Urgent.News

the world's headlines, one feed

Editions

Tech

Microsoft’s EWS shutdown should be treated as a warning, not a one-off

Organizations will be more exposed to Microsoft's EWS API phase-out than they realize.

Microsoft’s EWS shutdown should be treated as a warning, not a one-off

Microsoft will begin disabling its Exchange Web Services (EWS) API on 1st October, with a full shutdown planned for April 2027. This decision is driven by the fact that EWS, now 20 years old, no longer meets modern security, scalability, and reliability requirements. The API's involvement in 2024's Midnight Blizzard attack has further emphasized the urgency for its retirement.

The broader concern is that older, less visible APIs like EWS have become attractive targets for cybercriminals. In fact, recent research indicates that 99% of organizations encountered API security issues in the past year. While Microsoft's move towards more modern APIs like Microsoft Graph is a logical step, the process of migration is often more complex than simply switching one connection for another. Many organizations may find themselves in a precarious position due to a lack of visibility regarding EWS usage.

EWS is deeply embedded in the day-to-day operations of many organizations, particularly in larger and older ones. It is involved in booking meetings, syncing calendars, and allowing CRMs to log email activity automatically. This deep integration creates a challenge: many organizations may not fully understand where EWS is used, by whom, or for what purpose. Legacy workflows, third-party tools, and integrations built by former employees may all remain unaccounted for during the migration process.

This lack of visibility could make migration feel overwhelming, especially when EWS is so closely tied to everyday operations. The temptation may be to ignore the problem, relying on the adage "if it isn't broken, don't fix it." However, doing nothing is not a viable option as Microsoft phases out EWS and ends support. Critical applications may lose access to Exchange, and the security risks associated with legacy APIs will only become more pronounced.

Organizations that choose to merely intercept EWS calls and translate them into Microsoft Graph are only making a temporary fix. This approach still leaves the same security, visibility, and integration challenges in place, with additional complexity added as more dependencies are built around this workaround.

Instead of avoiding the migration, organizations should view Microsoft's EWS retirement as a warning about the consequences of allowing critical integrations to become invisible. Resilience is essential, and organizations should treat APIs as part of their digital supply chain and apply the same scrutiny as they would for third-party suppliers.

Continuous monitoring of APIs and staying informed about planned provider changes is crucial. A comprehensive API migration plan should cover API discovery, dependency mapping, ownership and management, testing, and ongoing monitoring.

Microsoft's decision to retire EWS is not an isolated incident but rather a reminder of the challenges that lie ahead as technology estates evolve. More legacy APIs will be retired in favor of newer versions that integrate more securely with modern solutions. The EWS retirement should serve as a warning to organizations about the importance of robust software lifecycle management. By preparing now, organizations can better manage the EWS migration and be more prepared for future changes.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

Read the original at techradar.com →

More in Tech

Terms and Policies

  • CNBC+ offers limited, non-exclusive license to access and use services.
  • Content quality varies based on format, location, internet bandwidth, device.
  • Commercial use prohibited; automatic ad blocking and recording restricted.