Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
KNOWLEDGE BASE ARTICLEVEEAMVERIFIED

PUBLISHER UPDATE · KB4820

KB4820 release notes and known issues

What Microsoft's EWS Retirement Means for Your Veeam Backups

Scope: Veeam products. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

What Microsoft's EWS Retirement Means for Your Veeam Backups KB ID: 4820 Product: Veeam Data Cloud for Microsoft 365 Veeam Backup for Microsoft 365 Published: 2026-03-25 Last Modified: 2026-09-24 Updated September 2026 This article has been revised to reflect: Microsoft's October 1, 2026 enforcement timeline. The introduction of the EWSAllowedAppIDs allow list. The current status of Veeam's transition to Microsoft Graph. Customers who have previously read this article are advised to review Steps 1 and 2 closely. Challenge Microsoft is retiring Exchange Web Services (EWS) in Exchange Online. EWS is the protocol Veeam currently uses to back up Exchange Online mailboxes. Key dates: October 1, 2026 — Microsoft begins disabling EWS tenant by tenant. Tenants who have not explicitly enabled EWS will be automatically blocked as the rollout proceeds. April 1, 2027 — EWS is fully and permanently shut down for all tenants. Note: These EWS phase-out dates apply to all Exchange Online mailbox types (including Kiosk/F1/F3). Configuring EWSAllowedAppIDs as described in Step 2 will maintain backup access for all mailboxes through the end of the transition period. However, if you take no action before October 1, your Exchange Online mailbox backups will fail. Veeam's transition to Microsoft Graph Veeam is actively transitioning Exchange backup functionality from EWS to the Microsoft Graph API. This requires additional Microsoft Graph permissions. However, Microsoft has not yet completed all the Graph API capabilities required — specifically, delta sync support needed for incremental backups. Veeam is working closely with Microsoft to close this gap. Until it is resolved, EWS must remain accessible for Exchange Online backups to continue. See Microsoft's parity gap roadmap for the latest status. Solution Exchange Online PowerShell Module Requirements The Exchange Online commands in this article are run using the Exchange Online PowerShell module. Instructions for installing or updating the module are provided in Install and update the Exchange Online PowerShell module , and instructions for connecting to the tenant are provided in Connect to Exchange Online PowerShell . Step 1: Keep EWS enabled in your tenant EWS access in Exchange Online is controlled by the EwsEnabled setting in your organization's configuration. Most tenants are currently at the default value of $null , and you will need to change this to $true before October 1, 2026. What happens to each setting value starting October 1, 2026 If EwsEnabled Value Is: This will happen starting October 1, 2026: $null (default — most tenants) Microsoft automatically changes this to $false . EWS is blocked for all apps. You can re-enable it afterward, but that change can take time to propagate, and you will then need a validated App ID allow list (see Step 2 ) before EWS access is restored. $true Microsoft honors an explicitly configured $true value and does not change it to $false during the rollout. However, the setting alone no longer determines access. If the App ID allow list is empty, all EWS access will be blocked. If the list is populated, only the applications on it can use EWS, which is already true before this date (see Step 2 ). $false EWS remains blocked. Swipe to show more of the table Action required: Explicitly set EwsEnabled to $true now Run the following PowerShell command against the Exchange Online tenant to check the current value first: Get-OrganizationConfig | Format-List EwsEnabled Copy If the current value is anything other than $true , run the following command to set the value to $true : Set-OrganizationConfig - EwsEnabled $true Copy Setting this explicitly to $true before October 1 protects your tenant from the automatic $null → $false conversion and gives you control over the transition timeline. Step 2: Manage your EWS App ID allow list Microsoft has introduced EWSAllowedAppIDs , an allow list that controls which Entra ID app registrations are permitted to use EWS.

Improvements and security content

  • What Microsoft's EWS Retirement Means for Your Veeam Backups KB ID: 4820 Product: Veeam Data Cloud for Microsoft 365 Veeam Backup for Microsoft 365 Published: 2026-03-25 Last Modified: 2026-09-24 Updated September 2026 This article has been revised to reflect: Microsoft's October 1, 2026 enforcement timeline. The introduction of the EWSAllowedAppIDs allow list. The current status of Veeam's transition to Microsoft Graph. Customers who have previously read this article are advised to review Steps 1 and 2 closely. Challenge Microsoft is retiring Exchange Web Services (EWS) in Exchange Online. EWS is the protocol Veeam currently uses to back up Exchange Online mailboxes. Key dates: October 1, 2026 — Microsoft begins disabling EWS tenant by tenant. Tenants who have not explicitly enabled EWS will be automatically blocked as the rollout proceeds. April 1, 2027 — EWS is fully and permanently shut down for all tenants. Note: These EWS phase-out dates apply to all Exchange Online mailbox types (including Kiosk/F1/F3). Configuring EWSAllowedAppIDs as described in Step 2 will maintain backup access for all mailboxes through the end of the transition period. However, if you take no action before October 1, your Exchange Online mailbox backups will fail. Veeam's transition to Microsoft Graph Veeam is actively transitioning Exchange backup functionality from EWS to the Microsoft Graph API. This requires additional Microsoft Graph permissions. However, Microsoft has not yet completed all the Graph API capabilities required — specifically, delta sync support needed for incremental backups. Veeam is working closely with Microsoft to close this gap. Until it is resolved, EWS must remain accessible for Exchange Online backups to continue. See Microsoft's parity gap roadmap for the latest status. Solution Exchange Online PowerShell Module Requirements The Exchange Online commands in this article are run using the Exchange Online PowerShell module. Instructions for installing or updating the module are provided in Install and update the Exchange Online PowerShell module , and instructions for connecting to the tenant are provided in Connect to Exchange Online PowerShell . Step 1: Keep EWS enabled in your tenant EWS access in Exchange Online is controlled by the EwsEnabled setting in your organization's configuration. Most tenants are currently at the default value of $null , and you will need to change this to $true before October 1, 2026. What happens to each setting value starting October 1, 2026 If EwsEnabled Value Is: This will happen starting October 1, 2026: $null (default — most tenants) Microsoft automatically changes this to $false . EWS is blocked for all apps. You can re-enable it afterward, but that change can take time to propagate, and you will then need a validated App ID allow list (see Step 2 ) before EWS access is restored. $true Microsoft honors an explicitly configured $true value and does not change it to $false during the rollout. However, the setting alone no longer determines access. If the App ID allow list is empty, all EWS access will be blocked. If the list is populated, only the applications on it can use EWS, which is already true before this date (see Step 2 ). $false EWS remains blocked. Swipe to show more of the table Action required: Explicitly set EwsEnabled to $true now Run the following PowerShell command against the Exchange Online tenant to check the current value first: Get-OrganizationConfig | Format-List EwsEnabled Copy If the current value is anything other than $true , run the following command to set the value to $true : Set-OrganizationConfig - EwsEnabled $true Copy Setting this explicitly to $true before October 1 protects your tenant from the automatic $null → $false conversion and gives you control over the transition timeline. Step 2: Manage your EWS App ID allow list Microsoft has introduced EWSAllowedAppIDs , an allow list that controls which Entra ID app registrations are permitted to use EWS.

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Veeam products

Affected versions

  • See the official publisher source for applicability.

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Official publisher evidence

VEEAMVERIFIED

What Microsoft's EWS Retirement Means for Your Veeam Backups

Checked 28 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source