EWS Retirement and Your AI Email Assistant

Microsoft starts disabling Exchange Web Services in October 2026 and asks admins to check every third-party app. What Insulin's docs say about its Outlook connection, and the report in your tenant that settles it.

Shirley Guo
Shirley Guo
Oct 8, 2026

EWS retirement is Microsoft’s phased disabling of Exchange Web Services (EWS) in Exchange Online: on Microsoft’s schedule it starts in October 2026, and EWS is fully disabled in April 2027. Fours documents the AI tools on its Outlook integration as wrapping the Microsoft Graph Mail API, Insulin’s Inbox app reuses that integration’s connection, and the EWS usage report in your own tenant shows whether any application still calls EWS.


Microsoft’s Learn page on the deprecation gives admins a call to action. The first item is to “Investigate the EWS footprint of all internal and third party applications in your organization.” Another is to “Work with your vendors to prioritize their migration from EWS.” An AI email assistant that reads and sends Outlook mail is one of those third-party applications, so its vendor gets the question: does your Outlook connection depend on EWS?

This post answers it for Insulin’s Inbox app with what the documentation states, laid out as an answer card you can copy into the audit. Then it shows the report in your own tenant that settles the question, and how to review and revoke the access your users granted.

What is EWS retirement, and when does it happen?

EWS retirement is Microsoft’s phased disabling of Exchange Web Services (EWS) in Exchange Online: Microsoft’s schedule starts it in October 2026 and has EWS fully disabled in April 2027. EWS is the older interface that applications call, through SOAP actions, to work with Exchange mailboxes, and Microsoft’s usage report counts each application’s calls by SOAP action.

Microsoft’s Learn page on the deprecation, last updated September 4, 2026, gives this timeline. It lists the last two rows under Upcoming:

WhenWhat Microsoft’s page saysKind of date
July 2018EWS deprecation announced: EWS will no longer receive functionality updatesAnnouncement
2023”EWS disablement date set to 10/2026”Announcement
January 2024The Midnight Blizzard security incident, which involved EWS. The scope “was also widened from third party applications to include all Microsoft applications”Incident
2025EWS usage reports released, and admins allowed to “manually disable EWS at the organization and user levels”Tools released
October 2026”EWS starts to be disabled globally for all organizations”Effective: disabling starts
April 2027”EWS is fully disabled”Effective: fully disabled

Two more things on the page matter for an audit:

  • The dates are Microsoft’s schedule, not your tenant’s. October 2026 is when disabling starts across all organizations. For “the latest updates on timeline and disablement process”, Learn points to the Exchange team’s post Exchange Online EWS, Your Time is Almost Up, which is where to check how the change reaches your tenant.
  • Microsoft’s own applications are in scope too. Since Midnight Blizzard, Microsoft has been removing EWS from its own products, naming Outlook, Office, Teams and Dynamics 365 among them. Third-party applications were in scope from the start. The retirement is of EWS in Exchange Online.

What should your EWS audit record for Insulin?

Record two documented facts about Insulin’s Outlook connection, then the result of your own EWS usage report. Each row of this answer card names the page that states it, so it can go into an audit as it stands:

Audit questionAnswer for Insulin’s Inbox appWhere it is stated
When does EWS stop working?Microsoft’s schedule: disabling starts in October 2026, and EWS is fully disabled in April 2027Microsoft Learn, Deprecation of Exchange Web Services in Exchange Online
Which Microsoft API does Fours document for Outlook?”Fours AI uses a middleware strategy — wrapping the Microsoft Graph Mail API directly.”Fours docs, Microsoft Outlook integration, Fours AI Tools
Does Inbox sign in to Outlook separately?No: “Inbox does not run its own OAuth flow — it reuses the connection you set up under Integrations.”Fours docs, Inbox, Connecting a Mailbox
Whose connection does Inbox use?Each user’s own: the mailbox is one of the user-level integrations Inbox’s rules check for, and a connection at the organization level does not satisfy themFours docs, Inbox, Rules
What does a user grant?The user clicks Accept on Microsoft’s OAuth 2.0 authentication page: “This authorization enables Fours to read, send emails on your behalf.”Fours docs, Microsoft Outlook integration
Has the application called EWS in your tenant?Your result: look for its Application ID in the EWS usage reportMicrosoft Learn, Exchange Web Services (EWS) usage report
Where is the grant recorded?The Microsoft Entra admin center: the application’s Permissions page, on the Admin consent or User consent tabMicrosoft Learn, Review permissions granted to enterprise applications
How is access removed?Delete the integration in Fours and revoke the permissions in Microsoft, because deleting the integration alone does not revoke themFours docs, Microsoft Outlook integration, Delete Integration

