Prerequisites
Steps to Get Backup Exec M365 applications

4. Click on the button titled ‘Fetch details’ to obtain the list of applications.

5. Copy all the values against the property “Application ID:” to another document to be used later. The number of applications may vary depending upon the configuration. It is mandatory to add all application IDs to the AllowList.
Steps to Enable EWS
Step 1: Connect to Exchange Online PowerShell
powershell
Connect-ExchangeOnline -UserPrincipalName
Step 2: Verify Current EWS Configuration
powershell
Get-OrganizationConfig | Select EwsEnabled, EwsAllowList
Ensure EwsEnabled is set to True.
Step 3: Enable EWS (if disabled)
powershell
Set-OrganizationConfig -EwsEnabled $true
Microsoft has claimed that they will populate the AllowList for tenants that have set EwsEnabled to True. One can check if any AllowList is created by running the following command:
powershell
Get-OrganizationConfig | Select EwsAllowList
If the command returns a list then validate that all the BackupExec application IDs are returned in the output.
You can skip next steps if BackupExec Application Ids are already part of EwsAllowList.
Step 4: Configure EWS Application Allowlist on your own
Add values of the Backup Exec Application IDs to the command and execute it.
powershell
Set-OrganizationConfig -EwsApplicationAccessPolicy EnforceAllowList -EwsAllowList @( "11111111-1111-1111-1111-111111111111", "22222222-2222-2222-2222-222222222222", "33333333-3333-3333-3333-333333333333", "44444444-4444-4444-4444-444444444444", "55555555-5555-5555-5555-555555555555", "66666666-6666-6666-6666-666666666666" )
Step 5: Confirm Configuration
powershell
Get-OrganizationConfig | Select EwsAllowList
Validate that all the application IDs are returned in the output of the above command.
Microsoft has set a timeline for Exchange Web Services (EWS) deprecation, meaning applications relying on EWS will lose support and functionality after the cutoff. At present, all data protection applications, including Backup Exec, rely on EWS to protect Exchange Online entities like User Mailboxes, Archive Mailboxes, Shared Mailboxes, Group Mailboxes, and Public Folders.
Microsoft is in the process of providing an alternative to EWS via the Graph API, which is a unified endpoint for Microsoft 365 services and supports Modern authentication with OAuth 2.0 and the Microsoft Identity platform.
Backup Exec is committed to delivering the transition to Graph before EWS is deprecated; however, it is to be noted that Microsoft has proposed turning off EWS functions well before the availability of fully functional Graph APIs. As a precautionary measure, we recommend registering the Backup Exec applications responsible for Exchange Online backup in the EWS Allow List to continue backup jobs seamlessly.
The steps to enable Exchange Web Services (EWS) in a Microsoft 365 tenant and configure an EWS application Allow List are as follows. This will ensure that EWS functionality remains available until Microsoft officially retires support.
FAQ:
Please note that this article references sites not owned or maintained by Backup Exec and, as such, is not responsible for the content portrayed on such sites, including any revisions to or deletions of content or third-party software on which this article relies. User is responsible for conducting all necessary due diligence prior to following the instructions described in this article.