Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Elastic simplifies log analytics for SREs and developers with launch of Log Essentials

      August 7, 2025

      OpenAI launches GPT-5

      August 7, 2025

      Melissa brings its data quality solutions to Azure with new SSIS integration

      August 7, 2025

      Automating Design Systems: Tips And Resources For Getting Started

      August 6, 2025

      This $180 mini projector has no business being this good for the price

      August 7, 2025

      GPT-5 is finally here, and you can access it for free today – no subscription needed

      August 7, 2025

      Changing this Android setting instantly doubled my phone speed (Samsung and Google models included)

      August 7, 2025

      ChatGPT can now talk nerdy to you – plus more personalities and other upgrades beyond GPT-5

      August 7, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Advanced Application Architecture through Laravel’s Service Container Management

      August 7, 2025
      Recent

      Advanced Application Architecture through Laravel’s Service Container Management

      August 7, 2025

      Switch Between Personas in Laravel With the MultiPersona Package

      August 7, 2025

      AI-Driven Smart Tagging and Metadata in AEM Assets

      August 7, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Bill Gates on AI’s Impact: ‘Be Curious, Read, and Use the Latest Tools’

      August 7, 2025
      Recent

      Bill Gates on AI’s Impact: ‘Be Curious, Read, and Use the Latest Tools’

      August 7, 2025

      Halo Infinite’s Fall Update: New Features and Modes to Revive the Game?

      August 7, 2025

      Forza Motorsport’s Future in Jeopardy: Fans Demand Clarity from Microsoft

      August 7, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Microsoft to Pull Plug on Shared EWS Access in Hybrid Exchange by October

    Microsoft to Pull Plug on Shared EWS Access in Hybrid Exchange by October

    August 7, 2025

    Exchange Web Services

    Organizations using Exchange hybrid deployments should prepare for new changes taking effect over the next few months. Microsoft has announced that beginning in August 2025, it will temporarily block Exchange Web Services (EWS) traffic that uses the Exchange Online shared service principal in certain hybrid environments.  

    The change primarily impacts organizations using “rich coexistence” features such as free/busy calendar lookups, MailTips, and profile picture sharing between on-premises Exchange Server and Exchange Online mailboxes. These features rely on EWS and have traditionally functioned through the shared service principal in Exchange Online. 

    However, Microsoft will permanently disable this method starting October 31, 2025. In preparation, temporary disruptions will occur throughout August, September, and October 2025 to prompt customers to make the necessary updates. These blocks are designed to ensure that affected organizations don’t overlook the October deadline. 

    The company stresses the security benefits of this shift. Moving away from the shared service principal reduces exposure to known risks, including CVE-2025-53786, a post-exploitation vulnerability that highlights the need for stronger authentication controls. 

    Who Will Be Affected by Exchange Web Services (EWS) Discontinuation? 

    Not all hybrid Exchange environments will be impacted by these disruptions. Only organizations meeting the following criteria will experience feature breaks during the temporary blocks: 

    • Mailboxes are hosted both in Exchange on-premises and Exchange Online. 
    • Rich coexistence features (free/busy, MailTips, profile pictures) are in use between on-prem and cloud users. 
    • On-premises Exchange servers are not updated to a version that supports the dedicated hybrid app. 
    • The dedicated Exchange hybrid app has not been created or properly enabled. 

    Organizations meeting these conditions should act immediately to avoid functionality loss. Microsoft has also issued Message Center notification MC1085578 to affected tenants.

    What Will Break and When? 

    The impact is limited but specific. During blocked periods, on-premises mailboxes will be unable to access rich coexistence features for Exchange Online mailboxes. These include: 

    • Free/busy calendar lookups 
    • MailTips 
    • Profile picture sharing 

    It’s important to note that these disruptions are one-way only, they affect on-premises users accessing cloud data, not vice versa. All other hybrid features will continue to work. 

    Support teams will not grant exceptions for these blocks. Organizations needing assistance should consult the documentation or reach out to Microsoft support. 

    What Organizations Need to Do 

    For organizations using rich coexistence features, Microsoft recommends two primary actions: 

    • Update Exchange Server to a version that supports the dedicated hybrid app. 
    • Create and enable the dedicated Exchange hybrid application using the new Hybrid Configuration Wizard (HCW) or a provided configuration script. 

    Supported minimum Exchange versions include: 

    • Exchange Server 2016 CU23 – Version 15.1.2507.55 or newer (April 2025 HU) 
    • Exchange Server 2019 CU14 – Version 15.2.1544.25 or newer (April 2025 HU) 
    • Exchange Server 2019 CU15 – Version 15.2.1748.24 or newer 
    • Exchange Subscription Edition (SE) – Version 15.2.2562.17 or newer 

    The updated Hybrid Configuration Wizard simplifies the setup of the dedicated app. When selected during the HCW process (Classic Full, Modern Full, or Choose Exchange Hybrid Configuration), the wizard: 

    • Registers a new application in Entra ID with a unique identifier. 
    • Adds EWS permissions (to be replaced with Microsoft Graph permissions in the future). 
    • Uploads current and future authentication certificates. 
    • Removes expired certificates. 
    • Requests tenant-wide admin consent. 

    However, HCW does not automatically enable the dedicated app within the on-premises Exchange environment. A separate Setting Override must be created to fully activate the feature. Instructions are available in the Deploy dedicated Exchange hybrid app documentation. 

    Conclusion 

    Even for organizations not using rich coexistence features, it’s important to perform a security cleanup. Running the Exchange Hybrid Configuration Wizard or configuring OAuth may have left custom certificates on the shared service principal, which should be removed using the provided script in Service Principal Clean-Up Mode. This process can be carried out from any Windows machine and does not require a specific Exchange version or server.  

    As Microsoft moves toward permanently blocking Exchange Web Services (EWS) traffic via the shared service principal after October 31, 2025, transitioning to the dedicated Exchange hybrid app is a critical step in securing hybrid Exchange deployments. Administrators should act now to ensure their environments are fully updated and aligned with the latest guidance, using the updated Hybrid Configuration Wizard and official documentation to avoid any disruption. 

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleGoogle Confirms Salesforce Database Breach by ShinyHunters Group
    Next Article FOSS Weekly #25.32: AWS Fiasco, AUR Poisoned Again, Ubuntu Manual, Firefox New Tab Customization and More Linux Stuff

    Related Posts

    Development

    Advanced Application Architecture through Laravel’s Service Container Management

    August 7, 2025
    Development

    Switch Between Personas in Laravel With the MultiPersona Package

    August 7, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-6390 – Brocade SANnav Password Storage Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Xiaomi introduced MiMo-7B: A Compact Language Model that Outperforms Larger Models in Mathematical and Code Reasoning through Rigorous Pre-Training and Reinforcement Learning

    Machine Learning

    CVE-2025-46688 – QuickJS Buffer Overflow Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Less UFO, more Wall-E: You’ve never seen the best robot vacuum on the market

    News & Updates

    Highlights

    Standard – JavaScript style guide, linter, and formatter

    July 28, 2025

    standard is designed to save you time by avoiding bikeshedding about code style. It’s a…

    Microsoft revolutionizes Edge as an AI-powered web browser with new experimental ‘Copilot Mode’ — here’s how to enable it right now

    July 28, 2025

    Le notizie minori del mondo GNU/Linux e dintorni della settimana nr 30/2025

    July 27, 2025

    Mozilla interrompe lo sviluppo di DeepSpeech

    June 26, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.