What Inbox does differently on an Outlook mailbox is a separate question from EWS, and the comparison of the AI email assistant on Outlook and Gmail answers it.

Which Microsoft API does Insulin’s Outlook integration use?

Fours documents the AI tools on its Outlook integration as “wrapping the Microsoft Graph Mail API directly”, and Insulin’s Inbox app reuses that integration’s connection instead of running a sign-in of its own. Microsoft Graph is the API Microsoft maps EWS operations to: “Many application scenarios are already supported with direct mappings between EWS operations and Graph APIs,” its Learn page says.

The two statements come from two pages of the Fours documentation:

  • The Microsoft Outlook integration page, in the section headed Fours AI Tools: “Fours AI uses a middleware strategy — wrapping the Microsoft Graph Mail API directly.” The section’s tool list runs from reading the profile, folders and messages to sending replies and managing drafts.
  • The Insulin Inbox page, under Connecting a Mailbox: “Inbox does not run its own OAuth flow — it reuses the connection you set up under Integrations.” Clicking Enable Inbox for Outlook health-checks your access, registers the mailbox webhook and starts building your writing style.

The connection Inbox reuses is each user’s own. The Inbox documentation lists the mailbox among the checks a rule must pass before it saves, and says of them: “All of these are user-level integrations, so the fix links point at Settings → Integrations → User Integrations or your Account page — connecting one at the organization level does not satisfy them.”

Neither page mentions EWS. You don’t need to take a vendor’s word on it either way, because Microsoft built a report that answers the question from your own tenant.

How do you check for EWS calls in your own tenant?

Open the EWS usage report in the Microsoft 365 admin center: it lists every application that sent at least one EWS request in the period, by Application ID, with the SOAP actions it called. Microsoft’s page on the EWS usage report gives the path and how to read it:

  1. In the Microsoft 365 admin center, select Reports, then Usage. If you don’t see Reports, select Show all first.
  2. On the Usage page, under Reports, select Exchange, then the EWS usage tab.
  3. Set the period to the last 90 days, the longest of the report’s 7, 30 and 90-day filters.
  4. Read the Usage details table: Application ID (the Microsoft Entra identifier for the registered application), SOAP Action, Call Volume and Last Activity date (UTC). Export saves the data as a .csv file.
  5. Match each Application ID to an application. When an ID isn’t familiar, Learn sends you to your Enterprise Applications in Microsoft Entra ID.

Two cautions come from the same page. Usage data “is collected and aggregated weekly, not daily”, and “It can take up to 10 days for usage to show in the report.” And a row appears only for an application that called EWS during the period, so a missing row tells you something only if the application was in use: read the 90-day view across a stretch when at least one person had Inbox enabled on an Outlook mailbox.

What do your users grant when they connect Outlook?

Each user grants Fours access on Microsoft’s own consent page: connecting the integration redirects to the Microsoft OAuth 2.0 authentication page, where the user clicks Accept. The Fours docs describe the grant in one line: “This authorization enables Fours to read, send emails on your behalf.”

