Skip to content

Commit 5f5074a

Browse files
committed
added line about list of Microsoft first-party client application IDs,
1 parent c09d89d commit 5f5074a

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

microsoft-365/baseline-security-mode/block-access-exchange-web-services.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Use the Microsoft 365 admin center, to prevent unauthorized and out
44
author: vpattnai
55
ms.author: vpattnaik
66
manager: dansimp
7-
ms.date: 02/25/2026
7+
ms.date: 03/25/2026
88
ms.topic: how-to
99
ms.service: microsoft-365-admin
1010
ms.localizationpriority: medium
@@ -26,7 +26,7 @@ If you have enabled this setting but need to revert to the default behavior (all
2626

2727
EWS has historically been used by legacy applications and custom integrations. However, it also represents a common attack vector because it allows broad programmatic access to mailbox data. Compromised accounts or malicious apps can use EWS to read mail, access contacts, send messages, or perform automated actions without user interaction. Enforcing this setting significantly reduces your risk by preventing unauthorized or outdated apps from reaching sensitive Exchange data. You can still allow exceptions for specific users or workloads using Exchange Online PowerShell.
2828

29-
You can also generate a CSV report to identify which apps are making EWS requests, how frequently they access EWS, and the extent of your organization’s dependency on EWS.
29+
You can also generate a CSV report to identify which apps are making EWS requests, how frequently they access EWS, and the extent of your organization’s dependency on EWS. For a list of Microsoft first-party client application IDs, see [Commonly used Microsoft first-party services and portal apps](/power-platform/admin/apps-to-allow). For Microsoft applications, Microsoft updates those periodically to remove EWS dependencies. We recommend that you keep your client applications up-to-date. If you still can't find the Application ID, check your Enterprise Applications in Entra ID. For more information, see [Quickstart: View enterprise applications](/entra/identity/enterprise-apps/view-applications-portal).
3030

3131
> [!NOTE]
3232
> Usage data is collected and aggregated weekly, not daily.

0 commit comments

Comments
 (0)