Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1015893

The way to control EWS usage in Exchange Online is changing

Plan for Change
Major Change

Message ID

MC1015893
View in Admin Center

Services

Exchange Online

Summary

The behavior of the EWSEnabled switch in Exchange Online is changing. Starting April 1, 2025, EWS will only be allowed if both the organization-level and user-level EWSEnabled flags are true. This change aims to improve policy enforcement consistency. Check the blog for more details: [The way to control EWS usage in Exchange Online is changing](https://aka.ms/EWSEnabledChange).

Details

We are making a change to the behavior of the EWSEnabled tenant-wide switch in Exchange Online.

When this will happen:

This change will rollout worldwide, starting April 1, 2025

How this affects your organization:

If you want to restrict the usage of EWS in your tenant, this change might affect you. The current behavior of the EWSEnabled flag is that it can be set at both the tenant (organization) level and the user (mailbox) level. Currently, when the flag is set to true at the user level, it takes precedence over the organization-level setting. If a setting is Null, it means the setting is not enforced at that level. If Org and user-level are both Null, the default behavior is to allow. This hierarchical structure means that if the organization-level flag is set to false, but the user-level flag is set to true, EWS requests from that user are still allowed. In summary:

Organization LevelUser Level EWS Requests
True or <null>True or <null>Allowed
True or <null>FalseNot Allowed
FalseTrueAllowed
FalseFalse or <null>Not Allowed

This approach has led to situations where it can be challenging for administrators to ensure uniform policy enforcement across their organization, particularly in large and complex environments.

New Behavior

To address these issues, we are altering the behavior so that EWS will only be allowed if both the organization-level and user-level EWSEnabled flags are true. Here's a simplified view of the new logic:

Organization Level User LevelEWS Requests
True or <null>True or <null>Allowed
True or <null>FalseNot Allowed
FalseTrue or <null>Not Allowed
FalseFalseNot Allowed

In short, EWS will be permitted only if both the organization and user-level allow it. This change ensures that administrators have better control over EWS access and can enforce policies more consistently across their entire organization

Next Steps:

Please check the blog for additional information and ensure your per-user and tenant wide settings are correct before this change is made to your tenant.

  •  The way to control EWS usage in Exchange Online is changing 


Timeline

📅
Published
Feb 25, 2025
Message published to Message Center
✏️
Updated
Feb 25, 2025
Message content updated
🏁
End Date
Dec 31, 2025
Message timeline ends

Tags

#Feature update#Admin impact

Category

📋Plan for Change

Related Messages

Similar updates

MC1024399●

Microsoft Exchange Online: New limit for dynamic distribution groups (DDGs)

Mar 5, 2025
MC1028317

Microsoft Teams: Enhanced compliance in voicemail messages

Mar 11, 2025
MC987329

Microsoft Teams: Enhanced compliance and security in voicemail messages

Jan 24, 2025
MC1030003

Microsoft Outlook: Disable add-in user reporting buttons now that built-in Report button is GA for all platforms

Mar 12, 2025
MC1023294●

New Exchange Online Tenant Outbound Email Limits

Mar 4, 2025