866-860-1223

Skip to main content
How Can We Help?

Search for answers or browse our knowledge base.

Categories
< All Topics
Print

Overview

Microsoft is retiring Exchange Web Services (EWS) in Exchange Online. Microsoft has announced that EWS will begin being disabled globally in October 2026, with EWS fully disabled in April 2027.

Customers using Microsoft 365 / Exchange Online mailboxes for email-based document imports into Epicor ECM or IDC will need to transition applicable mailbox connections from EWS to Microsoft Graph API.

This may apply to email imports configured in any of the following locations:

  • Epicor ECM Client Service
  • Epicor IDC Client Service
  • Epicor IDC Web UI email batch import configuration

Throughout this article, these components may collectively be referred to as Epicor Client Services or Epicor email imports.

Microsoft Graph configuration within the customer’s Microsoft 365 tenant must be completed by the customer’s Microsoft 365 / Microsoft Entra administrator. Mosaic does not administer or configure the customer’s Microsoft 365 tenant.

Once the required Microsoft-side configuration has been completed, customers should review each Microsoft 365 email import configured within Epicor ECM and/or IDC and change the applicable connection type from EWS to Microsoft Graph API. As part of this change, you may be required to sign in to Microsoft again and reauthorize the mailbox connection.


Why Is This Change Required?

Microsoft is retiring EWS in Exchange Online and recommends that applications accessing Exchange Online data migrate to Microsoft Graph.

According to Microsoft’s current retirement timeline:

  • October 2026 – Microsoft begins globally disabling EWS for Exchange Online organizations.
  • April 2027 – EWS is fully disabled in Exchange Online.

Customers should prepare their Microsoft 365 environment and migrate their applicable Epicor email import connections to Microsoft Graph before EWS becomes unavailable within their Microsoft 365 environment.

Microsoft Documentation:

Microsoft Learn – Deprecation of Exchange Web Services in Exchange Online

Microsoft Learn – Migrate Exchange Web Services (EWS) apps to Microsoft Graph


What Is Microsoft Graph?

Microsoft Graph is Microsoft’s API platform for accessing Microsoft 365 services and data, including Exchange Online mailboxes.

For Epicor email imports, Microsoft Graph replaces the EWS connection previously used to access a Microsoft 365 mailbox.

Existing EWS Connection:

Epicor Email Import → EWS → Microsoft 365 Mailbox

Microsoft Graph Connection:

Epicor Email Import → Microsoft Graph → Microsoft 365 Mailbox

This allows Epicor ECM and IDC to continue accessing designated Microsoft 365 mailboxes for email-based document and attachment imports after EWS is retired.

Microsoft Learn – Microsoft Graph Overview


Step 1 – Prepare Your Microsoft 365 Tenant for Microsoft Graph

Before an Epicor email import can be changed from EWS to Microsoft Graph API, your organization’s Microsoft 365 / Microsoft Entra administrator must prepare your Microsoft 365 tenant for the application connection.

At a high level, your Microsoft administrator will need to:

  1. Create or configure the appropriate application registration in Microsoft Entra ID.
  2. Configure the Microsoft Graph permissions required for access to the mailbox.
  3. Grant the required administrator consent.
  4. Configure the authentication and application credentials required by the integration.
  5. Ensure the application is permitted to access the Microsoft 365 mailbox or mailboxes used by Epicor email imports.

These tasks are performed within the customer’s Microsoft environment and should be completed by your organization’s Microsoft 365 administrator or IT provider. Mosaic does not administer or configure the customer’s Microsoft 365 / Microsoft Entra environment.

Microsoft Documentation

Your Microsoft 365 administrator should use Microsoft’s current documentation when preparing the environment:

Microsoft Learn – Register an application with the Microsoft identity platform

Microsoft Learn – Configure an application to access a web API

Microsoft Learn – Microsoft Graph Permissions Reference

Microsoft Learn – Get access without a user

Microsoft Learn – Role Based Access Control for Applications in Exchange Online


Step 2 – Identify Your Epicor Email Import Connections

After the Microsoft-side requirements have been completed, review the Microsoft 365 email imports configured within your Epicor environment.

Depending on your environment, email imports may be configured in one or more of the following locations:

Epicor ECM Client Service

Epicor ECM environments may use the ECM Client Service to monitor a Microsoft mailbox and import email messages, attachments, or documents into Epicor ECM.

Any applicable Microsoft 365 email import currently configured to use EWS should be reconfigured to use the supported Microsoft Graph API connection type.

Epicor IDC Client Service

Epicor IDC environments may use the IDC Client Service for email batch imports into Intelligent Data Capture.

Any applicable Microsoft 365 email import currently configured to use EWS should be reconfigured to use the supported Microsoft Graph API connection type.

Epicor IDC Web UI

Some IDC environments configure email batch imports through the IDC Web UI rather than through the locally installed IDC Client Service.

