In 2 daysExchange Online starts disabling EWS on 1 October 2026

Keep your EWS apps running after Exchange Online turns EWS off

EWS Bridge answers your application’s EWS calls through Microsoft Graph. Change the endpoint and the credential, keep the code.

Your application sendsEWS SOAP · FindItem

<m:FindItem Traversal="Shallow">
  <m:IndexedPageItemView MaxEntriesReturned="10"
      Offset="0" BasePoint="Beginning" />
  <m:Restriction>
    <t:And>
      <t:Contains ContainmentMode="Substring"
          ContainmentComparison="IgnoreCase">
        <t:FieldURI FieldURI="item:Subject" />
        <t:Constant Value="meeting notes" />
      </t:Contains>
      <t:IsEqualTo>
        <t:FieldURI FieldURI="message:Sender" />
        …
      </t:IsEqualTo>
    </t:And>
  </m:Restriction>
  <m:SortOrder>
    <t:FieldOrder Order="Descending">
      <t:FieldURI FieldURI="item:DateTimeReceived" />
  …

EWS Bridge callsMicrosoft Graph v1.0

GET /users/alex@contoso.com/mailFolders/inbox/messages
  ?$filter=receivedDateTime ge 1900-01-01T00:00:00Z
      and contains(subject,'meeting notes')
      and sender/emailAddress/address eq 'sadie@contoso.com'
  &$orderby=receivedDateTime desc
  &$top=10
  &…
and answers in EWS:FindItemResponseMessageResponseClass="Success"TotalItemsInView="1"Fixture ews/FindItem/restriction-and-sort from our test suite

What Microsoft has announced

EWS in Exchange Online is switched off in two steps. Applications that still call it need another way to reach Microsoft 365.

  1. In 2 days

    EWS starts to be disabled

    Microsoft: “EWS starts to be disabled globally for all organizations.” Tenants that have not kept EWS on with an AppID allow list get EWSEnabled=False as the rollout reaches them. An administrator can switch EWS back on until the final shutdown, after an interruption.

  2. EWS is fully disabled

    Microsoft: “EWS is fully disabled.” Administrators can no longer control EWSEnabled, and there are no exceptions past April 2027. Applications that still call EWS stop working.

  3. Exchange Server

    On-premises is not affected

    The retirement applies to Exchange Online in Microsoft 365. Exchange Server in your own data centre keeps EWS. The bridge is for mailboxes in Exchange Online.

Sources: Microsoft Learn, Deprecation of Exchange Web Services in Exchange Online, and the Exchange Team’s rollout plan, checked on 30 September 2026.

Three changes on your side, none in your code

The bridge accepts EWS SOAP, performs each call through Microsoft Graph with an app-only token of your tenant, and answers exactly like Exchange.

  1. Connect Microsoft 365An administrator, once

    A Global Administrator signs in with Microsoft in the console and grants admin consent to the Avakode EWS Bridge application: app-only Microsoft Graph permissions, no user passwords. The bridge takes your tenant from Microsoft’s signed token, never from a URL.

  2. Point the application at the bridgeOne URL, one credential

    // EWS Managed API: the only line that changes service.Url = new Uri("https://ews.avakode.com/EWS/Exchange.asmx");

    Authenticate with the bridge key: Basic with the mailbox address and the key, or Authorization: Bearer. Autodiscover in its POX, JSON and SOAP forms is answered too. SOAP 1.1 and 1.2, Exchange error codes and throttling answers stay what your client expects.

  3. Watch the gap reportHonest coverage

    Every call is counted per operation. A call the bridge cannot translate gets a clear EWS error and a line in your gap report, never an empty success. The report shows what your application still needs, before a user notices.

Every EWS operation, as the bridge answers it today

Generated from the registry the bridge dispatches on, so this page cannot claim more than the code does.

41of 96 EWS operations answered through Microsoft Graph: 31 fully, 10 with documented limits.
  • 31 translated
  • 10 partial
  • 55 not translated

The 55 others answer with a clear EWS error and appear in your gap report. Most are administrative or rarely used; the analyzer tells you whether your applications call any of them.

Know your EWS traffic before 1 April 2027

Upload a usage report or a log. You get every EWS operation your applications call and the share the bridge answers today. Free, and nothing is stored.

  • Microsoft 365 admin center: Reports, Usage, Exchange, EWS usage, Export (CSV)
  • Exchange Server EWS logs (Logging\Ews) or HttpProxy logs with a SoapAction column
  • IIS logs of /EWS/Exchange.asmx
  • EWS traces (EWS Managed API <Trace Tag="EwsRequest">) or raw SOAP requests
  • A list of operation names, one per line, optionally with a count

or

The file is analyzed in memory and discarded with the response. Nothing is stored or logged.

Rewrite on Microsoft Graph, or bridge it

Microsoft’s advice is to move to Microsoft Graph, and for code you own and maintain that is the long-term answer. The bridge is for everything that cannot move before 1 April 2027.

Rewriting an EWS application on Microsoft Graph compared with running it through EWS Bridge
QuestionRewrite on Microsoft GraphEWS Bridge
Code changesEvery EWS call ported: a new data model, ids, paging, errors and throttling.The endpoint URL and the credential. The code keeps speaking EWS.
Time to productionWeeks to months per application, plus testing against a live tenant.The same day: admin consent, a bridge key, one configuration change.
Applications you cannot changeVendor and abandoned applications stop when EWS stops.Keep working, as long as they call operations the bridge translates.
What Graph cannot doYou design around the gaps yourself.The same gaps, documented per operation; such calls answer with an EWS error and show in the gap report.
After 1 April 2027Works: it calls Microsoft Graph.Works: the bridge calls Microsoft Graph, not EWS.
CostDeveloper time, then maintenance.From $149 a month per tenant, or $1,500 a year self-hosted.
Your dataBetween your application and Microsoft.Through the bridge, in memory only; or self-host the bridge.

