Skip to content
TrustList
News

Exchange Online: apps using EWS must be on an allow list from 10 October 2026, and SharePoint’s one-time passcode retires from mid-October

Editorial

By TrustList Editorial

From 10 October 2026, Exchange Online apps using EWS must be listed in EWSAllowedAppIDs (MC1485116); Microsoft fills the list on 8-9 October from 60 days of use. SharePoint one-time passcodes retire from mid-October to end November (MC1243549).

  • Email Management
  • Regulatory Compliance
  • Collaboration Software
  • Identity Management Software
  • +1 more

About Exchange Online: apps using EWS must be on an allow list from 10 October 2026, and SharePoint’s one-time passcode retires from mid-October

Exchange Online: apps using EWS must be on an allow list from 10 October 2026, and SharePoint’s one-time passcode retires from mid-October

2 October 2026 — Two Microsoft 365 changes posted to the admin Message Center on 1 October 2026 have dates in the next few weeks. Both can cut off access that people and applications use today.

Not yet independently verified. This rests only on Microsoft’s own Message Center posts, read through a public archive because the admin centre requires sign-in. No independent report was found. We will update this when it can be confirmed, and remove this note.

Exchange Web Services: an allow list becomes mandatory (MC1485116)

Microsoft is already switching Exchange Web Services (EWS) off in Exchange Online, as our earlier item set out. This post adds the next enforcement step:

  • 2 October 2026: Microsoft identifies the tenants affected.
  • 8 to 9 October 2026: Microsoft fills in each affected tenant's EWSAllowedAppIDs list from the EWS activity it saw in the previous 60 days.
  • 10 October 2026: "EWSAllowedAPPIDs becomes required when EWSEnabled=True". An application that is not on the list can lose EWS access.
  • The rollout runs from early October 2026 to early July 2027 across the Worldwide, GCC, GCC High and DoD clouds.

An application that used EWS rarely, for example a quarterly export or a year-end archiving job, may not appear in 60 days of activity, and will then be missing from the list Microsoft builds.

What to do: review the EWS usage reports, build and validate your own allow list before 10 October, include the Microsoft first-party applications that appear in the data, and check it with Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs. Then keep moving those applications to Microsoft Graph.

SharePoint: one-time passcodes for external users retire (MC1243549)

Microsoft is replacing SharePoint Online's own one-time passcode (OTP) sign-in for external users with Microsoft Entra B2B guest accounts. The first phase, B2B for new external sharing, is complete. The update of 1 October says the second phase, the retirement of SharePoint OTP, starts in mid-October 2026 and should be finished by the end of November 2026.

From then, an external person without a matching B2B guest account who opens an older "specific people" link will see "access denied", until an administrator creates a guest account or someone inside the organisation shares the item again. GCC, GCC High and DoD are excluded for now.

What to do: list external sharing still relying on OTP, warn the partners, clients and auditors who use those links, decide whether to create guest accounts in bulk, and check your Entra B2B and guest-access policies before the phase starts.

Sources

Categories & features

  • Email Management
  • Regulatory Compliance
  • Collaboration Software
  • Identity Management Software
  • Redmond, Wa