and a round of follow-up questions answered in writing, in as much depth as you need.
06   Deletion
Raw and working copies are removed at the agreed deadlines, and the deletion is recorded with timestamps and digests.
Deliverable

You receive artefacts, not a slide deck

Every machine-readable artefact is deterministic: the same inputs, the same recorded decisions and the same ruleset produce byte-identical output, so a re-run produces a diff you can actually review.

Artefacts included in the evidence pack
ArtefactFormatWhat it contains
portfolio-summary.csvCSVOne row per tenant: applications observed, decisions taken, unresolved items.
reconciliation-findings.csvCSVOne row per tenant-application finding, with state, severity, explanation and evidence IDs.
decision-register.csvCSVThe human decisions: keep / migrate / remove / investigate, owner, target date, review status.
configuration-proposal.csvCSVReview-only allow-list proposal: current set, prospective set, delta, preconditions.
unknown-owner-queue.csvCSVApplications observed with no identified owner — the queue that actually needs your people.
validation-report.jsonJSONWhat was accepted, what was rejected and why. Fails closed on ambiguous input.
run-manifest.jsonJSONSHA-256 of every input and every artefact, plus ruleset and workbench versions.
tenants/<tenant>/overview.htmlHTMLPer-client evidence page, built only from that tenant's partition.

A fictional sample is available before any of your data moves

A complete three-tenant evidence pack built from entirely fictional data — deliberately mixed states: active and known, active and unknown, allow-listed but not observed. Every identifier in it is synthetic. It is a demonstration of the output format and of the limitations wording; it is not a customer result and implies no customer relationship. Ask for it in your first message; it is sent as a link, not as an attachment.

Vocabulary

Unknown stays unknown

The reconciliation vocabulary is deliberately narrow, and nothing is promoted out of it automatically. An application that is observed but not allow-listed is never silently added. An allow-listed application with no usage in the window is never called obsolete.

OBSERVED_ALLOWLISTED

Seen calling EWS and present in the current allow list.

OBSERVED_NOT_ALLOWLISTED

Seen calling EWS and absent from a populated allow list.

ALLOWLISTED_NOT_OBSERVED_IN_WINDOW

In the allow list, with no usage in the supplied window. This does not mean unused or safe to remove.

OBSERVED_ALLOWLIST_UNKNOWN

Seen calling EWS; no configuration snapshot was supplied.

INPUT_INVALID

The input could not be safely and unambiguously mapped. Nothing is guessed.

Data boundary

Where your data goes, and where it does not

You are a service provider. Handing a third party access to dozens of client tenants is not a reasonable ask, so it is not the ask.

  • No Microsoft 365 credentials, tokens or certificates are requested, held or accepted.
  • Files are processed locally on a controlled workstation under a written consent and retention record.
  • Your export is never uploaded to a hosted SaaS, a public repository, a CI system or an AI chat.
  • The deliverable minimises identifiers and records unresolved evidence explicitly instead of guessing.
  • Deletion is confirmed in writing at the end of the agreed retention window.
  • No direct connection is made to your tenant, to Exchange, to Microsoft Graph or to any RMM/PSA system.
Limits

What this audit does not claim

Stated plainly, before you buy, because a decision pack whose limits are hidden is worth less than no decision pack at all.

  • This is not a Microsoft product, and it is not endorsed by or affiliated with Microsoft.
  • It does not guarantee that every EWS dependency in your estate has been found.
  • It does not guarantee the prevention of any service interruption.
  • It is not a Graph migration project, and it does not rewrite any application.
  • It never modifies EwsEnabled, either allow list, a mailbox policy or any other tenant setting.
  • A usage inventory alone cannot prove your current allow-list configuration.
  • It does not accept “any CSV”. An unexpected or ambiguous input shape is rejected or re-scoped, not silently parsed.
  • The absence of an application from a report window does not prove the absence of a dependency.
Who does the work

One engineer, and no reason to take that on faith

The audit is delivered personally by SHEV Oleksii Shevchenko, trading as SHEV Software — a registered Polish business with published identity and tax numbers. There are no case studies here, no client logos and no testimonials, because there is no honest way to show them yet.

So the engagement is built to need as little trust as possible. That is a design decision, not a disclaimer:

  • There is nothing to revoke, because nothing is granted: no credentials, no tenant access, no connection to your environment at any point.
  • The deliverable is deterministic. Run the same inputs twice and the output is byte-identical — you can verify the work rather than trust it.
  • The full sample pack is available before any of your data moves, so the deliverable is known before the decision.
  • The provider is a registered Polish business with published identity, address and tax numbers, invoicing under its own name.
  • Every limitation is written down on this site, in the offer and in the deliverable itself — including the ones that cost us work.
Pricing

Fixed after intake, before any data is accepted

The band is agreed during the written scoping, once the portfolio and the available evidence are known. The final scope, delivery date and retention window are written into the order. Unexpected or ambiguous input is re-scoped or declined, not silently absorbed.

Small
EUR 500

A bounded inventory with a limited number of tenants and applications.

Standard
EUR 1,000

A multi-tenant inventory, or a full reconciliation for a moderate portfolio.

Complex
EUR 1,500

A larger portfolio, or one with material evidence exceptions to work through.

Prices are exclusive of any applicable tax, which is stated on the order. Quotes and invoices can be issued in EUR, USD or GBP — the amount is fixed in the written quote, not at payment time. Invoicing is from a Polish sole proprietorship; see legal information.

Next step

Start in writing

This engagement runs in writing from the first message to the final deliverable. A short scoping exchange by email establishes portfolio size, what evidence you can actually obtain, which scope applies, and who owns change control on your side. If it does not fit, you will hear that in the reply rather than in an invoice.

This form accepts only the fields shown below. Do not submit tenant or application IDs, customer data, credentials, tokens or audit files here.

Used to reply to you. Nothing else.
Used to sequence the work honestly — if a date cannot be met, you will be told in the reply.

This bounded form processes only the details above to answer you. Do not submit tenant or application IDs, customer data, credentials, tokens or audit files. The legal basis is Article 6(1)(b) GDPR — steps taken at your request. The record expires no later than 365 days after server receipt. Privacy notice.

The optional box above is never pre-ticked. When it is selected, the server stores the current consent wording with the submission; when it is not selected, no consent wording is stored.

Primary sources

Check the claims yourself

Last re-read 7 August 2026. Microsoft may revise this guidance at any time; where this page and Microsoft’s current documentation disagree, Microsoft is correct and this page is out of date.