Maintain control of your Microsoft 365 data
Post Reply
adam900331
Veteran
Posts: 363
Liked: 30 times
Joined: Dec 01, 2019 7:27 pm
Contact:

KB4820 - EWSAllowedAppID clarify

Post by adam900331 »

Hello!

I want to make sure, that the Exchange Online backup will work after October 1. I checked the KB4820, but I want to ask some clarification about EWSAllowedAppID. The KB say: "However, Microsoft recommends that admins create and validate their own list rather than relying on automatic population. The automatically populated list may include apps you are no longer aware of or wish to permit, and you, the admin, are responsible for ensuring the list is correct."

What do I have to do to add the AppId to the EWSAllowedAppID? What doeat it meean? I checked this command Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy and the EWSAllowedAppID parameter is empty. There is an app in our tenant: Veeam_Backup_for_Microsoft_365_App

Note, I have already set EwsEnabled to True.

Please help me.

Thanks,
Adam
DaStivi
Veeam Legend
Posts: 535
Liked: 112 times
Joined: Jun 30, 2015 9:13 am
Full Name: Stephan Lang
Location: Austria
Contact:

Re: KB4820 - EWSAllowedAppID clarify

Post by DaStivi » 1 person likes this post

You need to check the EWS Usage Report in the M365 Admin Portal.
There you’ll find the AppIds that are using EWS (it might be more than just Veeam Backup that still relies on EWS).

With those AppIds, you can then search in the Entra Admin Center for the corresponding app names. Be aware, though: the search box there doesn’t work directly with AppIds, so you’ll need to filter manually – another little catch.

Also, after setting the parameters via Exchange Online PowerShell, it can take up to 24 hours for the AppIds to be reflected when you check with a Get-OrganizationConfig PowerShell cmdlet.

Code: Select all

Set-OrganizationConfig -EwsEnabled $true -EwsAllowedAppIDs "AppID1,AppID2,..." 

#wait 24-hours:
Get-OrganizationConfig | fl ewsenabled,ewsallowedAppIDs

When you only enable the EwsEnable parameter, Microsoft may populate the AppIds automatically. However, this can result in EWS-related application permissions being granted that you no longer want to allow.
adam900331
Veteran
Posts: 363
Liked: 30 times
Joined: Dec 01, 2019 7:27 pm
Contact:

Re: KB4820 - EWSAllowedAppID clarify

Post by adam900331 »

Hy DaStivi!

I checked the EWS Usage Report in the M365 Admin Portal. I see many AppIds (not only the Veeam App). Do I have to add all of the AppIds?

Thanks.
DaStivi
Veeam Legend
Posts: 535
Liked: 112 times
Joined: Jun 30, 2015 9:13 am
Full Name: Stephan Lang
Location: Austria
Contact:

Re: KB4820 - EWSAllowedAppID clarify

Post by DaStivi » 1 person likes this post

Hi, yes, absolutely!

You need to add all App IDs from the list. I would recommend double-checking which application is associated with each App ID, as these applications should be migrated to Microsoft Graph API by April 2027, based on Microsoft's current guidance.

For example, I also found the first-party application Microsoft Outlook in that list. It does not appear under the tenant's App Registrations because first-party Microsoft applications are typically represented only by their App IDs. However, you can find public lists of Microsoft first-party App IDs online to identify them.

Another example I came across was a Teams/calling presence application that uses EWS to read calendar and presence-related status information. In this case, the vendor of the telephony system needs to take action and migrate their solution away from EWS before Microsoft's deadline.

Finding these App IDs is a good opportunity to identify third-party products that still rely on EWS and to engage the respective vendors early, rather than waiting until the service is eventually retired.

Microsoft also explicitly states in the article that even first-party applications must be added manually. Once you enable the EWSEnabled flag and configure the EWSAllowedAppIds list, only the applications included in that allow list will be permitted to use EWS.

This means that first-party Microsoft applications are not automatically exempt. If a first-party application still relies on EWS, its App ID must also be added to the allow list, as documented by Microsoft.

https://techcommunity.microsoft.com/blo ... nt/4529471

Image
adam900331
Veteran
Posts: 363
Liked: 30 times
Joined: Dec 01, 2019 7:27 pm
Contact:

Re: KB4820 - EWSAllowedAppID clarify

Post by adam900331 »

Hello,

I added all of the AppIds that uses EWS on Monday. I run the Get-OrganizationConfig | fl ewsenabled,ewsallowedAppIDs command and the EwsAllowedAppIDs paramter is empty. EwsEnabled is True.

Why can not see the AppIDs?

But now, all of the mailboxes got the following warning: Processing mailbox completed with warning: The HTTP request was forbidden with client authentication scheme 'Anonymous'. Total count of failed items: 1 (mailbox: ) :: 0:00:05

I checked this KB: https://www.veeam.com/kb4796

The EWSEnabled paramter is ture on the tenant level and also the mailbox level.

Thanks.
aeph
Expert
Posts: 114
Liked: 20 times
Joined: Sep 26, 2024 11:02 am
Contact:

Re: KB4820 - EWSAllowedAppID clarify

Post by aeph »

I used the MS introduction in the veeam post from here: https://techcommunity.microsoft.com/blo ... nt/4529471

$current = (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Select-Object -ExpandProperty EwsAllowedAppIDs)

$current is also empty in the tenants that we have checked.

