General Page
Links
- Retirement of Exchange Web Services (EWS) in Exchange Online
- Microsoft™ blog - Exchange Online EWS, Your Time is Almost Up
Important: Microsoft™ Graph API is the recommended modern API to access the Exchange Online data.
Prerequisites
For iOS:
- IBM® MaaS360® app version 6.70.00 and later.
From the IBM® MaaS360® Portal home page, the administrator must go to Setup > Settings > Mail Settings and select Enable backend notifications for Email and Calendar. Enter the Tenant ID of the Azure admin and click Consent.
Note: You will be redirected to the Microsoft™ login page for a one-time login activity. Only Microsoft™ Entra (Azure) global admin can complete the consent and other admins are not allowed to perform this action. Similar to Entra integration workflow for directory sync.Note: For more information on the built-in roles that you can assign to allow management of Microsoft™ Entra resources, see Microsoft Entra built-in roles.
For Primary accounts,
From the IBM® MaaS360® Portal home page, the administrator must go to Security > Policies and select the WorkPlace Persona policy. Under Email > Configuration > Configure MaaS360 Mail, select Migrate to Microsoft Graph > Enable Cloud-Based Notifications.
For Additional accounts,
From the IBM® MaaS360® Portal home page, the administrator must go to Security > Policies and select the WorkPlace Persona policy. Under Email > Advanced > Configure Additional MaaS360 Mail Accounts, select Migrate to Microsoft Graph > Enable Cloud-Based Notifications.
Enable this policy to migrate the deprecated EWS API to Microsoft™ Graph API. After the policy is enabled, a prompt for user's consent appears when they start the app. It enforces to reconfigure the Shared/Delegated Accounts to migrate to Microsoft™ Graph. If an error occurs, then the user is redirected to manually reconfigure the account.
Customers using Cloud Extender®
The existing Cloud Extender® customers who were using the old EWS Based Email Notifications workflow and who will now use the new Graph-based Email Notifications workflow, must turn off the Email Notifications module in their Cloud Extender® config tool.
For Android:
- IBM® MaaS360® app version 9.45 and later.
- IBM® MaaS360® Mail version 9.45 and later.
- Android OS version 8.0 or later. This is required for Graph-migrated features (shared/delegated accounts, calendar attachments feature for primary and additional accounts, calendar availability feature for primary and additional accounts).
For Primary accounts,
From the IBM® MaaS360® Portal home page, the administrator must go to Security > Policies and select the WorkPlace Persona policy. Under Email > Configuration > Configure MaaS360 Mail, select Migrate to Microsoft Graph.
For Additional accounts,
From the IBM® MaaS360® Portal home page, the administrator must go to Security > Policies and select the WorkPlace Persona policy. Under Email > Advanced > Configure Additional MaaS360 Mail Accounts, select Migrate to Microsoft Graph.
Enable this policy to migrate the deprecated EWS API to Microsoft™ Graph API. After the policy is enabled, a prompt for the user's consent appears when they start the app that enforces them to reconfigure the Shared/Delegated Accounts to migrate to Microsoft™ Graph. If an error occurs, then the user is redirected to manually reconfigure the account.
Authentication
For delegate accounts, the admin must also configure the required API permissions on the Microsoft™ Entra ID tenant. For more information, see Registering MaaS360 app in the Microsoft Entra ID tenant.
Important changes
The following changes have a direct impact on users and may require administrator communication or workflow updates prior to the upgrade.
Shared/Delegated Accounts reconfiguration
Users will receive a prompt when they start the app. If reconfiguration fails, then users must manually re-add their Shared/Delegated accounts through the Manage Accounts screen. The administrators must document all current configurations of the Shared/Delegated mailboxes before the upgrade.
Offline behavior
With EWS, actions such as email operations, contact edits, and calendar changes were saved locally first and synced to the server in the background, enabling them to function offline. With Microsoft™ Graph, all actions execute immediately and directly against Microsoft™ servers. If the device does not have an active network connection when an action is performed, the action fails and it will not be retried. Users must repeat the action after connectivity is restored.
Permission visibility
With EWS, actions such as Delete, Flag/Unflag, and Move were hidden when the required permissions had not been granted. With Microsoft™ Graph, all actions are always visible regardless of permission level. The following actions in IBM® MaaS360® PIM on Microsoft™ Graph are now executed directly against Microsoft™ servers the moment an action is taken. If a user attempts an action without sufficient permissions, an error message is displayed. The users may see options they are not permitted to use. Also, there are no changes to the folder-level permissions in IBM® MaaS360® Mail and they continue to be the same.
Contact Groups are not supported with Microsoft™ Graph
Microsoft™ Graph API does not currently support Contact Groups. Contact Groups will no longer be supported for any Microsoft™ 365 or Exchange Online account types, including Primary, Additional, and Shared/Delegated. This is a Microsoft™ platform limitation with no workaround and any workflows that rely on Contact Groups must be updated prior to the upgrade.
Before the migration, the existing Contact Groups that were already synced for Primary or Additional accounts will remain visible to the user. After the migration to Microsoft™ Graph, the Contact Groups are not in sync for Primary or Additional accounts. Any existing groups will remain visible but no further synchronization or updates will happen. For Delegate accounts, after the account is migrated to Microsoft™ Graph, the Contact Groups are no longer supported.
What is being moved?
The following features are moving from EWS to Microsoft™ Graph API.
Shared/Delegated Accounts
All operations for Shared/Delegated Accounts including email, calendar, and contacts synchronization are migrating to Microsoft™ Graph. Because these accounts rely entirely on EWS for all operations, the migration requires a complete account reconfiguration.
Primary and Additional Accounts
The following features are moving for Primary and Additional Accounts on Microsoft™ 365 or Exchange Online.
- Calendar attachments
- Calendar availability lookups
- Contact groups
Additional Limitations
Android OS requirement
Microsoft™ Graph API requires timestamp APIs that are only available in Android OS version 8.0 (Oreo) and later. Devices running on Android OS version 7.x (Nougat) or earlier will not support Shared/Delegated accounts, Calendar attachments, or Calendar availability lookups after migration. Users with on-premises Exchange accounts are not affected. IBM® MaaS360® recommends upgrading all affected devices to Android version 8.0 or later prior to the upgrade.
Unsupported Contact Phone Number types
When syncing contacts through Microsoft™ Graph, the following phone number types are not supported and will not be synced or displayed after the move. Work Fax, Company Main, Home Fax, Car, Radio, Pager, Assistant, MMS. These types no longer appear as options when adding or editing a contact on Graph-based accounts.
Policy Configuration updates
Policy text and helper text will be updated following the migration to clarify which accounts use Microsoft™ Graph API versus EWS. The administrators must review the updated policy descriptions after the upgrade. No functional policy changes are required.
Was this topic helpful?
Document Information
Modified date:
31 August 2026
UID
ibm17278372