M365 Backup: Approving Microsoft Graph permissions (EWS is being retired)
Microsoft is retiring Exchange Web Services (EWS) in Exchange Online. To ensure M365 Backup can continue to back up and restore your mailboxes, a Global Administrator of your Microsoft 365 tenant must approve the updated permissions for the Microsoft Graph API once. Without this approval, mailbox backups will fail as soon as Microsoft blocks EWS access.
Affected services
- M365 Backup (Netstream Security Service, Microsoft 365 Seats)
- Backup and recovery of Exchange Online mailboxes, including shared mailboxes and room mailboxes
Symptom
A warning with the following content appears in the backup console:
Microsoft EWS API is being deprecated. To continue backing up and recovering Microsoft 365 mailboxes, an administrator must approve the permissions required by the Microsoft Graph API for Exchange Online.
The banner contains the Review and approve permissions button and lists the affected Microsoft 365 workloads. The warning initially appears with the level Warning.
As soon as Microsoft actually blocks EWS access and backups fail, it is upgraded to Critical.
Cause
M365 Backup accesses Exchange Online via an app registration in your Microsoft 365 tenant. During the original setup, an administrator granted the permissions required at the time, which were based on EWS.
Microsoft is replacing EWS with the Microsoft Graph API. The application therefore needs new permissions. Only a Global Administrator of your tenant can grant this approval. Netstream cannot do this on your behalf.
Procedure
Prerequisite: administrator access to the backup console and a Microsoft 365 Global Administrator account for your tenant.
- Log in to the backup console as an administrator.
- Navigate to Devices > Microsoft 365.
- Click Review and approve permissions.
- Log in with a Microsoft 365 Global Administrator account of your organisation.
- Review the requested Microsoft Graph permissions and confirm them.
.jpeg?width=551&height=880&name=rtaImage%20(1).jpeg)
Once the approval has been granted successfully, the warning disappears and mailbox backups continue via the Microsoft Graph API.
If you have several Microsoft 365 organisations, carry out the steps separately for each affected organisation.
If Review and approve permissions does not appear, the required permissions have already been granted for this tenant. No further action is required.