The following frequently asked questions provide information about transitioning Exchange Online protection from EWS to Microsoft Graph.
Do I Have to Enable Microsoft Graph Myself?
Yes, whether you are a Commvault Cloud (SaaS) customer or a Commvault Software (Self-hosted) customer. The toggle is off by default. You must add the Microsoft Graph permissions, assign the Exchange role, authorize your apps, and enable the Graph toggle.
Which Permissions Do I Need?
Check the permission list in this documentation to ensure new Graph permissions are assigned and authorized.
Can I Remove the EWS Permissions After Moving to Graph?
Remove EWS access only after confirming that every protected workload and operation has moved to a supported Graph configuration. Retain the documented EWS access while any workload still depends on EWS.
Do I Have to Reauthorize My Applications?
Reauthorization is required when an application lacks required permissions, required consent, or an authorized status. Validate every application associated with the Exchange Online configuration.
Is Setting EwsEnabled to True Enough?
No. If temporary EWS access is required, follow the current Microsoft and Commvault guidance for both the organization setting and approved application IDs. Microsoft documents application-ID controls that limit access to listed applications.
What Happens if I Take No Action?
If your Exchange Online protection still depends on EWS when Microsoft disables it, affected backup operations may stop. The effect depends on your workload types, release, permissions, authorization status, and Graph-transition state.
Does This Affect On-Premises Exchange Server?
Microsoft's announced retirement applies to EWS in Exchange Online.