Blog Post

Exchange Team Blog
1 MIN READ

Update to EWS Access for Kiosk / Frontline Worker Licensed Users

The_Exchange_Team's avatar
The_Exchange_Team
Platinum Contributor
Dec 02, 2025

Update 12/15/2025: We modified the date of this change to end of June 2026 based on customer feedback. Please use that extra time to remove your dependencies on EWS.

As part of our ongoing efforts to deprecate Exchange Web Services (EWS), starting at the end of June 2026, we will start to block EWS access for all mailboxes without license rights to EWS. This is another step in our ongoing commitment to enhance the security and control mechanisms of EWS.

The impacted licenses are:

  • Exchange Online Kiosk
  • Microsoft 365 and Office 365 F1
  • Microsoft 365 and Office 365 F3

As stated in the Service Descriptions, these licenses do not provide access to mailboxes via EWS, but these restrictions were never enforced. With this change, EWS access for users with only these license types will be blocked.

If you wish them to use EWS, and your users are licensed with one of these noted above, you’ll need to assign a new license, one containing EWS access rights. For example, you could assign an Exchange Online Plan 1 or 2 license, or a Microsoft 365 or Office 365 E3 or E5 license.

Starting July 1, 2026, requests to use EWS without a suitable license will result in a HTTP 403 response.

The Exchange Team

Updated Dec 18, 2025
Version 4.0

18 Comments

  • Hi . My customer has the following question. Can you confirm that they will not be impacted? 

    We have employees with M365 F3 licenses, and using Exchange Webmail (OWA) with the 2GB storage limit. We want to make sure that the change below won't impact this use case. Could you please confirm and indicate if there is anything we should check in particular to confirm?

  • Is there are report or process I can use to determine if the change will impact our tenant? I am not sure which (if any) of our Exchange licenses are using EWS. We have many F3 licenses. I need a report or process I can use to gauge impact and communicate to the organization so they can decide if they want to upgrade to or more expensive license, deprecate or choose another path. Before the deadline I'd like to know the impact. If there is a way to get the info from Audit Logs or from the current "EWS Usage" report please help a brother out. I can open a support case if needed.  

    • davidvasta's avatar
      davidvasta
      Icon for Microsoft rankMicrosoft

      Yes, in O365 under the ADMIN Section, not Exchange there is a report. REPORTS > EXCHANGE > EWS Usage

      The report provides a comprehensive list of all registered apps using the EWS API for this tenant.

      That report should be helpful when trying to find out more about the EWS and your mailboxes. Adding Plan 1 or Plan 2 to those mailboxes will allow the KISKO and F3 license to still have EWS access, but keep in mind we are less than a year away from turning it off for good and the plan has been in place since 2018. Moving those applications to REST or GRAPH is critical now.



      There are also tools here that can help with EWS Discovery:

      https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/deprecation-of-ews-exchange-online#ews-deprecation-timeline

       

      • Ken_Harrell1145's avatar
        Ken_Harrell1145
        Brass Contributor

        I saw the EWS usage report and it looks like just application IDs are in there, I do not see any mailboxes. It says we have 6 applications. 

         

         

        Will that show mailboxes as well?

  • Hello,

    In Hybrid environments, for accounts where mailboxes are hosted on On-premise Exchange and which only use Teams on the M365 side (with a package like Microsoft Teams Essentials etc.), I believe the Exchange-Teams calendar synchronizations and Free/Busy availability status should not be affected by this EWS restriction, but I am not entirely sure about this. What do you think?

    MS Teams has a 2GB mailbox in the background to process objects like the calendar, etc. This mailbox is not visible in Exchange Online, cannot be used directly as an email account by people, but it still exists; it must exist. As far as I know, this mailbox package does not have a plan equivalent (like F1, F3, Kiosk, Plan1/2 etc.). Microsoft explicitly defines this mailbox used by Teams as 'Teams uses a lightweight unlicensed Exchange mailbox for Calendar.'