The Outlook integration has two levels. At the organization level it “Uses Azure AD app registration for organization-wide access”; at the user level, “Each user authenticates via Microsoft OAuth for personal Outlook access.” Inbox counts only the second, since its documentation treats the mailbox as a user-level integration that a connection at the organization level does not satisfy. So for Inbox, the grant to look for is each user’s own.

To see those grants from the admin side, follow Microsoft’s page on how to review permissions granted to enterprise applications, whose steps “apply to all applications that were added to your Microsoft Entra tenant via user or admin consent”:

  • Where. Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator, browse to Entra ID > Enterprise apps > All applications, select the application, then Permissions.
  • Which tab. The Admin consent tab shows permissions that apply to your entire organization; the User consent tab shows permissions granted to a specific user or group.
  • What you can revoke there. An admin-consented permission can be revoked in the portal, with Revoke permission. A user-consented one can’t: Learn sends you to Microsoft Graph API calls or PowerShell cmdlets instead.
  • What revoking doesn’t do. Revoking “doesn’t stop users from re-consenting to the application’s requested permissions.”

How do you revoke Insulin’s access to Outlook?

Delete the Outlook integration in Fours, and revoke the permissions in Microsoft as well: the Fours docs warn that “Deleting the integration in Fours does not automatically revoke permissions granted in Microsoft.” Deleting the integration removes “all integration info including the credentials and access tokens” from Fours, immediately and permanently, and the docs add: “To fully disable access, the user must also revoke the application’s permissions.”

For the user-level connection that Inbox uses, the documented steps are:

  1. Go to Microsoft Account → Privacy
  2. Select Apps and services
  3. Locate the Fours application that was granted Outlook access
  4. Click Remove these permissions

For an organization-level connection, the instruction is: “To completely delete the integration, please revoke the application permissions or delete the app registration from Azure Active Directory as well.” Azure Active Directory is the name Microsoft has since changed to Microsoft Entra ID, which is where an admin reviews either kind of grant as described above.

What Inbox stored runs on its own clock. When the Outlook integration under Settings → Integrations is disconnected, Inbox doesn’t purge its data at once: Insulin starts a 7-day grace period, reconnecting inside it loses nothing, and after it the stored email records are hard-deleted. What Disable and Disconnect do to your mail covers that grace period and the mailbox controls inside Inbox.

Frequently asked questions

When does Microsoft turn off EWS?

Microsoft’s Learn page gives October 2026 as the month EWS starts to be disabled globally for all organizations, and April 2027 as the month it is fully disabled. The retirement covers Exchange Online, for Microsoft’s own applications as well as third-party ones.

Which Microsoft API does Insulin’s Outlook integration use?

Fours documents the AI tools on its Outlook integration as wrapping the Microsoft Graph Mail API directly. Insulin’s Inbox app reuses that integration’s connection instead of running its own sign-in, and each user connects it at the user level.

How do I find out which apps still use EWS?

Open the EWS usage report in the Microsoft 365 admin center: Reports, Usage, Exchange, then the EWS usage tab. It lists each application that called EWS by Application ID and SOAP action. Data is aggregated weekly and can take up to 10 days to appear.

What does a user grant when they connect Outlook?

The user clicks Accept on Microsoft’s OAuth 2.0 authentication page. The Fours docs say this authorization enables Fours to read and send emails on the user’s behalf. Admins see the grant in the Microsoft Entra admin center, on the application’s Permissions page.

Does deleting the Outlook integration in Fours revoke its Microsoft permissions?

No. The Fours docs say deleting the integration does not automatically revoke permissions granted in Microsoft. The user also removes them in their Microsoft account, under Privacy, then Apps and services; for an organization-level connection, an admin revokes the application permissions or deletes the app registration.

Who can review the permissions an app was granted?

Microsoft’s Learn page lists the Cloud Application Administrator and Application Administrator roles. Permissions granted for the whole organization are on the Admin consent tab and can be revoked there; permissions a user granted are on the User consent tab and need Microsoft Graph or PowerShell to revoke.

