
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

Microsoft is tightening Exchange Online EWS access starting October 10, 2026, requiring applications to appear in EWSAllowedAppIDs to keep connecting.
Summary
According to Microsoft 365 Message Center MC1485116, setting EWSEnabled=True alone will no longer provide access to Exchange Web Services.
This is a brief wire summary, the full story (linked below) has the complete details.
KazaSec's take
Microsoft 365 tenants sit at the center of identity, email, and file storage for most organizations, which makes a single compromised admin account there far more damaging than one compromised endpoint. A dedicated tenant security review is the fastest way to know where that risk actually sits.
Coverage details
We've archived 449 other articles touching the same topic (news, microsoft, exchange) , see the full security news archive.
Related security advisories
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.