    Note: Microsoft says "that standalone Teams packages do not include Exchange Online". However, I once observed that due to an issue locally, the Exchange server was freshly installed, the Hybrid structure was broken during this process, and 2GB mailboxes were created for the users in Exchange Online.

  • tsd-bf's avatar
    tsd-bf
    Copper Contributor

    Why couldn't mailbox access be bundled in the F1 license? Is moving our users to Teams Essentials an option?

  • niehweune1's avatar
    niehweune1
    Copper Contributor

    Will this also affect access to these mailboxes as an app, i.e. when an app registration has EWS.AccessAsUser.All and/or full_access_as_app permissions on Exchange, will it still be able to get to those user's mailbox content after March 1st 2026?

    This is important, since this will break some (if not all) third party mailbox migration tools that still (forcibly) rely on EWS in their backend to access user mailbox data. There's still no complete feature parity between Graph and EWS, especially for these usage scenario's. E.g. there's still no access to archive mailboxes, even using the import/export api (which is also still in preview so 'not supported in production').

    The announcement from Sep 2023(!) stated 'we are working [on this] and will provide an updated timeline in the coming months.', but from what I can tell, over 2 years later we're still waiting on that timeline?

    • JrouziesM's avatar
      JrouziesM
      Brass Contributor

      I'm not sure you can have an Archive mailbox without an Exchange Plan 1 / 2, which in itself will support EWS.

      But I agree, there was already a downtime for Veeam 365 that impacted all Kiosk / F3 licenses recently, meaning all backups were blocked. Unsure if this was a test change from Microsoft, but that needs to be taken into consideration with major backup or data migration providers (Veeam, HYCU, Quest, etc.).

    • Greg Taylor - EXCHANGE's avatar
      Greg Taylor - EXCHANGE
      Icon for Microsoft rankMicrosoft

      Any use of EWS on a user's mailbox not licensed for it will be blocked. If the license is one with EWS rights, it'll work. 

      We have lots of work in progress on those gaps, we'll have lots to share in the coming months. 

  • JrouziesM's avatar
    JrouziesM
    Brass Contributor

    EWS ok, but what about GraphAPI?

    And what about Shared Mailboxes?

    What about OnPrem > Cloud migration endpoints that I think use EWS, that would target a mailbox licenses with Kiosk / F3?

    • No changes to Graph API or Shared Mailboxes. On-Prem to Cloud using MRS is a pull operation, and does not use EWS to populate the target mailbox. 

  • Beanvee2's avatar
    Beanvee2
    Copper Contributor

    Does this also include shared mailboxes, since they're usually unlicensed?

    • davidvasta's avatar
      davidvasta
      Icon for Microsoft rankMicrosoft

      No this does not include Shared Mailboxes unless they have one of those licensees, which would probably not be the best use of a license as a shared mailbox gets more space and features by just being a shared mailbox by itself.

  • AdeleVDev's avatar
    AdeleVDev
    Copper Contributor

    Hello,

    I recently am having an issue where I cannot set the EWS enabled for my users using the command of Set-CASMailbox -EwsEnabled $True (It errors out "License validation error: the action 'Set-CASMailbox', 'EwsEnabled', can't be performed on the user '' with license 'BPOS_S_Deskless"). This is for my users who have F3 Licensing. Has this changed recently or should we expect this to work up until March 1 2026?  This is only happening on my F3 users.

    If we can no longer set the EwsEnabled property to True for F3 licensed users would I need to re license these users? 
    I have seen the documentation stating EWS application is not supported for F3 licensed users but I was able to set this property to True up until a week ago.  

    Some clarification on this would be greatly appreciated.

    Thank you, 




    • Despite that error, and EWSEnabled showing as False, the user should be able to use EWS. Until March 1st, 2026.

      You don't need to try and set EWSEnabled to True for it to work, for users with Kiosk/F1/F3 only.