July 21, 2026 (Tue): Due to the phased discontinuation of legacy features in Cloud Protection, the deadline has been changed to August 31, 2026 (Mon). In addition, the Specification Changes Due to Migration section has been updated with the latest information.
Thank you for using HENNGE One.
Microsoft has announced that Exchange Web Services (EWS) will be deprecated as of October 1, 2026.
Official Microsoft information: Deprecation of EWS in Exchange Online (external link)
Accordingly, Cloud Protection will begin migrating to a more secure and future-proof integration method using Microsoft Graph API starting September 1, 2026, and will discontinue features that use EWS integration.
To use the integration method based on Graph API, you must authorize (verify) Cloud Protection to use Graph API in your tenant by August 31, 2026.
*If this process is not completed by the deadline, you may lose access to Exchange Online protection features in the service.
Target
-
All customers using Exchange Online protection features in Cloud Protection
This update is required to continue providing security protection for Exchange Online after September 1, 2026.
Deadline
August 31, 2026 (Mon)
Procedure
Please follow the steps below to update the permissions.
*This process requires authentication with a Microsoft 365 Global Administrator account.
Please make sure to complete this by August 31, 2026 (Mon).
- Log in to the Cloud Protection Administration (Element Security Center).
- From the left menu, go to [Collaboration Protection] – [Connected Service].
-
Confirm that a warning banner appears at the top of the screen stating, "To support the latest features and improvements, please update Exchange permissions."
-
Select the checkbox for the target tenant that requires a permission update, and from the action bar displayed at the bottom of the screen, click [Update Exchange Permissions].
*An exclamation mark (!) will be displayed in the row for the target service. - A popup will appear asking, "Do you want to set up access to Exchange?" Click [Connect].
- The Microsoft 365 login screen will appear. Authenticate using a Global Administrator account.
- On the permissions request screen, click the [Accept] button.
- Return to the [Connected Service] screen and confirm that the exclamation mark (!) next to the target app has disappeared.
*The permission update is complete with the above steps, but please also review the following notes regarding changes due to the migration to Graph API.
Notes
The migration to Graph API is a change based on Microsoft platform specifications, and some features will behave differently compared to the previous EWS connection.
Specification Changes Due to Migration
Change in Scan Method for Receive Trail Rules
-
Settings Changed: The method will change from the previous push notification to a polling method that checks periodically.
Due to Microsoft Graph API limitations (throttling), frequent checks from Cloud Protection may be restricted.
As a result, there may be a slight delay in detecting rule additions or updates.
Specification Change for Calendar and Contacts Quarantine Feature
Updated July 21, 2026: Calendar and contacts are now excluded from scan targets.
-
Settings Changed:
Due to Graph API limitations, the previous "Hide (Quarantine)" action will no longer be available. Going forward, one of the following actions will be used: "Rename," "Unlink," or "Delete." The previous quarantine feature using "Hide" will be discontinued, but the selected alternative action will continue to neutralize threats.
Exclusion of Tasks, Description, Calendar, and Contacts from Detection
Updated July 21, 2026: Calendar and contacts are now excluded from scan targets.
-
Settings Changed: Since Microsoft Graph API does not provide a detection mechanism equivalent to the previous EWS method, after migration, tasks, description, calendar, and contacts objects will be excluded from detection.
WithSecure has evaluated, based on historical attack statistics, that the risk of compromise via tasks or description is extremely rare.
Currently, we recognize that the security impact of this limitation is minimal, but if Microsoft Graph API functionality is enhanced in the future, we will consider supporting these features again.
These limitations are unavoidable changes due to Microsoft Graph API restrictions, but migrating to Graph API is a necessary process to strengthen security across your organization.
To ensure service continuity, we strongly recommend updating permissions as soon as possible.
We are fully committed to supporting your smooth migration to a more secure Graph API-based environment.
If you have any questions regarding this matter, please feel free to contact HENNGE One Technical Support.