Takeaways

  • Microsoft’s schedule: EWS starts to be disabled globally in October 2026 and is fully disabled in April 2027, for Microsoft’s own applications as well as third-party ones.
  • Two documented facts answer the vendor question: Fours documents its Outlook AI tools as wrapping the Microsoft Graph Mail API, and Inbox reuses each user’s own Outlook connection rather than signing in separately.
  • The deciding check is in your tenant: the EWS usage report lists each application that called EWS, by Application ID. Read 90 days, and allow for weekly aggregation and up to 10 days of delay.
  • Access comes from a consent, and removing it takes two steps: delete the integration in Fours, and revoke the permissions in Microsoft.

With the audit row filled in, see what that Outlook connection does day to day on the Insulin Inbox app page: rules that draft replies in your voice and stage CRM actions for your review.

Sources

Primary sources for the platform rules cited above. Last verified October 8, 2026. Cloud providers change fees, eligibility, and program terms without notice — check the source before relying on a figure.

  • Deprecation of Exchange Web Services in Exchange Online — Microsoft Learn — The timeline as of the page's September 4, 2026 update: July 2018 deprecation announced, with no more functionality updates; 2023 disablement date set to 10/2026; the January 2024 Midnight Blizzard incident widening the scope from third-party applications to all Microsoft applications; 2025 usage reports and admin control to disable EWS at the organization and user levels; October 2026 EWS starts to be disabled globally for all organizations and April 2027 EWS fully disabled, both listed as upcoming. Also the direct mappings between EWS operations and Graph APIs, the call to investigate the EWS footprint of all internal and third-party applications and to work with vendors, and the pointer to the Exchange team blog for the disablement process
  • Exchange Web Services (EWS) usage report — Microsoft Learn — The path in the Microsoft 365 admin center (Reports, Usage, Exchange, the EWS usage tab); the 7, 30 and 90-day filters; usage collected and aggregated weekly and up to 10 days to appear; active apps as apps that sent at least one EWS request in the period; the Usage details columns, with Application ID as the Microsoft Entra identifier for the registered application, SOAP Action, Call Volume and Last Activity date (UTC); Export to a .csv file; checking Enterprise Applications in Microsoft Entra ID for an unfamiliar ID
  • Review permissions granted to enterprise applications — Microsoft Learn — Applies to applications added to a Microsoft Entra tenant via user or admin consent; the Cloud Application Administrator and Application Administrator roles; Entra ID > Enterprise apps > All applications, then Permissions, with the Admin consent and User consent tabs; Revoke permission on the Admin consent tab, while user-consented permissions cannot be revoked in the portal and need Microsoft Graph or PowerShell; revoking does not stop users from re-consenting
  • New name for Azure Active Directory — Microsoft Learn — Microsoft renamed Azure Active Directory (Azure AD) to Microsoft Entra ID
  • Integrations Microsoft Outlook — Fours Doc — The org level using an Azure AD app registration and the user level having each user authenticate via Microsoft OAuth; Connect Now redirecting to the Microsoft OAuth 2.0 authentication page, and Accept granting Fours permission to read and send emails on your behalf; the Fours AI Tools section wrapping the Microsoft Graph Mail API directly, and its tool list; deleting the integration deleting its credentials and access tokens from Fours immediately and permanently; the warning that deleting it does not automatically revoke permissions granted in Microsoft, the org-level instruction to revoke the application permissions or delete the app registration from Azure Active Directory, and the four user-level revocation steps
  • Insulin Inbox — Fours Doc — Inbox not running its own OAuth flow and reusing the connection set up under Integrations; Enable Inbox for Outlook health-checking access, registering the mailbox webhook and starting the writing style; the mailbox among the rule checks that are user-level integrations, which a connection at the organization level does not satisfy; disconnecting the underlying integration starting a 7-day grace period before the stored email records are hard-deleted

Browse every post on the Insulin Blog

Stay Updated

New posts, product updates and marketplace strategy are shared on LinkedIn as they publish.

Follow Fours on LinkedIn