Tenant
One Microsoft 365 tenant, up to 50,000 requests a month.
Buy TenantIn 2 daysExchange Online starts disabling EWS on 1 October 2026
EWS Bridge answers your application’s EWS calls through Microsoft Graph. Change the endpoint and the credential, keep the code.
Your application sendsEWS SOAP · FindItem
<m:FindItem Traversal="Shallow"> <m:IndexedPageItemView MaxEntriesReturned="10" Offset="0" BasePoint="Beginning" /> <m:Restriction> <t:And> <t:Contains ContainmentMode="Substring" ContainmentComparison="IgnoreCase"> <t:FieldURI FieldURI="item:Subject" /> <t:Constant Value="meeting notes" /> </t:Contains> <t:IsEqualTo> <t:FieldURI FieldURI="message:Sender" /> … </t:IsEqualTo> </t:And> </m:Restriction> <m:SortOrder> <t:FieldOrder Order="Descending"> <t:FieldURI FieldURI="item:DateTimeReceived" /> …
EWS Bridge callsMicrosoft Graph v1.0
GET /users/alex@contoso.com/mailFolders/inbox/messages ?$filter=receivedDateTime ge 1900-01-01T00:00:00Z and contains(subject,'meeting notes') and sender/emailAddress/address eq 'sadie@contoso.com' &$orderby=receivedDateTime desc &$top=10 &…
FindItemResponseMessageResponseClass="Success"TotalItemsInView="1"Fixture ews/FindItem/restriction-and-sort from our test suiteEWS in Exchange Online is switched off in two steps. Applications that still call it need another way to reach Microsoft 365.
Microsoft: “EWS starts to be disabled globally for all organizations.” Tenants that have not kept EWS on with an AppID allow list get EWSEnabled=False as the rollout reaches them. An administrator can switch EWS back on until the final shutdown, after an interruption.
Microsoft: “EWS is fully disabled.” Administrators can no longer control EWSEnabled, and there are no exceptions past April 2027. Applications that still call EWS stop working.
The retirement applies to Exchange Online in Microsoft 365. Exchange Server in your own data centre keeps EWS. The bridge is for mailboxes in Exchange Online.
Sources: Microsoft Learn, Deprecation of Exchange Web Services in Exchange Online, and the Exchange Team’s rollout plan, checked on 30 September 2026.
The bridge accepts EWS SOAP, performs each call through Microsoft Graph with an app-only token of your tenant, and answers exactly like Exchange.
A Global Administrator signs in with Microsoft in the console and grants admin consent to the Avakode EWS Bridge application: app-only Microsoft Graph permissions, no user passwords. The bridge takes your tenant from Microsoft’s signed token, never from a URL.
// EWS Managed API: the only line that changes
service.Url = new Uri("https://ews.avakode.com/EWS/Exchange.asmx");Authenticate with the bridge key: Basic with the mailbox address and the key, or Authorization: Bearer. Autodiscover in its POX, JSON and SOAP forms is answered too. SOAP 1.1 and 1.2, Exchange error codes and throttling answers stay what your client expects.
Every call is counted per operation. A call the bridge cannot translate gets a clear EWS error and a line in your gap report, never an empty success. The report shows what your application still needs, before a user notices.
Generated from the registry the bridge dispatches on, so this page cannot claim more than the code does.
The 55 others answer with a clear EWS error and appear in your gap report. Most are administrative or rarely used; the analyzer tells you whether your applications call any of them.
Upload a usage report or a log. You get every EWS operation your applications call and the share the bridge answers today. Free, and nothing is stored.
Logging\Ews) or HttpProxy logs with a SoapAction column/EWS/Exchange.asmx<Trace Tag="EwsRequest">) or raw SOAP requestsMicrosoft’s advice is to move to Microsoft Graph, and for code you own and maintain that is the long-term answer. The bridge is for everything that cannot move before 1 April 2027.
