IBM Support

Deprecation of Exchange Web Services (EWS) for Exchange Online and Microsoft™ 365

General Page

Microsoft™ is retiring Exchange Web Services (EWS) for Exchange Online and Microsoft™ 365 from October 1, 2026. Microsoft™ will block all EWS requests to Exchange Online. IBM® MaaS360® Mail is moving the affected features to Microsoft™ Graph API to ensure continued service. On-premises Exchange accounts are not affected and continue to use EWS.

Links

Important: Microsoft™ Graph API is the recommended modern API to access the Exchange Online data.

Prerequisites

For iOS:

  1. IBM® MaaS360® app version 6.70.00 and later.
  2. From the IBM® MaaS360® Portal home page, the administrator must go to Setup > Settings > Mail Settings and select Enable backend notifications for Email and Calendar. Enter the Tenant ID of the Azure admin and click Consent.
    Note: You will be redirected to the Microsoft™ login page for a one-time login activity. Only Microsoft™ Entra (Azure) global admin can complete the consent and other admins are not allowed to perform this action. Similar to Entra integration workflow for directory sync.

    Note: For more information on the built-in roles that you can assign to allow management of Microsoft™ Entra resources, see Microsoft Entra built-in roles.

  3. For Primary accounts,

    From the IBM® MaaS360® Portal home page, the administrator must go to Security > Policies and select the WorkPlace Persona policy. Under Email > Configuration > Configure MaaS360 Mail, select Migrate to Microsoft Graph > Enable Cloud-Based Notifications

  4. For Additional accounts,

    From the IBM® MaaS360® Portal home page, the administrator must go to Security > Policies and select the WorkPlace Persona policy. Under Email > Advanced > Configure Additional MaaS360 Mail Accounts, select Migrate to Microsoft Graph > Enable Cloud-Based Notifications.

    Enable this policy to migrate the deprecated EWS API to Microsoft™ Graph API. After the policy is enabled, a prompt for user's consent appears when they start the app. It enforces to reconfigure the Shared/Delegated Accounts to migrate to Microsoft™ Graph. If an error occurs, then the user is redirected to manually reconfigure the account.

    Customers using Cloud Extender®

    The existing Cloud Extender® customers who were using the old EWS Based Email Notifications workflow and who will now use the new Graph-based Email Notifications workflow, must turn off the Email Notifications module in their Cloud Extender® config tool.

For Android:

  1. IBM® MaaS360® app version 9.45 and later.
  2. IBM® MaaS360® Mail version 9.45 and later.
  3. Android OS version 8.0 or later. This is required for Graph-migrated features (shared/delegated accounts, calendar attachments feature for primary and additional accounts, calendar availability feature for primary and additional accounts).
  4. For Primary accounts

    From the IBM® MaaS360® Portal home page, the administrator must go to Security > Policies and select the WorkPlace Persona policy. Under Email > Configuration > Configure MaaS360 Mail, select Migrate to Microsoft Graph

  5. For Additional accounts,

    From the IBM® MaaS360® Portal home page, the administrator must go to Security > Policies and select the WorkPlace Persona policy. Under Email > Advanced > Configure Additional MaaS360 Mail Accounts, select Migrate to Microsoft Graph.

    Enable this policy to migrate the deprecated EWS API to Microsoft™ Graph API. After the policy is enabled, a prompt for the user's consent appears when they start the app that enforces them to reconfigure the Shared/Delegated Accounts to migrate to Microsoft™ Graph. If an error occurs, then the user is redirected to manually reconfigure the account.

Authentication

For delegate accounts, the admin must also configure the required API permissions on the Microsoft™ Entra ID tenant. For more information, see Registering MaaS360 app in the Microsoft Entra ID tenant.

Important changes

The following changes have a direct impact on users and may require administrator communication or workflow updates prior to the upgrade.

  • Shared/Delegated Accounts reconfiguration

    Users will receive a prompt when they start the app. If reconfiguration fails, then users must manually re-add their Shared/Delegated accounts through the Manage Accounts screen. The administrators must document all current configurations of the Shared/Delegated mailboxes before the upgrade.

    • Offline behavior

      With EWS, actions such as email operations, contact edits, and calendar changes were saved locally first and synced to the server in the background, enabling them to function offline. With Microsoft™ Graph, all actions execute immediately and directly against Microsoft™ servers. If the device does not have an active network connection when an action is performed, the action fails and it will not be retried. Users must repeat the action after connectivity is restored.

    • Permission visibility

      With EWS, actions such as Delete, Flag/Unflag, and Move were hidden when the required permissions had not been granted. With Microsoft™ Graph, all actions are always visible regardless of permission level. The following actions in IBM® MaaS360® PIM on Microsoft™ Graph are now executed directly against Microsoft™ servers the moment an action is taken. If a user attempts an action without sufficient permissions, an error message is displayed. The users may see options they are not permitted to use. Also, there are no changes to the folder-level permissions in IBM® MaaS360® Mail and they continue to be the same.

  • Contact Groups are not supported with Microsoft™ Graph

    Microsoft™ Graph API does not currently support Contact Groups. Contact Groups will no longer be supported for any Microsoft™ 365 or Exchange Online account types, including Primary, Additional, and Shared/Delegated. This is a Microsoft™ platform limitation with no workaround and any workflows that rely on Contact Groups must be updated prior to the upgrade.

    Before the migration, the existing Contact Groups that were already synced for Primary or Additional accounts will remain visible to the user. After the migration to Microsoft Graph, the Contact Groups are not in sync for Primary or Additional accounts. Any existing groups will remain visible but no further synchronization or updates will happen. For Delegate accounts, after the account is migrated to Microsoft Graph, the Contact Groups are no longer supported.

What is being moved?

The following features are moving from EWS to Microsoft™ Graph API.

  • Shared/Delegated Accounts

    All operations for Shared/Delegated Accounts including email, calendar, and contacts synchronization are migrating to Microsoft™ Graph. Because these accounts rely entirely on EWS for all operations, the migration requires a complete account reconfiguration.

  • Primary and Additional Accounts

    The following features are moving for Primary and Additional Accounts on Microsoft 365 or Exchange Online.

    • Calendar attachments
    • Calendar availability lookups
    • Contact groups

Additional Limitations

  • Android OS requirement

    Microsoft™ Graph API requires timestamp APIs that are only available in Android OS version 8.0 (Oreo) and later. Devices running on Android OS version 7.x (Nougat) or earlier will not support Shared/Delegated accounts, Calendar attachments, or Calendar availability lookups after migration. Users with on-premises Exchange accounts are not affected. IBM® MaaS360® recommends upgrading all affected devices to Android version 8.0 or later prior to the upgrade.

  • Unsupported Contact Phone Number types

    When syncing contacts through Microsoft Graph, the following phone number types are not supported and will not be synced or displayed after the move. Work Fax, Company Main, Home Fax, Car, Radio, Pager, Assistant, MMS. These types no longer appear as options when adding or editing a contact on Graph-based accounts.

  • Policy Configuration updates

    Policy text and helper text will be updated following the migration to clarify which accounts use Microsoft™ Graph API versus EWS. The administrators must review the updated policy descriptions after the upgrade. No functional policy changes are required.

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSYSXX","label":"IBM MaaS360"},"ARM Category":[{"code":"a8m0z00000006zaAAA","label":"APPLICATIONS"},{"code":"a8m3p000000hCHSAA2","label":"EMAIL"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"and future releases"}]

Document Information

Modified date:
31 August 2026

UID

ibm17278372