Exchange Online customers: Microsoft is retiring Exchange Web Services. Here is what administrators need to do.
Notate Resource Center

Step 1: Keep EWS working until April 2027

For Exchange Online tenants only. Exchange on-premises customers are not affected by Microsoft's retirement of Exchange Web Services and can disregard this page.

What Microsoft is doing

Microsoft has confirmed that the retirement of Exchange Web Services (EWS) for Exchange Online is phased rather than immediate. Beginning , Microsoft disables EWS tenant by tenant unless the tenant has explicitly opted in to continued access. Tenants that opt in keep EWS until , when EWS is permanently removed with no possibility of re-enablement.

We recommend your Exchange administrator sets up the EWS exception for Notate now. Then move your users’ Notate Drive to OneDrive (Step 2) whenever it suits you.

Before you run it, find out what else in your tenant uses EWS. The allow-list is exclusive: once it is set, any application not on it loses EWS access across your whole organization. Check your Entra sign-in logs for applications authenticating to Exchange Web Services, and list every one of them alongside Notate in a single command.

What to do now

  1. Find out what actually uses EWS in your tenant. This is the step people skip. In the Microsoft Entra admin center, open Sign-in logs and look for applications authenticating to Exchange Web Services. Write down every one you find. If Microsoft has pre-populated an allow-list for your tenant from observed usage, that list is a useful second source — but do not assume it is complete.

  2. Set EWSEnabled to true at the tenant (organization) level.

  3. Set the allow-list in one command, containing Notate's application ID, 215843d3-1ef5-43d0-9b0f-76d16094ae79, together with every other application you found in step 1. The list replaces whatever was there before; it does not add to it.

  4. Confirm, then verify your other EWS systems are still working — archiving, e-discovery and backup first — before you consider the job done.

The commands

Run these in PowerShell on an administrator's machine, with the ExchangeOnlineManagement module installed or on the Azure PowerShell online.

PowerShell
# 1. Connect to Exchange Online.
Connect-ExchangeOnline

# 2. Enable EWS for your organization. Enables EWS until April 1, 2027.
Set-OrganizationConfig -EwsEnabled:$true

# 3. Show the allow-list as it stands today.
#    IMPORTANT: this returns the LIST, not what is USING EWS. On most tenants it
#    comes back empty, and empty does NOT mean nothing else needs EWS. Check the
#    Entra sign-in logs as well before you go any further.
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy |
    Select-Object -ExpandProperty EwsAllowedAppIDs

# 4. Set the list: Notate plus every other EWS application you found.
#    This parameter REPLACES the entire list rather than adding to it, so anything
#    you leave out loses EWS access immediately.
#    It takes ONE string: every ID inside a single pair of quotes, separated by commas.
Set-OrganizationConfig -EwsAllowedAppIDs "OTHER-APP-GUID-1,OTHER-APP-GUID-2,215843d3-1ef5-43d0-9b0f-76d16094ae79"

# 4b. Only if you have confirmed that nothing else in your tenant uses EWS:
Set-OrganizationConfig -EwsAllowedAppIDs "215843d3-1ef5-43d0-9b0f-76d16094ae79"

# 5. Confirm the result.
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy |
    Format-List EwsEnabled, EwsAllowedAppIDs

Step 5 should show EwsEnabled set to True, and every application you intended on the list:

EwsEnabled       : True
EwsAllowedAppIDs : 215843d3-1ef5-43d0-9b0f-76d16094ae79

Changes to the allow-list can take up to 24 hours to take effect. If Notate still cannot reach Exchange straight after you run these commands, wait a day before troubleshooting. To lift the restriction altogether while you sort something out, set EwsAllowedAppIDs to $null, which removes the application restriction and returns EWS to all applications.

Completing these steps keeps Notate sync uninterrupted when Microsoft begins tenant-by-tenant disablement in October 2026.

The exception extends EWS access only until April 1, 2027. After that date Microsoft removes tenant control entirely and no further extensions are available. Plan to move your users to OneDrive comfortably before then.

Authoritative sources

Microsoft 365 Message Center notice MC1447678, and the Exchange Team blog.

Next: move Notate Drive to OneDrive

See Step 2: Move Notate Drive to OneDrive. It takes one setting in your MDM.

Last updated: