Has anyone fixed the Microsoft 365 EWS policy settings from Synology's troubleshooting guidance but still been unable to back up archive mailboxes with Active Backup for Microsoft 365? EWS is enabled at both the organization and mailbox levels, and the required application IDs have been registered. Primary mailboxes and the rest of the backup jobs complete successfully, but archive mailboxes fail at multiple sites with an HTTP 403 error stating: "EWS is blocked by policy for this user or tenant." The error also includes the Synology application ID. Is there another Exchange policy, application access rule, or mailbox setting that needs to be changed?
3 Answers
The most important part of the error is `x-ews-policy-reason: EWS is blocked by policy for this user or tenant`. That points to an Exchange policy rejection rather than a basic Synology permission issue. Check both organization and mailbox-level settings with `Get-OrganizationConfig | fl Ews*` and `Get-CASMailbox [email protected] | fl Ews*`. Verify `EwsEnabled`, `EwsApplicationAccessPolicy`, and any allow or block lists. A mailbox-level setting can override the organization setting, so test an affected mailbox directly. Also allow time for tenant-wide changes to propagate. Since the same behavior occurs at several sites, include this exact response header when opening support cases with Microsoft or Synology.
EWS access is increasingly controlled through per-application authorization rather than one simple tenant-wide switch. Confirm that the specific application ID used by the backup software is authorized for the affected users and that no organization-wide or mailbox-specific block remains. If all primary mailbox backups work but every archive backup fails, the archive request may be hitting a different Exchange policy path or an unsupported API operation. Vendor support should be able to confirm whether the current application version supports archive mailboxes under Microsoft’s newer EWS restrictions.
Make sure EWS is enabled for each affected mailbox, not just globally. An archive mailbox may also be affected by licensing or application-access restrictions. The fact that the application ID appears in the response suggests Exchange recognizes the caller but is still denying the request through policy.
The organization and mailbox EWS flags are already enabled using the vendor’s PowerShell procedure. The Microsoft documentation I found discusses Graph API not supporting in-place archive mailboxes, but this backup application is using EWS, so I’m trying to determine whether EWS has a separate limitation or whether the request is simply being blocked by the tenant policy.

Also check the application access policy or its newer RBAC equivalent, not only the EWS switches. `Test-ApplicationAccessPolicy -Identity [email protected] -AppId` can reveal whether the application is being denied for that mailbox.