<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.grooper.com/index.php?action=history&amp;feed=atom&amp;title=Configuring_Exchange_Online_for_Grooper_Before_EWS_Retirement</id>
	<title>Configuring Exchange Online for Grooper Before EWS Retirement - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.grooper.com/index.php?action=history&amp;feed=atom&amp;title=Configuring_Exchange_Online_for_Grooper_Before_EWS_Retirement"/>
	<link rel="alternate" type="text/html" href="https://wiki.grooper.com/index.php?title=Configuring_Exchange_Online_for_Grooper_Before_EWS_Retirement&amp;action=history"/>
	<updated>2026-09-14T18:26:54Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.42.3</generator>
	<entry>
		<id>https://wiki.grooper.com/index.php?title=Configuring_Exchange_Online_for_Grooper_Before_EWS_Retirement&amp;diff=33322&amp;oldid=prev</id>
		<title>Dgreenwood at 19:46, 4 September 2026</title>
		<link rel="alternate" type="text/html" href="https://wiki.grooper.com/index.php?title=Configuring_Exchange_Online_for_Grooper_Before_EWS_Retirement&amp;diff=33322&amp;oldid=prev"/>
		<updated>2026-09-04T19:46:58Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 14:46, 4 September 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l19&quot;&gt;Line 19:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 19:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|}&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{{attn-box|The steps below only address the October 1, 2026 &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;blocking&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{{attn-box|The steps below only address the October 1, 2026 &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;blockage&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;   &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;EWS is being fully retired on April 1, 2027 with no exceptions of any kind. Your Grooper account representative can advise on the long-term migration path required before that date.}}&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;EWS is being fully retired on April 1, 2027 with no exceptions of any kind. Your Grooper account representative can advise on the long-term migration path required before that date.}}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Dgreenwood</name></author>
	</entry>
	<entry>
		<id>https://wiki.grooper.com/index.php?title=Configuring_Exchange_Online_for_Grooper_Before_EWS_Retirement&amp;diff=33321&amp;oldid=prev</id>
		<title>Dgreenwood at 19:46, 4 September 2026</title>
		<link rel="alternate" type="text/html" href="https://wiki.grooper.com/index.php?title=Configuring_Exchange_Online_for_Grooper_Before_EWS_Retirement&amp;diff=33321&amp;oldid=prev"/>
		<updated>2026-09-04T19:46:08Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://wiki.grooper.com/index.php?title=Configuring_Exchange_Online_for_Grooper_Before_EWS_Retirement&amp;amp;diff=33321&amp;amp;oldid=33320&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Dgreenwood</name></author>
	</entry>
	<entry>
		<id>https://wiki.grooper.com/index.php?title=Configuring_Exchange_Online_for_Grooper_Before_EWS_Retirement&amp;diff=33320&amp;oldid=prev</id>
		<title>Dgreenwood: Created page with &quot;Microsoft is retiring Exchange Web Services (EWS) in Exchange Online, the API that Grooper&#039;s Exchange CMIS Connection uses to import email.   This affects every Grooper version currently in use — the most recent release and older releases alike. If your organization uses Grooper&#039;s Exchange CMIS Connection to import email, action is required in your Microsoft 365 tenant to avoid an interruption.  == Key dates == {|class=&quot;wikitable&quot; |Date||What happens |- |Before Oct 1,...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.grooper.com/index.php?title=Configuring_Exchange_Online_for_Grooper_Before_EWS_Retirement&amp;diff=33320&amp;oldid=prev"/>
		<updated>2026-09-04T15:50:35Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;Microsoft is retiring Exchange Web Services (EWS) in Exchange Online, the API that Grooper&amp;#039;s Exchange CMIS Connection uses to import email.   This affects every Grooper version currently in use — the most recent release and older releases alike. If your organization uses Grooper&amp;#039;s Exchange CMIS Connection to import email, action is required in your Microsoft 365 tenant to avoid an interruption.  == Key dates == {|class=&amp;quot;wikitable&amp;quot; |Date||What happens |- |Before Oct 1,...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Microsoft is retiring Exchange Web Services (EWS) in Exchange Online, the API that Grooper&amp;#039;s Exchange CMIS Connection uses to import email. &lt;br /&gt;
