Skip to main content
StickyF.A.Q.

Migrating Exchange Online Protection from EWS to Microsoft Graph: Post Your Questions Here

  • September 19, 2026
  • 8 replies
  • 399 views
Jennifer Kelley
Vaulter
Forum|alt.badge.img+20

As we have shared throughout the last year, Microsoft is retiring Exchange Web Services (EWS) for Exchange Online in two phases, with the first milestone commencing October 1, 2026. 

This thread captures key dates, transition paths, resources, and recommended configuration steps to take in your Commvault and Azure environments to help reduce the risk of interruption to supported Exchange Online protection. 

As you review your environments and take steps to migrate to Graph, we know questions will arise. Put your questions here and our technical experts will review and respond regularly.

 

Note this transition impacts anyone backing up Exchange Online, inclusive of Commvault SaaS and on-prem software. It does not impact Exchange On-Prem users. Microsoft and Commvault feature support, dates, permissions, and transition behavior may evolve further.

 

Summary

This short video overview from our Readiverse Academy team summarizes key phases, dates, and critical steps to take in your environments.
 

 

Commvault supports Microsoft Graph for eligible Exchange Online workloads, but transition requirements vary by Commvault deployment, release, workload, and Azure tenant configuration.

If your environment relies on EWS when Microsoft disables it, affected Exchange Online backup operations may be disrupted until you enable the supported Microsoft Graph configuration or manually restore approved temporary EWS access.


Transitioning Eligible Workloads to Microsoft Graph (Recommended)

Commvault recommends most customers move to Graph at the earliest opportunity. Note that Microsoft has discontinued the ability to protect public folders with Graph API.


Microsoft Graph is Microsoft’s strategic API platform for Exchange Online, while EWS is a legacy protocol that no longer receives active investment and is being retired. Transitioning now reduces the risk of service interruption as EWS is disabled and places your environment on the supported path for future Microsoft 365 capabilities. Retain approved EWS access only as a temporary bridge for workloads or releases that are not yet supported through Graph.


Resources

 

Extending EWS Access on an Interim Basis

Many customers may require a phased approach: retain approved EWS access for workloads that still require it while transitioning eligible workloads to Graph.
 
Take steps to continue temporary EWS access if:  

  • You protect a workload that your Commvault release does not yet support through Microsoft Graph. 
  • You cannot assign and validate the required Graph permissions and Exchange roles before Microsoft disables EWS.  
  • Your organization needs additional time to test the Graph configuration.  

Note: Temporary EWS access does not remove Microsoft’s retirement deadline. Complete the transition to Graph before EWS is permanently retired, slated for April 2027.
 

Resources:

 

A Note About Public Folders

As part of the migration to Graph, Microsoft has confirmed that generic Public Folder access, including the APIs used to create, read, update, and delete Public Folder content — will not be available through Microsoft Graph. Microsoft plans to provide separate import/export capabilities for Public Folder data, but these do not replace the APIs currently used by backup and protection solutions to access and protect Public Folders.

As Microsoft begins disabling EWS globally in October 2026, with full disablement planned for April 2027, solutions that rely on EWS to protect Exchange Online Public Folders will no longer be able to provide the same functionality once EWS access is removed.

This is a limitation resulting from Microsoft’s platform transition rather than a change to Public Folders themselves. Public Folders will continue to exist within Exchange Online; however, Microsoft Graph will not provide the equivalent programmatic access required for their ongoing third-party protection.

 

Resources


Disclaimer

These resources explain the key dates, available transition paths, and configuration considerations designed to help reduce the risk of interruption to supported Exchange Online protection. Microsoft and Commvault capabilities, dates, permissions, and transition behavior may change. Before making changes, confirm the current requirements in the Commvault documentation for your deployment and release.

8 replies

Forum|alt.badge.img+4
  • Apprentice
  • September 23, 2026

Is conditional access policy and Microsoft Entra Workload ID Premium required? Specifically for a CommVault Core on-prem deployment with what looks like a single-tenant custom Azure App.

Appreciate any advice.


