This article shows you how to verify that your organization's Microsoft Graph and EWS migrations are fully finished. Complete these checks to confirm that distribution list expansion will keep working after Microsoft begins blocking Exchange Web Services (EWS) requests on October 1, 2026.
Prerequisites
- ContactMonkey Owner or Admin access for the ContactMonkey checks
- A privileged role in Microsoft Entra ID for the IT checks
- The migration steps in Migrating from EWS to Exchange Online Admin API and Migrating to the GroupMember.Read.All Permission for Microsoft Graph already completed
- For the Graph migration: written confirmation from ContactMonkey Support that the legacy
Directory.Read.Allpermission has been disabled
Which migrations apply to your organization?
Both migrations apply if your organization uses both expansion methods. These are two separate updates, and completing one does not complete the other.
-
Microsoft Graph expansion: Requires the permission change from
Directory.Read.AlltoGroupMember.Read.All - EWS expansion: Requires the move to the Exchange Online Admin API
If you are unsure which methods your organization uses, go to Settings → Integrations and check which utility account tiles are signed in.
Verify your integrations in ContactMonkey (ContactMonkey Admin)
Confirm the correct utility accounts are connected, and the legacy account is disconnected.
- Click your name at the top right of the ContactMonkey dashboard
- Select Settings → Integrations
- Confirm the Graph Utility Account tile is signed in, if your organization uses Graph expansion
- Confirm the Exchange Admin Utility Account tile is signed in
- Confirm the EWS Utility Account tile is signed out or removed altogether

Next, confirm expansion still resolves correctly:
- Click Show Details on each connected tile
- Enter one or more distribution list email addresses in the Distribution List field, separated by commas
- Click Test Count
- Check the emailed results against the number of recipients you expect
A recipient count that matches your expected number confirms that tile's migration is complete.
Verify your enterprise apps in Microsoft Entra ID (IT Admin)
Confirm the new enterprise apps and scopes exist, and the legacy app has been removed.
- Open the Entra Admin Center
- Click Enterprise applications
- Open ContactMonkey-Utility and confirm
GroupMember.Read.Allappears under Permissions - Open ContactMonkey - Exchange Online Admin API and confirm
Exchange.ManageV2appears under Permissions - Confirm ContactMonkey EWS-Utility no longer appears in the list


Then confirm the Exchange role assignment:
- Open the Exchange Admin Center
- Navigate to Roles → Admin roles
- Select View-Only Organization Management
- Click the Assigned tab and confirm the service account is listed
View-Only Organization Management is a read-only role. It allows ContactMonkey to see mailbox and group memberships, but does not permit ContactMonkey to modify settings, delete data, or read email content.
Troubleshooting
Problem: A utility account tile shows as Inactive.
Solution: OAuth tokens expire when they go unused. Run a Test Count to reactivate the account. If the tile stays inactive, sign out of the tile and sign back in. See Troubleshooting Distribution List Expansion for details.
Problem: Test Count returns a number that does not match expectations.
Solution: The migration may be complete while the distribution list itself is unsupported. On-premise lists are often not supported. See Troubleshooting Distribution List Expansion for diagnostic steps.
Problem: The Graph Utility Account tile is signed in, but ContactMonkey Support has not confirmed the Directory.Read.All removal.
Solution: The Graph migration is not complete. Email support@contactmonkey.com to confirm the legacy permission has been disabled, then sign out of the Graph Utility Account tile and sign back in with the same credentials.
Problem: Deleting ContactMonkey EWS-Utility in Entra is blocked or raises concerns about breaking expansion.
Solution: Run a successful Test Count on the Exchange Admin Utility Account tile first. Once that count is accurate, expansion no longer depends on the EWS app, and the app can be deleted safely.