&lt;br /&gt;
This affects every Grooper version currently in use — the most recent release and older releases alike. If your organization uses Grooper&amp;#039;s Exchange CMIS Connection to import email, action is required in your Microsoft 365 tenant to avoid an interruption.&lt;br /&gt;
&lt;br /&gt;
== Key dates ==&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|Date||What happens&lt;br /&gt;
|-&lt;br /&gt;
|Before Oct 1, 2026||Act immediately. Configuring now, before Microsoft&amp;#039;s rollout reaches your tenant, is expected to prevent an interruption — but the closer to October 1 you wait, the higher the risk. Also during September, Microsoft is automatically pre-populating allow lists for tenants that haven&amp;#039;t created one, based on observed usage.&lt;br /&gt;
|-&lt;br /&gt;
|Oct 1, 2026||Microsoft begins blocking EWS by default, tenant by tenant, for any Microsoft 365 tenant that has not opted in. Unconfigured tenants will have Exchange import stop working. EWS can be re-enabled afterward, but with a service interruption.&lt;br /&gt;
|-&lt;br /&gt;
|Apr 1, 2027||Microsoft permanently and fully shuts down EWS for every tenant. No allow list, exception, or configuration can restore it after this date.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{attn-box|The steps below only address the October 1, 2026 blocking.&lt;br /&gt;
 &lt;br /&gt;
EWS is being fully retired on April 1, 2027 with no exceptions of any kind. Your Grooper account representative can advise on the long-term migration path required before that date.}}&lt;br /&gt;
&lt;br /&gt;
==Before you begin==&lt;br /&gt;
You will need:&lt;br /&gt;
* A Microsoft 365 account with Exchange Online administrator rights (Global Administrator or Exchange Administrator role).&lt;br /&gt;
* The Exchange Online PowerShell module (&amp;quot;ExchangeOnlineManagement&amp;quot;) installed, or access to a machine where it can be installed.&lt;br /&gt;
* To know which authentication method your Grooper Exchange CMIS Connection uses — Exchange OAuth or OAuth Service Login. Your Grooper administrator or Grooper support contact can confirm this if you&amp;#039;re unsure.&lt;br /&gt;
* Access to the Microsoft 365 admin center to view your tenant&amp;#039;s EWS usage report (Step 3).&lt;br /&gt;
&lt;br /&gt;
== Step 1 – Connect to Exchange Online PowerShell==&lt;br /&gt;
&lt;br /&gt;
If the module isn&amp;#039;t already installed, install it once:&lt;br /&gt;
&amp;lt;pre&amp;gt;Install-Module -Name ExchangeOnlineManagement -Scope CurrentUser&amp;lt;/pre&amp;gt;&lt;br /&gt;
Then connect to your tenant (a browser window will open for sign-in):&lt;br /&gt;
&amp;lt;pre&amp;gt;Connect-ExchangeOnline -UserPrincipalName admin@yourdomain.com&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Step 2 – Check your current settings ==&lt;br /&gt;
&lt;br /&gt;
Before making changes, check the current value of &amp;lt;code&amp;gt;EWSEnabled&amp;lt;/code&amp;gt; and the existing allow list, if any:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Get-OrganizationConfig | Format-List EWSEnabled&lt;br /&gt;
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
What you should see: &lt;br /&gt;
* If &amp;lt;code&amp;gt;EWSEnabled&amp;lt;/code&amp;gt; shows blank or &amp;quot;null&amp;quot;, it has never been set. &lt;br /&gt;
* If &amp;lt;code&amp;gt;EwsAllowedAppIDs&amp;lt;/code&amp;gt; shows blank, no allow list exists yet.&lt;br /&gt;
{{fyi-box|An allow list may already exist even if no one in your organization created one.&lt;br /&gt;
&lt;br /&gt;
During September 2026, Microsoft is automatically pre-populating allow lists for tenants that haven&amp;#039;t made their own, based on observed usage in that tenant. &lt;br /&gt;
&lt;br /&gt;
If a list already exists, do NOT assume it is complete or correct — review it in Step 3, and confirm the Grooper App ID from Step 4 is on it.}}&lt;br /&gt;
==Step 3 – Review your EWS usage report==&lt;br /&gt;
{{attn-box|An allow list containing only the Grooper App ID could break other things your organization depends on.&lt;br /&gt;
&lt;br /&gt;
Once the allow list is populated and &amp;lt;code&amp;gt;EWSEnabled&amp;lt;/code&amp;gt; is True, every application NOT on the list is blocked from EWS — immediately after the change propagates, not just in October. That includes &amp;#039;&amp;#039;&amp;#039;any&amp;#039;&amp;#039;&amp;#039; application if they still use EWS in your tenant.}}&lt;br /&gt;
To see every application that has recently used EWS in your tenant:&lt;br /&gt;
* Sign in to the Microsoft 365 admin center (admin.microsoft.com).&lt;br /&gt;
