Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Client application doesn't honor EwsAllowList in Exchange Server 2019 and 2016


View products that this article applies to.

Symptoms

In Microsoft Exchange Server 2019 or Exchange Server 2016, assume that you try to prevent client applications from using REST and EWS by using the EwsAllowList parameter in the Set-OrganizationConfig cmdlet. However, you experience an issue that the application doesn't honor the EwsAllowList parameter. The client application can still use the REST and EWS to connect to Exchange Server even if the value of EwsAllowList is set to null (it prevents all client applications from using REST and EWS).

↑ Back to the top


Cause

This issue occurs because all users have the EWSEnabled parameter set to null by default in on-premises Exchange. This setting allows all clients that have null set in EWSEnabled to access without checking EwsAllowList

↑ Back to the top


Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. 

↑ Back to the top


Resolution

To fix this issue, install one of the following updates:
For Exchange Server 2019, install the Cumulative Update 1 for Exchange Server 2019 or a later cumulative update for Exchange Server 2019.
For Exchange Server 2016, install the Cumulative Update 12 for Exchange Server 2016 or a later cumulative update for Exchange Server 2016.

↑ Back to the top


References

Learn about the terminology that Microsoft uses to describe software updates.

↑ Back to the top


Keywords: client application, ewsallowlist not honored, kb, kbfix, kbqfe, kbHotfixAuto, CI97342

↑ Back to the top

Article Info
Article ID : 4488266
Revision : 7
Created on : 2/12/2019
Published on : 2/12/2019
Exists online : False
Views : 273