From 1 October 2026, Microsoft is retiring Exchange Web Services (EWS) â the protocol Access Profile uses to connect to Microsoft 365 mailboxes and calendars. If your tenant is not configured to keep EWS enabled, Access Profile will lose its mailbox and calendar connection.
This change is made by Microsoft, not Access. The fix is a setting on your own Microsoft 365 tenant, so your organisation's IT team or Global Admin needs to make it. Access Support cannot make this change on your behalf, even though Access Profile itself is hosted by Access.
â ď¸Important: EWS will be permanently switched off by Microsoft on 1 April 2027, with no extensions granted. We recommend acting before 1 October 2026 to avoid any interruption to your mailbox and calendar connection.
Environment
Access Profile Cloud (hosted by Access)
Mailbox and calendar integration with Microsoft 365 / Exchange Online
Symptoms
Access Profile stops connecting to Microsoft 365 mailboxes or calendars from 1 October 2026.
Mailbox actions or calendar syncs fail or return connection errors.
Cause
Microsoft is retiring EWS for Exchange Online. From 1 October 2026, Microsoft blocks EWS by default on any Microsoft 365 tenant that has not been configured to keep it enabled. EWS will be permanently switched off on 1 April 2027.
For further context, see Microsoft's announcement: Exchange Online EWS, Your Time is Almost Up.
Resolution
Your IT support company, or whoever holds the Global Admin role on your Microsoft 365 subscription, needs to re-enable EWS for Access Profile. Follow the steps below.
Before you start
You will need:
Global Admin access to the Microsoft 365 / Exchange Online tenant.
The Access Profile App ID (required for Option A only):
a7b883f4-4c85-475d-ae43-3aa754876a18
Step 1: Check the current EWS status
Connect to Exchange Online PowerShell and run the following commands:
Check whether EWS is enabled:
Get-OrganizationConfig | Format-List EwsEnabled
Check which apps are on the allow list:
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs
The EWS Usage Report in the Microsoft 365 admin centre also shows which applications â including Access Profile â are still using EWS.
Step 2: Choose an option
Option A â Enable EWS with an App ID allow list (Microsoft's recommended option)
Only the applications you approve can use EWS. Run the following command in Exchange Online PowerShell:
Set-OrganizationConfig -EwsEnabled $true -EwsAllowedAppIDs "a7b883f4-4c85-475d-ae43-3aa754876a18"
â ď¸Important: This command replaces the entire allow list every time it is run. If other applications are already on the list (visible in Step 1), include all of their App IDs as well, separated by commas â for example: "a7b883f4-4c85-475d-ae43-3aa754876a18,<other-app-id>". Otherwise those applications will lose access.
The allow list can also be managed through Baseline Security Mode in the Microsoft 365 admin centre. The EwsEnabled setting itself can only be changed in PowerShell.
Option B â Remove restrictions (temporary, until April 2027)
This re-opens EWS for all applications until Microsoft's final shutdown. Run the following command in Exchange Online PowerShell:
Set-OrganizationConfig -EwsEnabled $null
đNote: Option B only works after Microsoft has switched the tenant to blocked (EwsEnabled = False), which happens on or after 1 October 2026.
Step 3: Test the connection
Run a test calendar sync or mailbox action in Access Profile and confirm it completes without errors. Changes can take some time to take effect.
Step 4: If the change is made after 1 October 2026
If Microsoft has already blocked EWS on your tenant, expect a short interruption to the Access Profile mailbox and calendar connection until the change takes effect. Plan the change for a quiet period where possible.
Additional information
If you have no IT support company, you do not need one. The Global Admin just needs to run a single command. If they need help, they can contact Microsoft support as the tenant owner.
Access is developing a new version of Access Profile for cloud customers that no longer relies on EWS, moving to Microsoft Graph instead. Timelines will be shared once available.
Customers can speak to their Account Manager about Access's SaaS-based Recruitment CRM solutions.
Mailbox-level EWS settings: Exchange Online applies EWS access at two levels: the organisation and the individual mailbox. If EWS has been re-enabled at the organisation level but a single user still cannot connect, your IT admin should also check that EWS is enabled on that user's mailbox specifically.
FAQs
Q1: Why is this change happening?
Answer: This change is being driven by Microsoft as part of the retirement of Exchange Web Services (EWS). It is not a change initiated by Access.
Q2: What happens if no action is taken?
Answer: From 1 October 2026, Microsoft may block EWS connectivity, potentially causing mailbox and calendar integrations to stop working.
Q3: Is this issue limited to cloud customers?
Answer: This article applies to Access Profile Cloud customers. On-premise customers should refer to the dedicated on-premise guidance article.
Q4: When will EWS be permanently removed?
Answer: Microsoft has stated EWS will be permanently switched off on 1 April 2027.
