# Deprecation of EWS for Exchange Online

Microsoft are [deprecating Exchange Web Services (EWS) for Exchange Online](https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/deprecation-of-ews-exchange-online), disabling it for Organisations in **October 2026** and fully removing it in **April 2027**.

Therefore, you will need to migrate any accounts accessing Exchange Online via EWS  to use the Graph API before October to avoid any interruption to your connections. To do this, you need to follow our 'Migrate from EWS to Graph API Flow'.

## Migrating an Individual Connect connection
Individual users need to reauthorize their calendar via Graph API. Cronofy will email each affected user a migration link ahead of the October 2026 deadline, so there is nothing you need to do to start this process.

Clicking that link takes the user through the same steps they followed the first time they connected: they sign in with Microsoft and confirm they are happy to grant access again. This works in much the same way as relinking a calendar, and only affects the link between Cronofy and that user's calendar.

If a user sees a **"Need admin approval"** message, their organization's IT admin needs to approve the Cronofy application within the tenant before they can continue.

Our team can also provide the migration URL for a specific user, or an admin consent link, if you contact support at [support@cronofy.com](mailto:support@cronofy.com).

## Migrating an Enterprise Connect connection
### Before you migrate
Before migrating, you will need to:

- Configure the same limited access rules to the new Graph service account as previously configured for the Exchange service account. This must be completed before connecting via Graph, otherwise Cronofy may be able to sync data for more accounts than we did previously. See ['Do I need to setup any permissions before migrating?'](#do-i-need-to-setup-any-permissions-before-migrating) below.

- Ensure the account you use to authorize the M365 tenant to our Graph API application is an administrator of your Microsoft 365 tenant.

### How to migrate your EWS application
Your IT Admin will need to migrate your existing EWS connection to use the new Graph API connector. This can be done using our **Migrate from EWS to Graph API Flow**. This will create a new Graph Service Account for your tenant which will ensure your existing services connected through Cronofy continue to work. To do this:

- 
In order to log in to the existing EWS service account, select the relevant data center link below:

<li>[https://app.cronofy.com/enterprise_connect/authorizations](https://app.cronofy.com/enterprise_connect/authorizations)

- [https://app-au.cronofy.com/enterprise_connect/authorizations](https://app-au.cronofy.com/enterprise_connect/authorizations)

- [https://app-ca.cronofy.com/enterprise_connect/authorizations](https://app-ca.cronofy.com/enterprise_connect/authorizations)

- [https://app-de.cronofy.com/enterprise_connect/authorizations](https://app-de.cronofy.com/enterprise_connect/authorizations)

- [https://app-sg.cronofy.com/enterprise_connect/authorizations](https://app-sg.cronofy.com/enterprise_connect/authorizations)

- [https://app-uk.cronofy.com/enterprise_connect/authorizations](https://app-uk.cronofy.com/enterprise_connect/authorizations)

</li>
- 
Select the 'Office 365' option, then at the bottom of the next page select 'Login with an Exchange Service Account'. Log in using the existing EWS service account credentials.

![](/images/office365-exchange-option-red-border.7af2508e72f7c8e7fecfdba67cabd0ff9efa7048f5cfafee153a30c41ad1a98d.png)


- 
If you have a pending migration to Graph API, you will see the 'Migrate to Graph API' button.

![](/images/migrate-to-graph-required-button.deafffdf97574234ea8456716484ab6db3b4beacb963efdcd944a980eae5fe87.png)


- 
Once clicked, you will see a page with a button 'Connect Graph Service Account' to start the migration flow.

![](/images/start-migration-button.38b3943f6ab1831de0d9594c4944fb3c1427fcc5454992a490a4c38f6330eead.png)


- 
Accept the new Graph API permissions to authorize the new application.

![](/images/graph-permissions.0a6867555dcbc075e076c2ad43d24f1c194878b88e4c7dc386f7e6ce00aa55a3.png)


- 
Once successfully migrated you will see a message stating 'Successfully connected Graph Service Account'.

![](/images/successful-migration.09f6cf7cbf49ac9e638656f0b1330e87c0e76e0611d0fb14fcdc0d0fb33860b5.png)


### Do I need to setup any permissions before migrating?
If you have setup [Impersonation access with Distribution Groups](/calendar-admins/enterprise-connect-office365-exchange/access-via-distribution-groups/index.md), you will need to ensure that you configure an **[Role-Based Access Control Policy](/calendar-admins/enterprise-connect-office365-graph/restrict-data-access-rbac/index.md)** within your Office 365 Exchange tenant with the users to which you wish to restrict access instead. This will ensure that the new Graph API application will have the same access as the previous Exchange application.

### Errors
If you experience any errors when trying to migrate the EWS application to Graph API, please refer to the common errors below. If you are still experiencing issues, please reach out to us at [support@cronofy.com](mailto:support@cronofy.com).

##### Selected user account doesn’t exist in tenant
![](/images/user-tenant-error.fe0ad16e7c057f80c127b82be156cc4f0840a737e16b328bb1936fb62d7f56b4.png)
This occurs if you attempt to connect a Graph Service Account for a different tenant than the one that was previously connected using Exchange. You need to go back and select an administrator account that exists in the same tenant as the Exchange Service Account that you're trying to migrate.

##### Admin consent failed
![](/images/migration-admin-consent-failed.8da3d86bb8cb2c6c709ee832d87b1c281cf137d512bb012f6045bc88a00bfd0b.png)
This occurs when the account you have selected during the migration doesn't have admin permissions required to authorize the M365 tenant to the new application. You need to go back and select an account that has administrator permissions in the tenant that you're trying to migrate. You can see more about this via this [guide:](/calendar-admins/faqs/need-admin-approval-error/index.md).

## Extending EWS support until April 2027
If you cannot migrate before EWS is disabled in October 2026, you can extend EWS support until April 2027 by adding Cronofy's **Application ID** `820f153b-2593-41ba-8d8c-157eec4bb791` to your organisation's allowed apps, following [Microsoft's guidance](https://techcommunity.microsoft.com/blog/exchange/introducing-ewsallowedappids-preparing-for-the-final-phase-of-ews-retirement/4529471).

This only delays the deadline rather than removing it, as EWS is fully removed in April 2027. You will still need to migrate to Graph API before then.

## Contact Us
If you require assistance with any of the above, please reach out to our support team at [support@cronofy.com](mailto:support@cronofy.com) or click the support widget on this page.


---
[Read in HTML](/calendar-admins/faqs/ews-exchange-online-retirement/)