Exchange Mailbox (EWS)
Use the Exchange Mailbox (EWS) source to crawl and classify content stored in a single Exchange mailbox on an on-premises Exchange server or in Exchange Online, using Exchange Web Services (EWS). Microsoft is deprecating EWS for Exchange Online and will fully disable it in April 2027. Netwrix recommends using Exchange Mailbox (Graph) for any new sources intended to crawl Exchange Online mailboxes.
Step 1 – In Netwrix Data Classification management console, open the Sources view and click Add.
Step 2 – Select the Exchange Mailbox (EWS) source type and in the properties window specify the necessary settings.
Authentication type: Modern authentication
If you plan to use this authentication type (available only for Exchange Online mailbox processing), specify the following:
| Option | Description |
|---|---|
| Authentication type | Select Modern (O365) |
| Admin Username | Specify the administrative account for the required Exchange Online organization. The user must have a mailbox connected to it to crawl Exchange. |
| Tenant ID | Enter the Tenant ID you obtained at Step 5: Obtain Tenant ID. |
| Certificate thumbprint | Enter the certificate thumbprint you prepared at Step 4: Configure Certificates & secrets. |
| Application ID | Enter the app ID you got at application registration at Step 2: Create and Register a new app in Azure AD (you can find it in the Azure AD app properties >Overview). |
Authentication type: Basic
To use this authentication type, specify the following:
| Option | Description | Comments |
|---|---|---|
| Email Address / Password | An Administrator account with both: 1. Impersonation right 2. Discovery Management role | See Configure Microsoft Exchange for Crawling and Classification for details on the rights assignment. |
Other configuration settings
By default, only basic settings appear. To view advanced options, click the "wrench" icon at Settings in the bottom.
| Option | Description | Comments |
|---|---|---|
| Basic settings | ||
| Mailbox | The mailbox to crawl. | When you use impersonation, the settings can be like the following example:
|
| Crawl Range | Define the time period to crawl:
| |
| Crawl In-Place Archive | Select this option if you want to crawl Exchange Online in-place archive mailboxes. | Applies to Exchange Online. |
| OCR Processing Mode | Set the processing mode for document images:
| The Enhanced mode will provide better accuracy but can lead to longer processing time if the images don't contain text. |
| Source Group | Select the source group to add this source to. If no source groups exist, the product automatically creates one named after the source. | |
| Pause source on creation | Select if you want to make other configuration changes before data collection occurs. | |
| Advanced settings | ||
| Build Search Index | Select to create a search index. | |
| Re-Index Period | Specify how often to check the source for changes. Default is 7 days. | Netwrix recommends using default values. |
| Priority | Set the crawl priority for this data source. Select the priority level from the list values:
| |
| Document Type | Specify a value to restrict queries when using the Netwrix Data Classification search index. |