The migration fails with:
Error Message
Error during folders binding in the SOURCE/TARGET : The operation failed. 403 Forbidden
Affected migrations
Any migration where Cloudiway connects to Exchange Online through EWS (Exchange Web Services) and attempts to bind mailbox folders. This includes:
- Mailbox audits
- Mail migrations where the source is Exchange Online
- Mail migrations where the target is Exchange Online
- Calendar, contact, and task migrations that rely on EWS folder binding
Cause
A 403 Forbidden response can occur when EWS is disabled at the Exchange Online organization or mailbox level, or when the application used by Cloudiway is not authorized to access EWS.
Microsoft is introducing additional EWS access controls as part of the Exchange Online EWS retirement. In particular, tenants must explicitly enable EWS at the organization level and allow authorized applications through the EwsAllowedAppIDs configuration.
Important
Having EwsEnabled : True on an individual mailbox is not sufficient. The Cloudiway application must also be permitted to access EWS at the tenant level.
Microsoft's current guidance states that when EwsEnabled is set to $true, only application IDs included in the EWS allowed application ID list can use EWS.
Resolution
An Exchange Online administrator should perform the following steps using Exchange Online PowerShell.
1. Connect to Exchange Online
Install the Exchange Online PowerShell module if necessary:
Install-Module ExchangeOnlineManagement -Scope CurrentUser Connect to Exchange Online:
Connect-ExchangeOnline -UserPrincipalName [email protected] 2. Check the current EWS configuration
Check the organization-level configuration:
Get-OrganizationConfig | fl EwsEnabled,EwsAllowedAppIDs,EwsApplicationAccessPolicy Check the affected mailbox:
Get-CASMailbox <failing-user>@yourdomain.com | fl EwsEnabled,EwsApplicationAccessPolicy,EwsAllowList,EwsBlockList 3. Enable EWS at the organization level
The organization-level EWS setting must explicitly be enabled:
Set-OrganizationConfig -EwsEnabled $true Verify:
Get-OrganizationConfig | fl EwsEnabled The expected result is:
EwsEnabled : True 4. Enable EWS for the affected mailbox
If the mailbox has EWS disabled, enable it:
Set-CASMailbox -Identity <failing-user>@yourdomain.com -EwsEnabled $true Verify:
Get-CASMailbox <failing-user>@yourdomain.com | fl EwsEnabled The expected result is:
EwsEnabled : True 5. Allow Cloudiway to access EWS
Important — required for Exchange Online EWS enforcement
Starting October 1, 2026, Exchange Online will enforce the EWS application allow-list for tenants that continue using EWS.
The Cloudiway application ID must therefore be included in the tenant's EwsAllowedAppIDs configuration.
The App ID depends on how the Cloudiway Microsoft 365 connector is configured.
For Cloudiway Automatic Connectors, use the following application IDs:
| Cloudiway connector | Application ID |
|---|---|
| Automatic Microsoft 365 Source | 5f7eb765-974a-45c6-8f93-43a417abdedd |
| Automatic Microsoft 365 Target | ac1e5a45-2177-412c-ac06-09ba04df530a |
If the migration uses a manually created Entra ID application, add the Application (Client) ID of that application instead of the Cloudiway automatic connector App ID.
5.1 Check the current allowed application IDs
Run:
Get-OrganizationConfig | fl EwsAllowedAppIDs If the result is empty, no EWS application IDs are currently configured.
5.2 Add the Cloudiway application ID without removing existing entries
Do not overwrite an existing allow list if other applications are already authorized.
The following example retrieves the existing values, adds the Cloudiway application ID, removes duplicates, and writes the resulting list back:
$cloudiwayAppId = "5f7eb765-974a-45c6-8f93-43a417abedd"
$config = Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy
$current = $config.EwsAllowedAppIDs
if ([string]::IsNullOrWhiteSpace($current)) {
$updated = $cloudiwayAppId
}
else {
$updated = (($current -split "," | ForEach-Object { $_.Trim() }) + $cloudiwayAppId |
Sort-Object -Unique) -join ","
}
Set-OrganizationConfig -EwsEnabled $true -EwsAllowedAppIDs $updated For a source automatic Microsoft 365 connector, use:
$cloudiwayAppId = "5f7eb765-974a-45c6-8f93-43a417abdedd" For a target automatic Microsoft 365 connector, use:
$cloudiwayAppId = "ac1e5a45-2177-412c-ac06-09ba04df530a" 5.3 Verify the configuration
Run:
Get-OrganizationConfig | fl EwsEnabled,EwsAllowedAppIDs The result should show:
EwsEnabled : True
EwsAllowedAppIDs : <Cloudiway App ID(s)> Important Note
Changes to the organization configuration may take a few minutes to propagate across all Exchange Online services. If the issue persists after enabling EWS, wait 5-10 minutes before retrying the migration.