API sunsets · Microsoft · checked
Exchange Web Services (EWS) in Exchange Online shutdown on 1 April 2027
Exchange Web Services (EWS) in Exchange Online shuts down on 1 April 2027. After it, EWS is fully and permanently disabled in every Exchange Online tenant; and no allow list, setting or extension keeps it on. The failure is loud: calls return errors. Microsoft names Microsoft Graph as the replacement (Microsoft lists the gaps Graph has yet to close, most due in the third or fourth quarter of 2026, on its deprecation page; EWS in Exchange Server on premises is not retired). Record your real calls on EWS before the date and replay them on Microsoft Graph: after it, nobody can record what EWS returned. Find every place your code pins EWS: npx --allow-remote=root https://agentwares.vercel.app/dl/api-sunset-0.1.0.tgz scan
$ npx --allow-remote=root https://agentwares.vercel.app/dl/api-sunset-0.1.0.tgz scan
npx --allow-remote=root https://agentwares.vercel.app/dl/api-sunset-0.1.0.tgz scan lists every API version your code and config pin (Shopify, Meta Graph, Google Ads, HubSpot, Stripe and the rest of this list) with its end date, what breaks and this page's link. It needs no account and no API key, reads your files on your machine and sends nothing; its one request fetches this data. Free and MIT licensed.
The facts
- API
- Exchange OnlineCovers Exchange Web Services (EWS) in Exchange Online and Microsoft 365, such as outlook.office365.com/EWS/Exchange.asmx; not EWS in Exchange Server on premises.
- Version
ews- Announced
- 5 February 2026
- Ends
- 1 April 2027
- After the date
- calls fail
- Silent?
- No: calls return errors
- Replacement
Microsoft GraphMicrosoft lists the gaps Graph has yet to close, most due in the third or fourth quarter of 2026, on its deprecation page; EWS in Exchange Server on premises is not retired
What breaks after 1 Apr 2027
- Starting with April 1, 2027, EWS will be fully and permanently disabled, and the ability to control EWSEnabled will be removed from tenant admins. source
- There will be no exceptions past April 2027: an AppID Allow List and EWSEnabled=True keep EWS working only until the final shutdown. source
- Since 1 October 2026, a tenant whose EWSEnabled setting was still Null has it set to False as the rollout reaches it, which blocks EWS for every app. Until 1 April 2027 an admin can turn it back on (EWSEnabled=True with an AppID Allow List, or Null), after a service interruption.
- Before then Microsoft may switch EWS off for short periods ("scream tests") to expose hidden dependencies; a tenant that set EWSEnabled=True is not affected by them.
- Only Exchange Online and Microsoft 365 are affected; EWS in Exchange Server on premises is not retired.
- Microsoft's deprecation page gives the month, April 2027; the Exchange Team blog gives the day, 1 April 2027. They agree.
- The EWS usage reports in the Microsoft 365 admin center show which apps call EWS in a tenant; the scan finds the code that calls it.
How to upgrade
- Find every place your code and config pin EWS:
npx --allow-remote=root https://agentwares.vercel.app/dl/api-sunset-0.1.0.tgz scanprints each file and line, and the variable name for a.envfile, never its value. - Read what changed between EWS and
Microsoft Graphin Microsoft's notes, and list the calls that touch it. - Before 1 April 2027, send your real calls to EWS and to Microsoft Graph and compare the answers: same status, same fields, same values where they should match; after it, nobody can record what EWS returned.
- Change the version string, deploy, and watch the first day's responses.
Record your real calls on the old version before the date, and replay them on the new one.
agentcheck runs scheduled checks of an endpoint. A check sends the request you define (a path or a full URL, a method and a body, with your API key as a header, stored encrypted) on a schedule and compares each response with a golden: exact text, contains, a regular expression or a JSON Schema, none of which costs an LLM call. When a response stops matching, it opens an incident and alerts you. Point one check at EWS and one at Microsoft Graph with the same golden, and you see which of your calls answer differently before 1 April 2027.
Set up the two checks, freeFree: 1 monitored target, hourly checks, badge and public status page. Starter: 3 targets, 5-minute checks, Slack and Discord alerts, 30-day history. Recording the calls your code already makes is a different path: the trace import (POST /api/v1/targets/{id}/traces, or the agentcheck_record MCP tool) takes agent traces, a prompt and an answer, and turns them into checks judged by the LLM judge (Pro). It does not take raw HTTP requests and responses, so for an API the scheduled checks are the way in today.
Migration watch is not built. It would record the calls your code makes to Exchange Web Services (EWS) in Exchange Online and replay them on Microsoft Graph until 1 April 2027, with nothing to set up, and email you what answers differently. If you would pay for that, say so with one click. The click is counted, and nothing else is sent or stored unless you then leave an email.
Counted. Thank you; nothing else was sent.
Sources
- Exchange Online EWS, Your Time is Almost Up (Exchange Team Blog, updated 9 September 2026) — the date and the replacement, read 10 Oct 2026
Built only from Microsoft's own pages. No intent is implied: a date is what the page says on the day it was read. Data: /apis/sunsets.json.
api-sunset is a free tool from agentcheck, which runs scheduled checks of your endpoints and alerts you when an answer changes.