How to Prepare for Exchange Online ApplicationImpersonation Retirement
Question details
The user needs to understand how to prepare for the retirement of Exchange Online ApplicationImpersonation, including assessing affected applications and planning remediation.
- Product
- Microsoft Exchange Online
- Device & OS
- not provided
- Scenario
- Preparing for Microsoft's deprecation of ApplicationImpersonation and RBAC in Exchange Online.
- Observed behavior
- Administrators need to identify affected applications within their tenant and migrate them to supported authentication methods like Microsoft Graph or EWS.AccessAsApp.
Ensure you have global administrator or Exchange administrator privileges in your Microsoft 365 tenant to run diagnostic scripts and review application permissions in Microsoft Entra ID.
Identify Affected Apps and Migrate to Supported Protocols
Follow these steps to find apps using ApplicationImpersonation and migrate them to Microsoft Graph or Exchange Online RBAC for Applications.
Microsoft is officially retiring the ApplicationImpersonation role in Exchange Online. Applications relying on this role for access must be updated to ensure continuous functionality.
Run the necessary assessment scripts provided by Microsoft to generate a report of service principals and apps currently utilizing the ApplicationImpersonation role.
Open the Microsoft Entra ID admin center. Use the application IDs gathered from your script reports to locate the specific affected applications within your tenant.
Whenever possible, update your applications to use the Microsoft Graph API, which provides a more modern and secure method for accessing Exchange Online data.
For scenarios where Microsoft Graph cannot be used and app-only access is supported, update the app to use EWS.AccessAsApp in conjunction with Exchange Online RBAC for Applications.
If you encounter complex dependencies or require tenant-specific guidance during the migration process, open a support ticket with Microsoft 365 support.
Try WPS Office for a Seamless Document Management Experience
While backend Exchange server updates require Microsoft 365 administrative tools, everyday document productivity doesn't have to be complicated. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office for creating, editing, and managing your Word, Excel, and PowerPoint files.
- 1. Download and Install: Get the free WPS Office suite from the official website and install it on your device in minutes.
- 2. Open Your Documents: Seamlessly open your existing Word, Excel, and PowerPoint files with zero formatting loss.
- 3. Save and Share: Edit your documents and save them in standard Office formats to easily share with colleagues and clients.

Frequently Asked Questions
What is ApplicationImpersonation in Exchange Online?
ApplicationImpersonation is a management role in Exchange Online that allows an application to impersonate a user to perform operations on their behalf, such as accessing mailboxes, sending emails, or managing calendars.
Why is Microsoft retiring ApplicationImpersonation?
Microsoft is retiring this role to improve platform security and align with modern authentication standards. They strongly recommend using the more secure Microsoft Graph API or Exchange Online RBAC for Applications instead.
What happens if I don't migrate my applications?
Once the ApplicationImpersonation role is fully retired by Microsoft, any applications still relying on it will lose their ability to access Exchange Online data, resulting in immediate service disruptions and API failures.
How do I find out which apps use ApplicationImpersonation?
You can run Exchange Online PowerShell diagnostic scripts to generate a report of all service principals and apps currently using the role, then match the application IDs in the Microsoft Entra ID admin center.