These email batch import configurations should also be reviewed. Any applicable Microsoft 365 mailbox connection using EWS should be reconfigured to use the supported Microsoft Graph API connection type.

Important: Many customers use both Epicor ECM and Epicor IDC. If your organization uses both products, review the email import configurations for both ECM and IDC. Updating one email import does not necessarily update other mailbox connections configured elsewhere in the environment.


Step 3 – Change the Epicor Email Import from EWS to Microsoft Graph API

Once your Microsoft 365 administrator has completed the required Microsoft-side preparation, each applicable Epicor email import should be reconfigured to use Microsoft Graph API instead of EWS.

This should be completed for each affected email import configured within:

  • Epicor ECM Client Service
  • Epicor IDC Client Service
  • Epicor IDC Web UI email batch import configuration

When changing the connection from EWS to Microsoft Graph API, the Microsoft mailbox may need to be authenticated and authorized again. If prompted, sign in using the appropriate Microsoft account and complete the Microsoft authorization process for the mailbox connection.

Note: Changing the connection type from EWS to Microsoft Graph may require a new Microsoft sign-in/authorization even though the same mailbox was previously configured and working with EWS.

Repeat this process for each Microsoft 365 mailbox/email import configured in your Epicor environment that currently uses EWS.


Step 4 – Test Each Email Import

After changing an email import from EWS to Microsoft Graph API, test the connection before considering the migration complete.

For each updated email import:

  1. Confirm that the Microsoft Graph connection can successfully connect to the configured mailbox.
  2. Send a test email to the mailbox with a supported document attachment.
  3. Confirm that Epicor detects and processes the email.
  4. Confirm that the attachment is successfully imported into Epicor ECM or IDC as expected.
  5. Confirm that any expected post-processing of the email occurs correctly.

If your environment contains multiple email imports, each connection should be tested individually.


Recommended Customer Action

If your organization currently imports documents or attachments from Microsoft 365 mailboxes into Epicor ECM or IDC, we recommend beginning this process before Microsoft’s EWS retirement affects your environment.

  1. Identify Microsoft 365 email imports currently configured in Epicor ECM and/or IDC.
  2. Provide this article and the linked Microsoft documentation to your Microsoft 365 administrator or IT provider.
  3. Complete the required Microsoft 365 / Microsoft Entra configuration for Microsoft Graph.
  4. Reconfigure each applicable Epicor email import to use Microsoft Graph API instead of EWS.
  5. Complete the Microsoft sign-in/authorization process again if prompted when configuring the Graph connection.
  6. Test each email import to confirm emails and attachments continue to process successfully.

Customers using both Epicor ECM and Epicor IDC should verify whether email imports are configured in both systems and update each applicable connection.


Microsoft Resources

EWS Retirement
Microsoft Learn – Deprecation of Exchange Web Services in Exchange Online

Migrating from EWS to Microsoft Graph
Microsoft Learn – Migrate Exchange Web Services (EWS) apps to Microsoft Graph

Microsoft Graph Overview
Microsoft Learn – Microsoft Graph Overview

Register an Application
Microsoft Learn – Register an application with the Microsoft identity platform

Configure API Permissions
Microsoft Learn – Configure an application to access a web API

Microsoft Graph Permissions
Microsoft Learn – Microsoft Graph Permissions Reference

Application-Only Authentication
Microsoft Learn – Get access without a user

Restricting Application Access to Exchange Online Mailboxes
Microsoft Learn – Role Based Access Control for Applications in Exchange Online


Important Notes

This Microsoft EWS retirement applies to Exchange Online / Microsoft 365. Microsoft states that the retirement does not apply to EWS in on-premises Exchange Server.

This article is intended to identify the Microsoft 365 preparation required before Epicor email imports can be changed to Microsoft Graph. Mosaic Support does not configure or administer the customer’s Microsoft 365 / Microsoft Entra tenant. Microsoft-side configuration should be completed by the customer’s Microsoft 365 administrator or IT provider using Microsoft’s documentation linked throughout this article.

Once the required Microsoft-side configuration has been completed, the customer should proceed with reconfiguring each applicable Epicor email import to use Microsoft Graph API instead of EWS. Depending on the customer’s environment, this may include email imports configured in the Epicor ECM Client Service, Epicor IDC Client Service, IDC Web UI, or a combination of these locations.

When changing an existing email import from EWS to Microsoft Graph API, the Microsoft mailbox may need to be signed into and authorized again. Complete the Microsoft authentication/authorization process if prompted, then test the email import to confirm that Epicor can successfully access the mailbox and process email attachments.

Customers with multiple Microsoft 365 email imports should review, update, and test each applicable connection individually before the EWS retirement deadline.


Additional Resources

Configuring Batch Import Email – Epicor Content Management.pdf

Was this article helpful?
0 out of 5 stars
5 Stars 0%
4 Stars 0%
3 Stars 0%
2 Stars 0%
1 Stars 0%
5
Please Share Your Feedback
How Can We Improve This Article?
Table of Contents