The Vantage View | Salesforce

Salesforce and the EWS Retirement: October 2026 Cutoff Guide

Written by David Cockrum | Sep 1, 2026, 12:00:03 PM

Quick answer: Microsoft will start blocking Exchange Web Services (EWS) requests to Exchange Online on October 1, 2026, with full retirement by April 1, 2027, per Microsoft's Exchange Team announcement. Salesforce features that historically connected to Exchange through EWS — including Einstein Activity Capture, Salesforce Inbox, and Lightning Sync — must move to Microsoft Graph before the block takes effect, or email and calendar sync will stop working. The fix is a known, documented upgrade path, but it requires coordination between your Salesforce admin and your Microsoft 365 admin, so the time to start is now, not September.

What exactly is Microsoft retiring, and when?

Exchange Web Services is the legacy API that third-party applications — including CRM email integrations — have used for years to read mailboxes, sync calendars, and send email through Exchange. Microsoft has been steering developers toward its modern replacement, Microsoft Graph, and the transition now has hard dates.

Per Microsoft's Exchange Team announcement and Microsoft Learn documentation, the timeline is:

  • October 1, 2026: Microsoft begins blocking EWS requests to Exchange Online, using a phased disablement process for tenants still making EWS calls.
  • April 1, 2027: Full retirement — EWS in Exchange Online is shut down entirely.

Two clarifications matter for planning. First, this applies to Exchange Online (Microsoft 365) — Microsoft has stated that on-premises Exchange Server is not affected by this retirement. Second, the October date is when blocking begins, not a soft deadline. Once your tenant is blocked, any integration still calling EWS simply stops functioning.

Which Salesforce integrations are affected?

Salesforce's help documentation identifies three features that have used EWS-based connections to Microsoft Exchange and directs customers to upgrade their authentication to Microsoft Graph:

  • Einstein Activity Capture (EAC) — the automatic capture of emails and calendar events onto Salesforce records. If your EAC connection to Microsoft 365 still runs on EWS, capture and sync will fail once EWS is blocked.
  • Salesforce Inbox — the productivity layer that depends on the same Microsoft 365 connection.
  • Lightning Sync — the older contact and calendar sync product, which Salesforce has been retiring in favor of Einstein Activity Capture. The EWS shutdown effectively ends any remaining Lightning Sync usage against Exchange Online. If you are still on Lightning Sync, see our complete Lightning Sync retirement migration guide.

Because Salesforce adjusts its guidance as the deadline approaches, treat this list as a starting point and confirm your org's exposure against Salesforce's current documentation — specifically the help articles on upgrading the Microsoft 365 authentication method to Microsoft Graph. Newer EAC connections may already authenticate through Graph; older ones typically do not.

How do you know if your org is exposed?

You cannot fix what you have not inventoried. A quick exposure check looks like this:

  1. Check your EAC connection type. In Setup, review your Einstein Activity Capture configuration and note whether the Microsoft 365 connection uses EWS or Microsoft Graph. Salesforce surfaces an upgrade path for EWS-based connections.
  2. Identify Lightning Sync usage. Any active Lightning Sync configuration against Exchange Online needs a full migration to Einstein Activity Capture, not just an authentication change. Recent Salesforce configuration changes also affect how EAC is set up — our guide to the May 2026 Einstein Activity Capture configuration changes covers what admins need to know.
  3. Ask Microsoft 365 admins to review EWS traffic. Microsoft provides tenant-level reporting on which applications still make EWS calls. Salesforce may not be your only exposed integration — archiving tools, meeting-room systems, and telephony platforms often use EWS too.

What does the Microsoft Graph upgrade involve?

For Salesforce, the destination is a Microsoft Graph–based connection using modern OAuth authentication. The upgrade is well documented, but it is a cross-team effort:

  • Azure admin consent. Your Microsoft 365 administrator must grant consent for the Salesforce integration to use Microsoft Graph. This is frequently the longest step in regulated organizations, where app approvals go through security review.
  • Running the upgrade in Salesforce. Salesforce provides an in-product path to upgrade an existing EWS-based Einstein Activity Capture connection to Microsoft Graph from the EAC settings.
  • Reauthorization and testing. After the upgrade, verify that email capture, event sync, and send-from-Salesforce behavior work for a pilot group before declaring victory.

