Exchange Web Services (EWS) Deprecation and Barracuda Cloud-to-Cloud Backup

Exchange Web Services (EWS) Deprecation and Barracuda Cloud-to-Cloud Backup

This migration ensures continued compatibility and security for your backups ahead of Microsoft's planned retirement of EWS on October 1, 2026.

What This Means for You

Barracuda Cloud-to-Cloud Backup is migrating from Exchange Web Services (EWS) to the Microsoft Graph API in stages ahead of Microsoft's October 1, 2026 EWS retirement deadline.

When you reauthorize your connection, the application receives the updated permissions required for the Microsoft Graph API. The backend migration from EWS to the Microsoft Graph API occurs gradually, so you may still see EWS in use after reauthorizing. This is expected. Barracuda will complete the migration before the October 1, 2026 deadline.

Existing customers should reauthorize their connection now to ensure that the required Microsoft Graph API permissions are in place.

Important: If your organization uses Frontline or Kiosk licenses (F1, F3, or Exchange Online Kiosk), set the tenant-level EWSEnabled setting to True to allow EWS-based backups through October 1, 2026. The default null value does not allow access to these mailboxes. EWS cannot be enabled individually for Frontline or Kiosk mailboxes.

Note: The following limitations currently apply to the Microsoft Graph API. These are due to Microsoft’s current API capabilities and may change in the future:

  • Recoverable items are not supported

  • Archive mailboxes are not supported

  • Group/Team mailboxes are not supported

How to Reauthorize Your Connection

To ensure you have the updated Microsoft Graph API permissions, reauthorize your connection. For steps, see How to Reauthorize a Connection.

Once complete, your connection will have the updated permissions. Barracuda Cloud-to-Cloud Backup will migrate backup activity from EWS to the Microsoft Graph API in stages. For more information, see How to Connect to Your Microsoft Tenant.

Backup Job Warning for Frontline and Kiosk Licenses

If your organization uses Frontline or Kiosk licenses (F1, F3, or Exchange Online Kiosk), you may see a warning in your backup job reports while these mailboxes are backed up through EWS.

To allow EWS-based backups for these mailboxes, set the tenant-level EWSEnabled setting to True. The default null value does not allow access to Frontline and Kiosk mailboxes. Because EWS cannot be enabled individually for these license types, the tenant-level setting is required.

To check the current tenant-level setting, run the following command in Exchange Online PowerShell:

Get-OrganizationConfig | Format-List EWSEnabled

If EWSEnabled is blank or set to null, set the tenant-level value to True:

Set-OrganizationConfig -EWSEnabled $true

Reauthorize your connection separately to grant the updated Microsoft Graph API permissions required for the EWS-to-Graph migration. Reauthorization does not replace the tenant-level EWS requirement, and the warning may continue to appear while these mailboxes are backed up through EWS.

Frequently Asked Questions

  • When exactly is Microsoft retiring EWS?
    Microsoft is retiring EWS beginning October 1, 2026. We recommend reauthorizing your connection as soon as possible.

  • Will Cloud-to-Cloud Backup stop working after EWS is retired?
    No. Cloud-to-Cloud Backup is migrating to the Microsoft Graph API to maintain service continuity after EWS is retired. Existing customers must reauthorize their connection to grant the updated Microsoft Graph API permissions.

  • Do I need to do anything now?
    Existing customers should reauthorize their connection to grant the updated Microsoft Graph API permissions. New customers authenticating for the first time will automatically receive the necessary permissions during setup.

  • I reauthorized my connection but still see EWS in use. Is something wrong?
    No. Reauthorizing grants the required Graph API permissions, but Barracuda is completing the backend migration in stages before October 1, 2026.

  • Are there any limitations with the Microsoft Graph API migration?
    Yes. Graph API currently does not support recoverable items, archive mailboxes, or Group/Team mailboxes. See the What This Means for You section above for details.

 


We value your feedback.
If you have questions, suggestions, or feedback on our documentation, contact the Campus Product Documentation team.
For general product inquiries or technical support, please contact the global Barracuda Support team.