Has anyone run into this issue after applying Microsoft's recommended EWS configuration for Synology Active Backup for Microsoft 365? EWS is enabled at the tenant and mailbox levels, and the required application IDs have been registered. Primary mailbox, calendar, and other backup items complete successfully, but archive mailbox backups fail at multiple customer sites with an HTTP 403 error. The response includes the message: "EWS is blocked by policy for this user or tenant." Is there another Exchange policy, application access setting, or licensing requirement that needs to be configured specifically for archive mailbox access?
3 Answers
Confirm that EWS is enabled for each affected mailbox, not just for the organization. Also check whether the account and archive have the required licensing. However, Microsoft Graph does not currently provide access to in-place archive mailboxes, so switching a backup product from EWS to Graph would not automatically solve archive backups. The product needs a supported EWS archive implementation, and that may be affected by Microsoft's ongoing EWS restrictions.
The important part of the error is the policy reason, which means Exchange is actively refusing the request rather than simply failing to authenticate. Check both organization and mailbox-level settings with PowerShell, including EwsEnabled, EwsApplicationAccessPolicy, and any allow or block lists. A mailbox-level setting can override the organization setting, so test one of the affected users directly. Also verify the application access policy or Applications RBAC permissions for the app ID. `Test-ApplicationAccessPolicy` should confirm whether the app is allowed to access that mailbox. If the changes were recent, allow time for them to propagate. Since the same archive-only failure occurs across several tenants, Synology or Microsoft support may need to investigate the archive request path.
Run the application access policy test against an affected mailbox. If it returns denied, the EWS settings can look correct while the application is still blocked.
The timing matters here because EWS access is being restricted and deprecated in stages. Enabling EWS alone is no longer necessarily sufficient; the application also needs explicit authorization under the tenant's current access policy. If the settings and app permissions are correct but archive mailboxes still return the same 403, this is likely a compatibility or service-side issue rather than a simple mailbox configuration problem.

A 403 that includes the app ID usually means Exchange recognizes the application but is rejecting its authorization. Archive requests may be evaluated differently from primary mailbox requests, so checking only the normal EWS switches may not be enough.