* Go to Reports &amp;gt; Usage &amp;gt; Exchange &amp;gt; EWS Usage.&lt;br /&gt;
* Note the App ID of every application your organization intends to keep using. Your final allow list must include all of them, not just Grooper&amp;#039;s.&lt;br /&gt;
The report shows raw App ID values (GUIDs). To identify what an unfamiliar App ID belongs to, look it up in Microsoft Entra ID under Enterprise Applications, or check Microsoft&amp;#039;s published reference list of first-party application IDs.&lt;br /&gt;
== Step 4 – Identify Grooper&amp;#039;s App ID==&lt;br /&gt;
Add the App ID that matches the authentication method your Grooper Exchange CMIS Connection uses:&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|Authentication method||App ID to add&lt;br /&gt;
|-&lt;br /&gt;
|Exchange OAuth||e79cac6f-a984-41c3-bbe4-19b348c3da56  (fixed — same for every Grooper customer)&lt;br /&gt;
|-&lt;br /&gt;
|OAuth Service Login||The Application (Client) ID of the app registration your organization created in your own Microsoft Entra tenant. This value is different for every customer.&lt;br /&gt;
•	Found in the Azure Portal under &amp;quot;App registrations &amp;gt; [your app] &amp;gt; Overview&amp;quot;.&lt;br /&gt;
•	Found in Grooper in the CMIS Connection’s OAuth Service Login settings stored in the &amp;quot;Client Id&amp;quot; property&lt;br /&gt;
|}&lt;br /&gt;
==Step 5 – Set the complete allow list==&lt;br /&gt;
{{attn-box|&amp;lt;code&amp;gt;Set-OrganizationConfig -EwsAllowedAppIds&amp;lt;/code&amp;gt; has no &amp;quot;add&amp;quot; mode.&lt;br /&gt;
&lt;br /&gt;
Whatever value you give it becomes the entire list, discarding whatever was there before. If you run it with only one App ID, every other App ID previously on the list is gone.&lt;br /&gt;
&lt;br /&gt;
The script below exists specifically to avoid that. It reads the current list first, adds the ID to it, and only then writes the full command back in a single call.}}&lt;br /&gt;
&lt;br /&gt;
The safest pattern reads the current list first, merges in the new App ID, and writes the combined result back:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$current = (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy).EwsAllowedAppIDs&lt;br /&gt;
$updated = @($current -split &amp;quot;,&amp;quot; | ForEach-Object { $_.Trim() } | Where-Object { $_ }; &amp;quot;YOUR-APP-ID-HERE&amp;quot;) | Select-Object -Unique&lt;br /&gt;
Set-OrganizationConfig -EwsAllowedAppIDs ($updated -join &amp;quot;,&amp;quot;)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Replace &amp;quot;YOUR-APP-ID-HERE&amp;quot; with the Grooper App ID from Step 4. If Step 3 identified other App IDs that are not yet on the list, run the middle line once for each of them (or add them all before the final line).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;big&amp;gt;Alternative to populate the entire allow list&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you know the full list of App IDs you need to add to the allow list, you can add them as a comma separated list:&lt;br /&gt;
{{attn-box|The command below replaces the ENTIRE list every time it runs.&lt;br /&gt;
&lt;br /&gt;
It does not append to an existing list. If you use this command, be sure you have the ENTIRE set of allowed App IDs listed. &amp;#039;&amp;#039;&amp;#039;Only use this command if you are populating an empty allow list.&amp;#039;&amp;#039;&amp;#039;}}&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Set-OrganizationConfig -EwsAllowedAppIDs &amp;quot;ID1,ID2,ID3...&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Step 6 – Set EWSEnabled to True ==&lt;br /&gt;
Only after the list is complete, turn on &amp;lt;code&amp;gt;EWSEnabled&amp;lt;/code&amp;gt;. This activates the allow list and opts your tenant out of Microsoft&amp;#039;s automatic blocking:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Set-OrganizationConfig -EwsEnabled $true&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
{{fyi-box|Why finish the list first? Not because the list gets locked. You can add App IDs at any time by re-running the Step 5 command. &lt;br /&gt;
&lt;br /&gt;
The reason is timing. Once &amp;lt;code&amp;gt;EWSEnabled&amp;lt;/code&amp;gt; is True and the list is populated, any app missing from it is blocked, and additions to the list can take up to 24 hours to take effect. Completing the list before enabling avoids a temporary, self-inflicted outage for a forgotten app.}}&lt;br /&gt;
&lt;br /&gt;
== Step 7 – Verify ==&lt;br /&gt;
&lt;br /&gt;
Confirm both settings were applied as expected. EWSEnabled should show True, and EwsAllowedAppIDs should show every App ID you intended:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Get-OrganizationConfig | Format-List EWSEnabled&lt;br /&gt;
