Microsoft is retiring Exchange Web Services (EWS) for Exchange Online as part of its ongoing platform modernization. To stay aligned with Microsoft’s recommended architecture, WithSecure Collaboration Protection is transitioning Exchange protection from EWS to Microsoft Graph API.
This transition ensures that Collaboration Protection continues to provide reliable protection for Microsoft 365 environments while adopting Microsoft’s modern, supported platform.
For more information about Microsoft’s announcement, please refer to Microsoft’s official documentation:
Deprecation of Exchange Web Services in Exchange Online | Microsoft Learn
What is changing?
Following the transition, Collaboration Protection will use Microsoft Graph API for Exchange Online alongside the existing Microsoft Graph API integrations used for Microsoft Teams, OneDrive, and SharePoint.
Email protection—the primary security workload—will continue without interruption. Customers will continue to benefit from the same email scanning and detection capabilities throughout and after the transition.
The main change concerns a small number of Exchange item types. Microsoft Graph API does not provide equivalent capabilities for calendar events, contacts, tasks, notes, and sticky notes. As a result, Collaboration Protection will no longer scan these item types after the transition.
Historically, these content types have represented less than 1% of all detections generated by Collaboration Protection, meaning the practical security impact of this change is expected to be minimal.
What does this mean for customers?
For the vast majority of customers, there is no expected change to day-to-day protection. Email remains the primary attack vector targeted by Collaboration Protection and will continue to be fully protected throughout and after the transition.
The only change is that Collaboration Protection will no longer scan Exchange content types other than email, including calendar events, contacts, tasks, notes, and sticky notes. Based on our historical detection data, these content types have contributed to fewer than 1% of all detections, making the impact on overall protection very limited.
Why are we making this change?
This change is driven by Microsoft’s retirement of Exchange Web Services and the transition to Microsoft Graph API as the supported interface for Exchange Online.
By aligning with Microsoft’s modern platform, we ensure that Collaboration Protection remains reliable, supported, and ready for future Microsoft 365 enhancements while continuing to provide strong protection where it matters most.
Transition timeline
August 2026 – Transition begins
Customer environments will be transitioned to Microsoft Graph API–based Exchange protection in stages throughout August 2026.
Email protection will remain fully operational throughout the transition.
Microsoft Graph API requires updated permissions. Customers who need to grant the new permissions will see a notification banner in the Collaboration Protection Portal with step-by-step instructions.
September 2026 – EWS support ends
From 1 September 2026, Collaboration Protection will begin phasing out Exchange Web Services.
After the transition is complete, Collaboration Protection will no longer scan the following Exchange item types: Calendar events, Contacts, Tasks, Notes and Sticky notes. Email protection will continue as normal.
Action Required: Existing EWS‑Quarantined Items
Items previously quarantined via EWS — particularly Calendar events, Contacts, Tasks, Notes and Sticky notes — will no longer be accessible via the Graph API once the migration is complete. Due to this limitation, action is needed for items that were previously quarantined via EWS.
What you need to do
Administrators must verify if they would like to release or delete any of the existing EWS-quarantined items, which will no longer be accessible via Graph API, no later than August 31, 2026. Any items left unreleased by this date will be automatically deleted by ECP on September 15, 2026
How to identify affected items
Items requiring action can be identified in the Collaboration Protection portal, on the Quarantine page, in two ways:
- Check the item type via detection details - Select "View detection" on the quarantined item and verify whether the Item type is one of: Appointment, Contact, Contact group, Post item, or Task
- Use the new Item type filter (available from early August 2026) - Apply the filter: Exchange → Item type: Appointment, Contact, or Other.
Either method will help you identify items that require verification and possible action before the deadlines above.
Our commitment
This transition keeps Collaboration Protection aligned with Microsoft’s modern platform while ensuring uninterrupted protection for the workloads that matter most.
We will communicate with customers throughout the rollout and provide guidance where any action is required to complete the transition.
If you have any questions, please contact your WithSecure representative.