EWS allow lists compared: App IDs and User-Agent policy
Exchange Online has two similarly named access controls. This page separates the EWS retirement App ID mechanism from the longer-standing User-Agent policy so a review does not change the wrong boundary.
The fixed-date milestones are available as a calendar. Month windows and operational targets remain text so they are not presented as invented event dates.
Download the calendar: two source-confirmed fixed-date milestones
Two controls, two different keys
EwsAllowedAppIDs is keyed on an Entra application App ID and works with EwsEnabled. EwsApplicationAccessPolicy instead applies an allow or block policy to a User-Agent value through EwsAllowList or EwsBlockList.
They do not replace each other. The App ID retirement setting and the User-Agent policy need to be read as separate configuration surfaces before deciding which one explains an observed result.
Sources for this section
The User-Agent policy reaches beyond EWS
Microsoft documents EWS and REST behavior on the Exchange access-control page. Separate Microsoft Graph authorization guidance states that many Graph APIs accessing Exchange Online are also subject to these EWS application policies.
An empty EwsAllowList with an enforced allow-list policy blocks every matching application. That is a policy result to review, not evidence that an App ID retirement list is complete.
Sources for this section
Keep the retirement dates at their published precision
Microsoft begins the updated EWS behavior on 1 October 2026 and rolls it out tenant by tenant. Missing-list creation happens shortly before the new logic reaches a tenant, not on one calendar-wide September date.
Neither date answers whether an individual application is needed or whether its User-Agent policy is safe to change. That still requires tenant-specific evidence and approval outside this website.