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
== Step 8 – Allow time to propagate, then test ==&lt;br /&gt;
* Changes to &amp;lt;code&amp;gt;EWSEnabled&amp;lt;/code&amp;gt; typically take effect within about &amp;#039;&amp;#039;&amp;#039;1 hour&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
* Changes to &amp;lt;code&amp;gt;EwsAllowedAppIDs&amp;lt;/code&amp;gt; can take up to &amp;#039;&amp;#039;&amp;#039;24 hours&amp;#039;&amp;#039;&amp;#039; to fully propagate, because Exchange Online servers refresh this list from a cache about once a day.&lt;br /&gt;
* After waiting, confirm Grooper&amp;#039;s Exchange import is working normally. If something that was working stops working immediately after the change, wait the full 24 hours before troubleshooting further. This is almost always the propagation delay, not a configuration error.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
* Forgot an App ID: re-run the Step 5 merge command with the missing ID — the list can be updated at any time. The blocked app may take up to 24 hours to start working again after the fix. &lt;br /&gt;
** If you need it working sooner: temporarily set EWSEnabled back to Null (Set-OrganizationConfig -EwsEnabled $null). The allow list is ignored while Null, and EWS becomes unrestricted within about an hour. Fix the list, then set EWSEnabled to True again promptly. &lt;br /&gt;
** Do not leave the tenant on Null: a Null tenant is subject to Microsoft&amp;#039;s automatic October 1 block, and this workaround stops being clean after that date.&lt;br /&gt;
* Wrong ID type: confirm the value entered is the Application (Client) ID — not the Object ID or Service Principal ID — from the Azure Portal app registration.&lt;br /&gt;
* List got overwritten: because Set-OrganizationConfig replaces the whole list, re-run the Step 7 verification and confirm every expected App ID is still present. A missing entry means a later command overwrote it.&lt;br /&gt;
* Missing consent (OAuth Service Login only): confirm the app registration has the required Exchange/EWS permission and that it has received tenant-wide admin consent.&lt;br /&gt;
* Mailbox-level block: EWS can also be disabled on an individual mailbox. Check the specific mailbox Grooper connects to with: Get-CASMailbox -Identity mailbox@yourdomain.com | Format-List EwsEnabled — it must not be False.&lt;br /&gt;
* Application Access Policy: a separate policy (New-ApplicationAccessPolicy) can restrict which mailboxes an app may touch, independent of the allow list. Run Test-ApplicationAccessPolicy against the app&amp;#039;s ID and the target mailbox to check.&lt;br /&gt;
* Frontline licenses: mailboxes on Kiosk, F1, or F3 licenses are subject to a separate license-based EWS restriction that the allow list does not override. If Grooper imports from a mailbox on one of these licenses, a license change may be required.&lt;br /&gt;
* Expired credentials: if a client secret or certificate is used for authentication, confirm it has not expired.&lt;br /&gt;
&lt;br /&gt;
==Quick reference – all commands in order==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# 1. Connect&lt;br /&gt;
Connect-ExchangeOnline -UserPrincipalName admin@yourdomain.com&lt;br /&gt;
&lt;br /&gt;
# 2. Check current state&lt;br /&gt;
Get-OrganizationConfig | Format-List EWSEnabled&lt;br /&gt;
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs&lt;br /&gt;
&lt;br /&gt;
# 3. Add an App ID without losing existing entries&lt;br /&gt;
$current = (Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy).EwsAllowedAppIDs&lt;br /&gt;
$updated = @($current -split &amp;quot;,&amp;quot; | ForEach-Object { $_.Trim() } | Where-Object { $_ }; &amp;quot;YOUR-APP-ID-HERE&amp;quot;) | Select-Object -Unique&lt;br /&gt;
Set-OrganizationConfig -EwsAllowedAppIDs ($updated -join &amp;quot;,&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
# 4. Enable (only after the list is complete)&lt;br /&gt;
Set-OrganizationConfig -EwsEnabled $true&lt;br /&gt;
&lt;br /&gt;
# 5. Verify&lt;br /&gt;
Get-OrganizationConfig | Format-List EWSEnabled&lt;br /&gt;
Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy | Format-List EwsAllowedAppIDs&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Remember: EWSEnabled changes take about 1 hour; allow list changes take up to 24 hours.&lt;br /&gt;
== Questions ==&lt;br /&gt;
Contact your Grooper account representative or Grooper Support with any questions about this change.&lt;/div&gt;</summary>
		<author><name>Dgreenwood</name></author>
	</entry>
</feed>