EWS 403 Forbidden during mailbox migration

Updated on April 21, 2026 Cloudiway Team

The migration fails with:

Error Message

Error during folders binding in the SOURCE/TARGET : The operation failed. 403 Forbidden

Affected migrations

Any migration where Cloudiway connects to Exchange Online through EWS (Exchange Web Services) and attempts to bind mailbox folders. This includes:

  • Mailbox audits
  • Mail migrations where the source is Exchange Online
  • Mail migrations where the target is Exchange Online
  • Calendar, contact, and task migrations that rely on EWS folder binding

Cause

A 403 Forbidden response can occur when EWS is disabled at the Exchange Online organization or mailbox level, or when the application used by Cloudiway is not authorized to access EWS.

Microsoft is introducing additional EWS access controls as part of the Exchange Online EWS retirement. In particular, tenants must explicitly enable EWS at the organization level and allow authorized applications through the EwsAllowedAppIDs configuration.

Important

Having EwsEnabled : True on an individual mailbox is not sufficient. The Cloudiway application must also be permitted to access EWS at the tenant level.

Microsoft's current guidance states that when EwsEnabled is set to $true, only application IDs included in the EWS allowed application ID list can use EWS.

Resolution

An Exchange Online administrator should perform the following steps using Exchange Online PowerShell.

1. Connect to Exchange Online

Install the Exchange Online PowerShell module if necessary:

Install-Module ExchangeOnlineManagement -Scope CurrentUser

Connect to Exchange Online:

Connect-ExchangeOnline -UserPrincipalName [email protected]

2. Check the current EWS configuration

Check the organization-level configuration:

Get-OrganizationConfig | fl EwsEnabled,EwsAllowedAppIDs,EwsApplicationAccessPolicy

Check the affected mailbox:

Get-CASMailbox <failing-user>@yourdomain.com | fl EwsEnabled,EwsApplicationAccessPolicy,EwsAllowList,EwsBlockList

3. Enable EWS at the organization level

The organization-level EWS setting must explicitly be enabled:

Set-OrganizationConfig -EwsEnabled $true

Verify:

Get-OrganizationConfig | fl EwsEnabled

The expected result is:

EwsEnabled : True

4. Enable EWS for the affected mailbox

If the mailbox has EWS disabled, enable it:

Set-CASMailbox -Identity <failing-user>@yourdomain.com -EwsEnabled $true

Verify:

Get-CASMailbox <failing-user>@yourdomain.com | fl EwsEnabled

The expected result is:

EwsEnabled : True

5. Allow Cloudiway to access EWS

Important — required for Exchange Online EWS enforcement

Starting October 1, 2026, Exchange Online will enforce the EWS application allow-list for tenants that continue using EWS.

The Cloudiway application ID must therefore be included in the tenant's EwsAllowedAppIDs configuration.

The App ID depends on how the Cloudiway Microsoft 365 connector is configured.

For Cloudiway Automatic Connectors, use the following application IDs:

Cloudiway connector Application ID
Automatic Microsoft 365 Source 5f7eb765-974a-45c6-8f93-43a417abdedd
Automatic Microsoft 365 Target ac1e5a45-2177-412c-ac06-09ba04df530a

If the migration uses a manually created Entra ID application, add the Application (Client) ID of that application instead of the Cloudiway automatic connector App ID.

5.1 Check the current allowed application IDs

Run:

Get-OrganizationConfig | fl EwsAllowedAppIDs

If the result is empty, no EWS application IDs are currently configured.

5.2 Add the Cloudiway application ID without removing existing entries

Do not overwrite an existing allow list if other applications are already authorized.

The following example retrieves the existing values, adds the Cloudiway application ID, removes duplicates, and writes the resulting list back:

$cloudiwayAppId = "5f7eb765-974a-45c6-8f93-43a417abedd"
$config = Get-OrganizationConfig -RetrieveEwsOperationAccessPolicy
$current = $config.EwsAllowedAppIDs
if ([string]::IsNullOrWhiteSpace($current)) {
    $updated = $cloudiwayAppId
}
else {
    $updated = (($current -split "," | ForEach-Object { $_.Trim() }) + $cloudiwayAppId |
        Sort-Object -Unique) -join ","
}
Set-OrganizationConfig -EwsEnabled $true -EwsAllowedAppIDs $updated

For a source automatic Microsoft 365 connector, use:

$cloudiwayAppId = "5f7eb765-974a-45c6-8f93-43a417abdedd"

For a target automatic Microsoft 365 connector, use:

$cloudiwayAppId = "ac1e5a45-2177-412c-ac06-09ba04df530a"

5.3 Verify the configuration

Run:

Get-OrganizationConfig | fl EwsEnabled,EwsAllowedAppIDs

The result should show:

EwsEnabled       : True
EwsAllowedAppIDs : <Cloudiway App ID(s)>

Important Note

Changes to the organization configuration may take a few minutes to propagate across all Exchange Online services. If the issue persists after enabling EWS, wait 5-10 minutes before retrying the migration.

We value your feedback

Help us improve your experience

What would you like to share with us?

Need direct support? Open a ticket