Here is how the two connection types compare:

Aspect EWS (legacy) Microsoft Graph (modern)
Status in Exchange Online Blocking begins October 1, 2026; retired April 1, 2027 (per Microsoft) Microsoft's supported, actively developed API
Authentication Legacy authentication patterns OAuth 2.0 with admin consent and conditional access support
Salesforce support Being phased out; upgrade prompts in Setup Required path for Einstein Activity Capture, Inbox, and related features
Admin effort None — until it breaks One-time coordinated upgrade, then business as usual

What should your migration plan look like?

A phased plan removes the drama. For most mid-market orgs this is weeks of elapsed time, not months — but the coordination points are real.

  1. Inventory (week 1). Document every Salesforce–Exchange touchpoint: EAC, Inbox, Lightning Sync, plus any third-party email or calendar tools connected to both systems.
  2. Align stakeholders (weeks 1–2). Bring Salesforce admins, Microsoft 365 admins, and security together. Agree on who owns Azure consent and when the change window is.
  3. Sandbox validation (weeks 2–3). Test the Graph upgrade in a sandbox where feasible, and confirm licensing prerequisites for each feature you use.
  4. Production upgrade (weeks 3–4). Run the upgrade, reauthorize users, and validate capture and sync with a pilot group before rolling to everyone.
  5. Monitor and close out (ongoing). Watch sync status dashboards for two to four weeks and confirm no residual EWS traffic remains from your Salesforce integration.

Why is waiting until October risky?

Three reasons. First, the failure mode is silent data loss: when EWS calls are blocked, activity capture just stops. Sellers keep working, but emails and meetings stop landing on records — and you cannot backfill relationship history you never captured.

Second, the bottleneck is not you. Azure admin consent, internal security reviews, and change-freeze calendars all sit outside the Salesforce team's control. Organizations that start in September are betting that every other team has capacity in the same crunch window as everyone else facing the deadline.

Third, this deadline is shared across your entire stack. Every vendor still on EWS is pushing customers through the same gate at once. Support queues — Microsoft's, Salesforce's, and every ISV's — will be at their worst in Q4 2026.

Frequently asked questions

Does the EWS retirement affect on-premises Exchange Server?

No. Per Microsoft's announcement, the retirement applies to Exchange Online (Microsoft 365) only. However, hybrid organizations should still review their setup, because mailboxes hosted in Exchange Online are affected regardless of how the rest of the environment is architected.

Will Salesforce automatically upgrade my connection to Microsoft Graph?

Do not assume so. Salesforce provides an upgrade path in Setup for EWS-based Einstein Activity Capture connections, but the upgrade requires Microsoft 365 admin consent on your side — something Salesforce cannot do for you. Verify your connection type and plan the upgrade deliberately, confirming steps against Salesforce's current help documentation.

We still use Lightning Sync. Is upgrading authentication enough?

No. Lightning Sync is being retired as a product, so the path forward is a migration to Einstein Activity Capture plus a Microsoft Graph connection. That is a bigger change than an authentication swap — it affects how activities are stored and reported — so budget more time for it.

What happens if we miss the October 1, 2026 date?

Once Microsoft blocks EWS for your tenant, any Salesforce feature still using an EWS connection stops syncing email and calendar data. Microsoft has described a phased disablement process, but planning around the possibility of a grace period is not a strategy — the safe assumption is that October 1 is your deadline.

Could other systems in our company also break?

Yes. EWS is used by many enterprise tools beyond CRM — archiving, compliance capture, room booking, and telephony integrations are common examples. Ask your Microsoft 365 team to pull EWS usage reporting for the tenant so the full list is known early.

How Vantage Point helps

Migrations like this sit at the seam between two platforms — exactly where things get dropped. Vantage Point's system integration and data migration team runs EWS-to-Graph transitions end to end: exposure audit, Microsoft 365 coordination, sandbox validation, production cutover, and post-migration monitoring, including Lightning Sync to Einstein Activity Capture moves. Senior consultants only — no junior handoffs; the experts you meet are the experts who deliver. If your email integration is still on EWS, a short assessment now is far cheaper than a silent sync outage in October.