Many teams do both: the bridge keeps production running while the rewrite happens, and the gap report shows which calls to port first.

Built so your mail stays yours

What the bridge keeps, what it never keeps, and how you limit what it can reach.

Message content is never stored.

Bodies, subjects, addresses, attachments and calendar content pass through memory and are answered. Logs carry no request URLs. How data is handled

What the bridge records about a call
{ "ts": "2026-09-30T08:14:03.512Z", "adapter": "ews",
  "operation": "FindItem", "status": "translated",
  "upstream_calls": 1, "latency_ms": 212,
  "request_id": "req_…" }

App-only consent you control

Eight Microsoft Graph application permissions, each tied to the EWS operations that need it. Revoke them in Microsoft Entra at any time.

  • Mail.ReadWrite
  • Mail.Send
  • Calendars.ReadWrite
  • Contacts.ReadWrite
  • User.Read.All
  • MailboxSettings.ReadWrite
  • Place.Read.All
  • GroupMember.Read.All

Limit it to some mailboxes

An Application Access Policy or RBAC for Applications restricts the bridge to a mail-enabled security group.

New-ApplicationAccessPolicy -AppId <app-id> -PolicyScopeGroupId <group> -AccessRight RestrictAccess

Keys hashed, secrets sealed

Bridge keys are stored as SHA-256 hashes and shown once. Tenant settings are sealed with AES-256-GCM. The console is HTTPS only.

Or run it yourself

The same bridge as a Docker image on your server, with no tenant limit: mail never leaves your network except to Microsoft Graph. $1,500 a year.

Pricing

Per Microsoft 365 tenant, or a yearly licence to run the bridge yourself. Going over the monthly volume never breaks your integration: we get in touch instead.

Tenant

$149/month

One Microsoft 365 tenant, up to 50,000 requests a month.

Buy Tenant

Tenant Plus

$299/month

One Microsoft 365 tenant, up to 500,000 requests a month.

Buy Tenant Plus

Self-hosted

$1,500/year

Run the bridge on your own server (Docker), no tenant limit.

Buy Self-hosted

Payment is handled by Paddle, our reseller and Merchant of Record (buyer terms): card, invoice and sales tax. Buying takes you to bridges.avakode.com, the Avakode Bridges checkout, where Paddle’s checkout opens. Monthly plans can be cancelled at any time and end with the paid month; the first payment is refundable for 14 days, the self-hosted licence for 14 days from purchase (Terms · Refunds · Privacy). Your licence key (FRG-…) arrives by email a few minutes later. Already have one? Sign in to the console to create your bridge.

Questions IT teams ask

Anything else: support@avakode.com.

Does the bridge still work after 1 April 2027?

Yes. The bridge calls Microsoft Graph, not EWS, so Microsoft switching EWS off does not affect it. Your application speaks EWS to the bridge only.

Is this a migration tool?

No. It is a translation layer that runs in production: your application keeps sending EWS SOAP, the bridge performs each call through Microsoft Graph and answers in the EWS format your client already parses.

What happens to an operation the bridge does not translate?

It answers with a clear EWS error (“Not translated by Avakode EWS Bridge: …”) and appears in your gap report. The bridge never returns an empty success for something it did not do.

Which permissions does it need, and why?

Eight Microsoft Graph application permissions: Mail.ReadWrite, Mail.Send, Calendars.ReadWrite, Contacts.ReadWrite, User.Read.All, MailboxSettings.ReadWrite, Place.Read.All, GroupMember.Read.All. The connection guide lists the EWS operations each one serves.

Can we restrict it to a few mailboxes?

Yes: an Exchange Online Application Access Policy or RBAC for Applications, scoped to a mail-enabled security group. The guide has the PowerShell.

Do you store our mail?

No. Content passes through memory only. The bridge keeps your tenant id, sealed settings, key hashes, daily counters and coverage metadata; the security page lists everything.

We run Exchange Server on-premises. Do we need this?

Microsoft’s EWS retirement applies to Exchange Online. Exchange Server on-premises keeps EWS; the bridge is for mailboxes in Exchange Online.

Can we run the bridge ourselves?

Yes. The self-hosted licence ($1,500 a year) runs the same bridge as a Docker image on your server, with no tenant limit.

How do we pay, and can we cancel?

Paddle is our reseller and Merchant of Record: card or invoice, with sales tax handled. Monthly plans can be cancelled at any time and end with the paid month; the first payment is refundable for 14 days (Refund Policy).

Who is behind EWS Bridge

EWS Bridge is built and run by Avakode, a small software company making bridges for retired APIs. Questions go to people who wrote the code: support@avakode.com, answered within two business days.

Company
Avakode, trading name of Individual Entrepreneur Darya Avakova
Registered
Tashkent, Republic of Uzbekistan · Tax ID 534556558
Payments
Paddle.com, our reseller and Merchant of Record: card or invoice, sales tax handled
Legal
Terms · Privacy · Refunds
Family
Avakode Bridges: EWS Bridge and Legacy Bridge