How to read the Exchange Online EWS usage report
The EWS usage report is a useful source of observed successful calls. It is not an inventory of every dependency, a configuration snapshot, or an automatic allow-list decision.
The fixed-date milestones are available as a calendar. Month windows and operational targets remain text so they are not presented as invented event dates.
Download the calendar: two source-confirmed fixed-date milestones
The window changes what absence means
Microsoft offers EWS usage windows of 7, 30, or 90 days and aggregates the data weekly. Choose and record the window before comparing reports, because a shorter or older window can exclude infrequent activity.
The report shows successful calls. An application that is blocked, intermittent, or outside the selected period may not appear, so absence from a window is not evidence of absence of a dependency.
Sources for this section
Treat each export as a dated observation
Microsoft states that the report is aggregated weekly and that activity can take up to 10 days to appear. A recent empty or lower count can therefore reflect reporting delay rather than the absence of EWS activity.
A single export covers a selected historical window. It is a dated observation, not a live configuration snapshot or evidence that a dependency is safe to remove.
Use the report as one evidence input, then reconcile it with a separately obtained EwsEnabled and EwsAllowedAppIDs configuration snapshot when the engagement scope allows that comparison.
Sources for this section
Use the report before the published milestones
Microsoft's published preparation target is Before 1 October 2026. Updated EWS behavior then rolls out tenant by tenant from 1 October 2026; missing-list creation is relative to that tenant rollout, not a calendar-wide September event.
A report can surface observed EWS activity, but it cannot prove that a listed application is unused, that a dependency is safe to remove, or that EWS retirement will affect a tenant on a known day.