| Question | Rewrite on Microsoft Graph | EWS Bridge |
|---|---|---|
| Code changes | Every EWS call ported: a new data model, ids, paging, errors and throttling. | The endpoint URL and the credential. The code keeps speaking EWS. |
| Time to production | Weeks to months per application, plus testing against a live tenant. | The same day: admin consent, a bridge key, one configuration change. |
| Applications you cannot change | Vendor and abandoned applications stop when EWS stops. | Keep working, as long as they call operations the bridge translates. |
| What Graph cannot do | You design around the gaps yourself. | The same gaps, documented per operation; such calls answer with an EWS error and show in the gap report. |
| After 1 April 2027 | Works: it calls Microsoft Graph. | Works: the bridge calls Microsoft Graph, not EWS. |
| Cost | Developer time, then maintenance. | From $149 a month per tenant, or $1,500 a year self-hosted. |
| Your data | Between your application and Microsoft. | Through the bridge, in memory only; or self-host the bridge. |
Many teams do both: the bridge keeps production running while the rewrite happens, and the gap report shows which calls to port first.
What the bridge keeps, what it never keeps, and how you limit what it can reach.
Bodies, subjects, addresses, attachments and calendar content pass through memory and are answered. Logs carry no request URLs. How data is handled
{ "ts": "2026-09-30T08:14:03.512Z", "adapter": "ews",
"operation": "FindItem", "status": "translated",
"upstream_calls": 1, "latency_ms": 212,
"request_id": "req_…" }Eight Microsoft Graph application permissions, each tied to the EWS operations that need it. Revoke them in Microsoft Entra at any time.
An Application Access Policy or RBAC for Applications restricts the bridge to a mail-enabled security group.
New-ApplicationAccessPolicy
-AppId <app-id>
-PolicyScopeGroupId <group>
-AccessRight RestrictAccessBridge keys are stored as SHA-256 hashes and shown once. Tenant settings are sealed with AES-256-GCM. The console is HTTPS only.
The same bridge as a Docker image on your server, with no tenant limit: mail never leaves your network except to Microsoft Graph. $1,500 a year.
Per Microsoft 365 tenant, or a yearly licence to run the bridge yourself. Going over the monthly volume never breaks your integration: we get in touch instead.
One Microsoft 365 tenant, up to 50,000 requests a month.
Buy TenantOne Microsoft 365 tenant, up to 500,000 requests a month.
Buy Tenant PlusRun the bridge on your own server (Docker), no tenant limit.
Buy Self-hostedPayment is handled by Paddle, our reseller and Merchant of Record (buyer terms): card, invoice and sales tax. Buying takes you to bridges.avakode.com, the Avakode Bridges checkout, where Paddle’s checkout opens. Monthly plans can be cancelled at any time and end with the paid month; the first payment is refundable for 14 days, the self-hosted licence for 14 days from purchase (Terms · Refunds · Privacy). Your licence key (FRG-…) arrives by email a few minutes later. Already have one? Sign in to the console to create your bridge.
Anything else: support@avakode.com.
Yes. The bridge calls Microsoft Graph, not EWS, so Microsoft switching EWS off does not affect it. Your application speaks EWS to the bridge only.
No. It is a translation layer that runs in production: your application keeps sending EWS SOAP, the bridge performs each call through Microsoft Graph and answers in the EWS format your client already parses.
It answers with a clear EWS error (“Not translated by Avakode EWS Bridge: …”) and appears in your gap report. The bridge never returns an empty success for something it did not do.
Eight Microsoft Graph application permissions: Mail.ReadWrite, Mail.Send, Calendars.ReadWrite, Contacts.ReadWrite, User.Read.All, MailboxSettings.ReadWrite, Place.Read.All, GroupMember.Read.All. The connection guide lists the EWS operations each one serves.
Yes: an Exchange Online Application Access Policy or RBAC for Applications, scoped to a mail-enabled security group. The guide has the PowerShell.
No. Content passes through memory only. The bridge keeps your tenant id, sealed settings, key hashes, daily counters and coverage metadata; the security page lists everything.
Microsoft’s EWS retirement applies to Exchange Online. Exchange Server on-premises keeps EWS; the bridge is for mailboxes in Exchange Online.
Yes. The self-hosted licence ($1,500 a year) runs the same bridge as a Docker image on your server, with no tenant limit.
Paddle is our reseller and Merchant of Record: card or invoice, with sales tax handled. Monthly plans can be cancelled at any time and end with the paid month; the first payment is refundable for 14 days (Refund Policy).
EWS Bridge is built and run by Avakode, a small software company making bridges for retired APIs. Questions go to people who wrote the code: support@avakode.com, answered within two business days.