Two controls, two different keys

EwsAllowedAppIDs is keyed on an Entra application App ID and works with EwsEnabled. EwsApplicationAccessPolicy instead applies an allow or block policy to a User-Agent value through EwsAllowList or EwsBlockList.

They do not replace each other. The App ID retirement setting and the User-Agent policy need to be read as separate configuration surfaces before deciding which one explains an observed result.

Sources for this section

The User-Agent policy reaches beyond EWS

Microsoft documents EWS and REST behavior on the Exchange access-control page. Separate Microsoft Graph authorization guidance states that many Graph APIs accessing Exchange Online are also subject to these EWS application policies.

An empty EwsAllowList with an enforced allow-list policy blocks every matching application. That is a policy result to review, not evidence that an App ID retirement list is complete.

Sources for this section

Keep the retirement dates at their published precision

Microsoft begins the updated EWS behavior on 1 October 2026 and rolls it out tenant by tenant. Missing-list creation happens shortly before the new logic reaches a tenant, not on one calendar-wide September date.

Neither date answers whether an individual application is needed or whether its User-Agent policy is safe to change. That still requires tenant-specific evidence and approval outside this website.

Sources for this section