As we have shared throughout the last year, Microsoft is retiring Exchange Web Services (EWS) for Exchange Online in two phases, with the first milestone commencing October 1, 2026.
This thread captures key dates, transition paths, resources, and recommended configuration steps to take in your Commvault and Azure environments to help reduce the risk of interruption to supported Exchange Online protection.
As you review your environments and take steps to migrate to Graph, we know questions will arise. Put your questions here and our technical experts will review and respond regularly.
Note this transition impacts anyone backing up Exchange Online, inclusive of Commvault SaaS and on-prem software. It does not impact Exchange On-Prem users. Microsoft and Commvault feature support, dates, permissions, and transition behavior may evolve further.
Summary
This short video overview from our Readiverse Academy team summarizes key phases, dates, and critical steps to take in your environments.
Commvault supports Microsoft Graph for eligible Exchange Online workloads, but transition requirements vary by Commvault deployment, release, workload, and Azure tenant configuration.
If your environment relies on EWS when Microsoft disables it, affected Exchange Online backup operations may be disrupted until you enable the supported Microsoft Graph configuration or manually restore approved temporary EWS access.
Transitioning Eligible Workloads to Microsoft Graph (Recommended)
Commvault recommends most customers move to Graph at the earliest opportunity. Note that Microsoft has discontinued the ability to protect public folders with Graph API.
Microsoft Graph is Microsoft’s strategic API platform for Exchange Online, while EWS is a legacy protocol that no longer receives active investment and is being retired. Transitioning now reduces the risk of service interruption as EWS is disabled and places your environment on the supported path for future Microsoft 365 capabilities. Retain approved EWS access only as a temporary bridge for workloads or releases that are not yet supported through Graph.
Resources
- KB article with detailed instructions for enabling Graph usage and validating that relevant Azure apps have the appropriate permissions set to use the Graph API
- Click “subscribe” in the upper right to receive notifications of future updates
- Product documentation with release notes
Extending EWS Access on an Interim Basis
Many customers may require a phased approach: retain approved EWS access for workloads that still require it while transitioning eligible workloads to Graph.
Take steps to continue temporary EWS access if:
- You protect a workload that your Commvault release does not yet support through Microsoft Graph.
- You cannot assign and validate the required Graph permissions and Exchange roles before Microsoft disables EWS.
- Your organization needs additional time to test the Graph configuration.
Note: Temporary EWS access does not remove Microsoft’s retirement deadline. Complete the transition to Graph before EWS is permanently retired, slated for April 2027.
Resources:
- KB: Maintaining Exchange Web Services (EWS) access for Exchange Online before planned EOL
- Documentation
A Note About Public Folders
As part of the migration to Graph, Microsoft has confirmed that generic Public Folder access, including the APIs used to create, read, update, and delete Public Folder content — will not be available through Microsoft Graph. Microsoft plans to provide separate import/export capabilities for Public Folder data, but these do not replace the APIs currently used by backup and protection solutions to access and protect Public Folders.
As Microsoft begins disabling EWS globally in October 2026, with full disablement planned for April 2027, solutions that rely on EWS to protect Exchange Online Public Folders will no longer be able to provide the same functionality once EWS access is removed.
This is a limitation resulting from Microsoft’s platform transition rather than a change to Public Folders themselves. Public Folders will continue to exist within Exchange Online; however, Microsoft Graph will not provide the equivalent programmatic access required for their ongoing third-party protection.
Resources
- KB: Public Folder support in Exchange Online, and moving to the Graph API
- Microsoft Article: Deprecation of Exchange Web Services in Exchange Online
Disclaimer
These resources explain the key dates, available transition paths, and configuration considerations designed to help reduce the risk of interruption to supported Exchange Online protection. Microsoft and Commvault capabilities, dates, permissions, and transition behavior may change. Before making changes, confirm the current requirements in the Commvault documentation for your deployment and release.
