Microsoft Tightens Exchange Online Security with New App Whitelist
Microsoft is tightening security on its Exchange Online platform by requiring applications to be explicitly listed in the EWSAllowedAppIDs configuration starting October 10, 2026.
This change affects all tenants worldwide, including GCC, GCC High, and DoD. Applications that are not included in this list may experience silent connection failures or service disruptions.
Microsoft will automatically populate the allow list for qualifying Worldwide tenants on October 8 and 9 by analyzing EWS activity from the previous 60 days.
However, applications that only occasionally connect to Exchange Online may not appear in the automatic list, requiring administrators to add them manually.