DGarra
Vaulter
Forum|alt.badge.img+3
  • Vaulter
  • September 23, 2026

Is conditional access policy and Microsoft Entra Workload ID Premium required? Specifically for a CommVault Core on-prem deployment with what looks like a single-tenant custom Azure App.

Appreciate any advice.

Adam, 

Conditional access policies are required (to meet Microsoft security best practices) of any and all use of Single Tenant Azure applications, regardless of API (graph vs EWS),

Commvault Cloud vs software, or Hybrid vs Entra/Azure ID. This is for all workloads in Office 365. 

Please see this KB: https://support.commvault.com/Article/Details/89658

 


Forum|alt.badge.img+5

The documentation describes the migration to Microsoft Graph only in Exchange Online. What are the recommendations/procedures for hybrid environments? 

 

Regards,

Michał


DGarra
Vaulter
Forum|alt.badge.img+3
  • Vaulter
  • October 1, 2026

The documentation describes the migration to Microsoft Graph only in Exchange Online. What are the recommendations/procedures for hybrid environments? 

 

Regards,

Michał

 

Michal, 

Please see: “What do I need to do as a Commvault (on-premises) customer” 

https://support.commvault.com/Article/Details/KA-201741


Forum|alt.badge.img+7
  • Apprentice
  • October 2, 2026

The documentation describes the migration to Microsoft Graph only in Exchange Online. What are the recommendations/procedures for hybrid environments? 

 

Regards,

Michał

 

Michal, 

Please see: “What do I need to do as a Commvault (on-premises) customer” 

https://support.commvault.com/Article/Details/KA-201741

Hi,

Does the planned version 11.44.30 or later introduce significant changes in functionality for managing the Exchange Online + Exchange On-prem (SE) hybrid configuration compared to, for example, version 11.36?

We would simply like to avoid a situation where, after an update, the Client loses some functionality—and I am not referring here to the backup method (EWS vs Graph API), but rather, for instance, the ability to operate from a single client interface.

Regards,

Lukas

=


DGarra
Vaulter
Forum|alt.badge.img+3
  • Vaulter
  • October 2, 2026

Lukasz, 

11.36 is the oldest still-supported version of CV, moving to 11.44 would represent 2-3 years of change at once, so yes, there is differences. 

Common points are administrators transitioning to leverage the CommandCenter vs the older deprecated Java console, and the full deprecation of the Web Console if you use the legacy Webconsole for self-servicing your end users. 

Additionally, if you’re still using the legacy compliance search via workarounds/hacks (it was killed off in FR28), these will no longer work once you’re past FR36. 

If you’re already using the CC, and not leveraging the WebConsole, there aren’t any major changes worth noting here. 

As these subjects aren’t really tied to the greater Graph vs EWS conversation, I would advise if you have concerns about these subjects to reach out to your CSM or ESP team for guidance. This thread is tied specifically the Graph transition. 

Hope this helps, 


Forum|alt.badge.img+7
  • Apprentice
  • October 2, 2026

Lukasz, 

11.36 is the oldest still-supported version of CV, moving to 11.44 would represent 2-3 years of change at once, so yes, there is differences. 

Two common points are administrators transitioning to leverage the CommandCenter vs the older deprecated Java console, and the full deprecation of the Web Console if you use the legacy Webconsole for self-servicing your end users. 

If you’re already using the CC, and not leveraging the WebConsole, there aren’t any major changes worth noting here. 

As these subjects aren’t really tied to the greater Graph vs EWS conversation, I would advise if you have concerns about these subjects to reach out to your CSM team for guidance. This thread is tied specifically the Graph transition. 

Hope this helps, 

Hi,
the question is: If the customer moves to Microsoft Graph, they will still be able to manage the hybrid environment as one client. 

 

Regards,

Lukasz


DGarra
Vaulter
Forum|alt.badge.img+3
  • Vaulter
  • October 2, 2026

Lukasz, 

 

Hybrid configuration with an on-premises CommCell is supported, and there’s no stipulations tied to a hybrid client, specific to the Graph-EWS conversation. You’re going to treat it no differently than any other non-hybrid client.