SAP Knowledge Base Article - Public

3798115 - Migration From Microsoft Exchange Basic Authorization (EWS API End User Sign In) to Microsoft Graph API on Server Side Integration (FAQ)

Symptom

Reviewing Events related to the deprecation of Microsoft Exchange Web Services (EWS). During assessment of the SAP Sales Cloud (C4C) tenant, the users are currently configured with the following:

Microsoft Exchange Basic Authorization (EWS API End User Sign In)

Environment

SAP Cloud for Customer

Resolution

Here are some points to be considered:

1. Is the current configuration impacted?

Yes, if users are connected to Exchange Online/Microsoft 365, the current EWS-based configuration is affected by the Microsoft EWS deprecation and should be migrated to the Microsoft Graph API before the October 2026 deadline.
The deprecation concerns EWS access to Exchange Online. On-premises Exchange environments are not part of this Microsoft Exchange Online EWS retirement.

2. Which SAP Sales Cloud functionalities are affected?

The change primarily affects the server-side integration between Microsoft 365 and SAP Sales Cloud, including the synchronization of supported mailbox objects such as:

  • Emails
  • Appointments/calendar items
  • Contacts
  • Tasks
  • Other supported SAP Sales Cloud activities synchronized with Outlook

If EWS is retired while the organization is still configured to use EWS, the server-side synchronization relying on that connection will no longer operate correctly.

3. Which migration option is recommended?

Where the customer's Microsoft security policy allows it, we generally recommend Microsoft Graph App-Only Access.

The main advantages are the following:

  • One-time administrator authorization
  • No individual Microsoft sign-in required from every user
  • Less user interaction during initial setup and ongoing operation
  • Easier administration and maintenance
  • No dependency on individual user refresh tokens for background synchronization

Microsoft Graph Delegated / end-user logon remains available where App-Only permissions cannot be approved by the customer's security team. With this option, each user must authorize the Microsoft connection individually.

4. Key migration activities and user impact:

The main activities are:

  • Select the required Microsoft Graph authentication type in Groupware Settings.
  • Ensure the required Microsoft Graph permissions are approved by the Microsoft 365 administrator.
  • Configure and validate the Microsoft Graph connection.
  • For Graph End User Logon / Delegated, each user must authenticate/reconnect their mailbox.
  • For Graph App-Only, authorization is performed centrally by the administrator.
  • Validate synchronization with a limited set of test users before migrating the remaining users.

Existing records already synchronized to SAP Sales Cloud are not deleted simply because the authentication method is changed.

Please also note that Outlook Add-in deployment for Graph-based organizations should be managed through Microsoft 365 centralized deployment using the manifest exported from Groupware Settings.

5. How can the migration be validated?

After migration, we recommend checking the following:

  • The organization/mailbox authentication type shows Microsoft Graph API rather than EWS.
  • Microsoft authorization/consent has completed successfully.
  • The affected users show a successful mailbox connection.
  • Test items can be synchronized successfully in both required directions, for example:
    • Outlook → SAP Sales Cloud
    • SAP Sales Cloud → Outlook
  • No EWS authentication or connectivity errors are reported for the migrated users.

We strongly recommend completing this validation with a small pilot group before moving all production users.

6. Recommended migration approach:

As a best practice, we recommend:

  1. Review the required Microsoft Graph permissions with the Microsoft 365/security team.
  2. Decide between Graph App-Only and Graph End User Logon (Delegated).
  3. Configure and test the Graph with a small pilot group.
  4. Validate email/calendar/contact synchronization according to the functionality used by your organization.
  5. Roll out the configuration to the remaining users.
  6. Confirm that all production users have successfully moved away from EWS before the Microsoft deadline.

7. Can we just switch to the Microsoft 365 OAuth (Graph API) to migrate by organization?

Yes, you can switch the organization connectivity type.
The required steps depend on whether you would like to migrate to Graph API – End user sign-in or Graph API – App-only sign-in.

Graph API – End user sign-in

If you change the organization connectivity type from Microsoft 365 OAuth (EWS API) – End user sign-in to Microsoft 365 OAuth (Graph API) – End user sign-in:

  • The administrator needs to change the connectivity type in the Admin UI.
  • Each affected user then needs to reconnect their mailbox via User Settings → My Sync Status → Email configuration → Change or Refresh.
  • There is no tenant-wide admin authorization that reconnects all users in this configuration.

Users who do not reconnect will remain on their existing EWS connection until EWS is no longer available, after which synchronization will stop.

Graph API – App-only sign-in

If you would prefer to avoid requiring each user to reconnect individually, you can migrate to Microsoft 365 OAuth (Graph API) – App-only sign-in.

In this case:

  • The administrator changes the organization connectivity type.
  • A Microsoft 365 administrator provides the required tenant-wide consent.
  • Once the App-only configuration is completed successfully, no individual mailbox reconnection is required from end users.

For organizations with multiple users, Graph API – App-only sign-in is generally the more convenient migration option, as the authorization is managed centrally rather than individually by each user.

See Also

Known limitations on the Graph side

   --> Categories are not supported. 
   --> Recurring task synchronization is not supported (both V1 and V2)
   --> Deleted tasks cannot be processed through Graph the way they were via EWS.
   --> Migrating tasks back from Graph to EWS is not supported - task migration is effectively one-directional.
   --> Instant sync of calendar events from Outlook to SAP Sales Cloud is not available both in V1 and V2 for Graph users.
   --> Notifications for non-essential meeting updates (including past meetings) made by the organizer are sent to all attendees automatically; this behavior needed further verification and may differ from EWS.
   --> Centralized/mass Add-in deployment through our own admin panel is not available for Graph  app-only sign-in and end-user sign-in - it must go through the "Deploy Add-ins" feature in the Microsoft 365 Admin Center, using a manifest exported from Groupware Settings. This is a genuine Microsoft-side platform limitation (confirmed with Microsoft, on their roadmap as high priority but with no committed date), not a gap in our implementation. We're also working on a Microsoft Store listing for the add-in as an alternative deployment path.

Keywords

C4C; SSI; Server Side; EWS; Graph; Microsoft; Migration; Exchange; API; End User , KBA , LOD-CRM-GW-SCC , Invisible CRM - Smart Cloud Connect Solution , How To

Product

SAP Cloud for Customer add-ins all versions ; SAP Cloud for Customer core applications 2608