Get all your news in one place.
100's of premium titles.
One app.
Start reading
TechRadar
TechRadar
Markus Müller

Microsoft’s EWS shutdown should be treated as a warning, not a one-off

Concept art representing cybersecurity principles.

On 1st October, Microsoft will begin disabling its Exchange Web Services (EWS) API, ahead of a full shutdown in April 2027. For many organizations, EWS has long been part of the invisible plumbing behind everyday workplace tools. It allows applications to connect to Exchange mailboxes, making it possible to access and manage data from emails, calendars, contacts and folders.

But EWS is almost 20 years old. Microsoft says it no longer aligns with modern requirements for security, scale and reliability, and its involvement in 2024’s Midnight Blizzard attack has added urgency to its retirement. The wider risk is also clear: APIs, particularly older and less visible ones, have become attractive targets for cybercriminals. Recent research found that 99% of organizations encountered API security issues in the past year.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.