I this cases i modified the next command:

Code: Select all

$backupAppId = "--- ID HERE ---"

Set-OrganizationConfig -EwsAllowedAppIDs $backupAppId 
instead of

Code: Select all

$updated = @($current, $backupAppId)
Set-OrganizationConfig -EwsAllowedAppIDs ($updated -join ",")
Because when empty i just add the backupAppId without ",".

When now running:

Code: Select all

$current = (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Select-Object -ExpandProperty EwsAllowedAppIDs)
It reflects the AppID.


UPDATE:
When using the command from @adam900331, its empty in my case as well.

So the above command reflects the AppID, but this command does not:

Code: Select all

Get-OrganizationConfig | fl ewsenabled,EwsAllowedAppIDs
Whats wrong here?

And one important question:

Do our customers still need to enable EWS on Mailbox-Level?
adam900331
Veteran
Posts: 363
Liked: 30 times
Joined: Dec 01, 2019 7:27 pm
Contact:

Re: KB4820 - EWSAllowedAppID clarify

Post by adam900331 »

Hy!

Thanks, now I run the following command and get all of the AppIDs:
$current = (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Select-Object -ExpandProperty EwsAllowedAppIDs)
adam900331
Veteran
Posts: 363
Liked: 30 times
Joined: Dec 01, 2019 7:27 pm
Contact:

Re: KB4820 - EWSAllowedAppID clarify

Post by adam900331 »

adam900331 wrote: Sep 16, 2026 6:45 am Hello,

I added all of the AppIds that uses EWS on Monday. I run the Get-OrganizationConfig | fl ewsenabled,ewsallowedAppIDs command and the EwsAllowedAppIDs paramter is empty. EwsEnabled is True.

Why can not see the AppIDs?

But now, all of the mailboxes got the following warning: Processing mailbox completed with warning: The HTTP request was forbidden with client authentication scheme 'Anonymous'. Total count of failed items: 1 (mailbox: ) :: 0:00:05

I checked this KB: https://www.veeam.com/kb4796

The EWSEnabled paramter is ture on the tenant level and also the mailbox level.

Thanks.
The error is gone after waiting 24 hours. :)
DaStivi
Veeam Legend
Posts: 535
Liked: 112 times
Joined: Jun 30, 2015 9:13 am
Full Name: Stephan Lang
Location: Austria
Contact:

Re: KB4820 - EWSAllowedAppID clarify

Post by DaStivi »

Not really belonging here, but kinda interesting I feel, "Samsung Mail" and also "Apple Internet Accounts" (Apple/iOS nativ Mail App) also using EWS, hence these AppIDs might also appear ! I'm really looking forward and being afraid from October if Microsoft just disable this in all tenants and many of customers will having issues !

Other issue I might see, admins just enable Veeam backup app and overlook others, hence also blocking other EWS Apps... 🫣😒
Mildur
Product Manager
Posts: 12346
Liked: 3560 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: KB4820 - EWSAllowedAppID clarify

Post by Mildur »

Hi Stephan,

To the best of my knowledge, these two apps use only ActiveSync on mobile phones, not EWS.
Active Sync is not getting disabled.

Best,
Fabian
Product Management Analyst @ Veeam Software
aeph
Expert
Posts: 114
Liked: 20 times
Joined: Sep 26, 2024 11:02 am
Contact:

Re: KB4820 - EWSAllowedAppID clarify

Post by aeph »

Would like to ask once again if ews still needs to be activated on mailbox-level?

What we have now.
    EwsEnabled on Orga-Level
      EwsEnabled on Mailbox-Level (?) (This was necessary in the past; there is no longer any mention of it in the knowledge base articles.)
        EwsAllowedAppID

        We have prepared a guide for all our customers—based on the Knowledge Base articles (weeks ago). Now that the release of 8.6 has introduced additional requirements (AllowList) in addition to permissions, we don’t want to cause confusion with a third guide so close to the deadline.

        So what’s the current status? We’ve already installed 8.6—is there any way we can check whether our customers’ tenants are ready yet?
        Mildur
        Product Manager
        Posts: 12346
        Liked: 3560 times
        Joined: May 13, 2017 4:51 pm
        Full Name: Fabian K.
        Location: Switzerland
        Contact:

        Re: KB4820 - EWSAllowedAppID clarify

        Post by Mildur »

        Hi aeph,

        According to Microsoft's online documentation, mailbox-level controls for EwsEnabled are still available through Set-CASMailbox (Microsoft Learn).

        Settings explicitly configured at the mailbox level generally override organization-wide settings configured through Set-OrganizationConfig. I would therefore expect Set-CASMailbox -EwsEnabled:$false to continue disabling EWS access for the specified mailboxes.

        However, I'll double-check with my colleague on the Alliance team.

        Best,
        Fabian
        Product Management Analyst @ Veeam Software
        Post Reply

        Who is online

        Users browsing this forum: No registered users and 6 guests