Action Required: Existing EWS‑Quarantined Items
Following the announcement about the Collaboration Protection Exchange protection transition to Microsoft Graph API, action may be required by administrators.
https://community.withsecure.com/announcements-en/kb/articles/32991-collaboration-protection-transitioning-exchange-protection-to-microsoft-graph-api
What's changing
Items previously quarantined via EWS — particularly Calendar events, Contacts, Tasks, Notes and Sticky notes — will no longer be accessible via the Graph API once the migration is complete. Due to this limitation, action is needed for items that were previously quarantined via EWS.
What you need to do
Administrators must verify if they would like to release or delete any of the existing EWS-quarantined items, which will no longer be accessible via Graph API, no later than August 31, 2026. Any items left unreleased by this date will be automatically deleted by ECP on September 15, 2026.
How to identify affected items
Items requiring action can be identified in the Collaboration Protection portal, on the Quarantine page, in two ways:
- Check the item type via detection details - Select "View detection" on the quarantined item and verify whether the Item type is one of: Appointment, Contact, Contact group, Post item, or Task.
- Use the new Item type filter - Apply the filter: Exchange → Item type: Calendar event, Contact, or Other.
Either method will help you identify items that require verification and possible action before the deadlines above.