MC1477180

Microsoft Defender for Cloud Apps: Retirement of EWS detections in App Governance

What and why

As announced in 2023, Exchange Web Services (EWS) in Exchange Online is being retired. Phased disablement will begin on October 1, 2026. The Microsoft Defender for Cloud Apps app governance threat detections that rely on EWS activity signals will also be sunset, starting October 15, 2026.

If you have already migrated your applications from EWS, no action is required. For customers who have not yet migrated, we recommend you do so to maintain protection.

Rollout schedule

Global: We will begin rolling out on mid-October 2026 and expect to complete by late October 2026.

Impact on your organization

Organizations that plan to keep using EWS between October 15, 2026 and April 2027

Starting October 15, 2026, app governance will no longer generate alerts for suspicious app behavior observed through EWS activity, and the Defender for Cloud Apps detections you may have used to monitor and protect those integrations will no longer appear. To maintain protection, ensure your applications have migrated away from EWS.

For the full details on the EWS retirement please see the learn docs here.

Action required / Recommendations

Who is affected and what to do

Two groups of organizations should take note:

Organizations that do not use EWS: No action is required. Microsoft Defender for Cloud Apps already provides threat protection for Microsoft Graph activity, and app governance detections based on Microsoft Graph activity, app metadata, consent behavior, and credential changes continue to operate as they do today. More detail can be found in our Learn docs.

Organizations that plan to keep using EWS between October 15, 2026 and April 2027: Starting October 15, 2026, app governance will no longer generate alerts for suspicious app behavior observed through EWS activity, and the Defender for Cloud Apps detections you may have used to monitor and protect those integrations will no longer appear. To maintain protection, ensure your applications have migrated away from EWS. Microsoft Graph is the most common API to move to. It offers improved security, modern authentication, and broader capability support, and is where we continue to invest in new app governance threat detections. Review the EWS retirement guidance and timelines to ensure your organization is prepared for permanent retirement.

Learn more

  1. Exchange Online EWS, Your Time is Almost Up | Microsoft Community Hub
  2. Microsoft Defender for Cloud Apps app governance detections