Skip to main content

Exchange Mailbox (EWS)

Use the Exchange Mailbox (EWS) source to crawl and classify content stored in a single Exchange mailbox on an on-premises Exchange server or in Exchange Online, using Exchange Web Services (EWS). Microsoft is deprecating EWS for Exchange Online and will fully disable it in April 2027. Netwrix recommends using Exchange Mailbox (Graph) for any new sources intended to crawl Exchange Online mailboxes.

Step 1 – In Netwrix Data Classification management console, open the Sources view and click Add.

Step 2 – Select the Exchange Mailbox (EWS) source type and in the properties window specify the necessary settings.

Authentication type: Modern authentication​

If you plan to use this authentication type (available only for Exchange Online mailbox processing), specify the following:

OptionDescription
Authentication typeSelect Modern (O365)
Admin UsernameSpecify the administrative account for the required Exchange Online organization. The user must have a mailbox connected to it to crawl Exchange.
Tenant IDEnter the Tenant ID you obtained at Step 5: Obtain Tenant ID.
Certificate thumbprintEnter the certificate thumbprint you prepared at Step 4: Configure Certificates & secrets.
Application IDEnter the app ID you got at application registration at Step 2: Create and Register a new app in Azure AD (you can find it in the Azure AD app properties >Overview).

Authentication type: Basic​

To use this authentication type, specify the following:

OptionDescriptionComments
Email Address / PasswordAn Administrator account with both: 1. Impersonation right 2. Discovery Management roleSee Configure Microsoft Exchange for Crawling and Classification for details on the rights assignment.

Other configuration settings​

By default, only basic settings appear. To view advanced options, click the "wrench" icon at Settings in the bottom.

OptionDescriptionComments
Basic settings
MailboxThe mailbox to crawl.When you use impersonation, the settings can be like the following example:
Crawl RangeDefine the time period to crawl:
  • Select Date Range to crawl a static set of data within the specified interval.
  • Select Since if you want to periodically re-crawl content from the specified date onwards, taking into account the last crawl date for each object.
Crawl In-Place ArchiveSelect this option if you want to crawl Exchange Online in-place archive mailboxes.Applies to Exchange Online.
OCR Processing ModeSet the processing mode for document images:
  • Disabled
  • skip processing document images
  • Default
  • defaults to the global setting
  • Normal
  • process the images with normal quality settings
  • Enhanced
  • upscale the images further to allow more accurate results.
The Enhanced mode will provide better accuracy but can lead to longer processing time if the images don't contain text.
Source GroupSelect the source group to add this source to. If no source groups exist, the product automatically creates one named after the source.
Pause source on creationSelect if you want to make other configuration changes before data collection occurs.
Advanced settings
Build Search IndexSelect to create a search index.
Re-Index PeriodSpecify how often to check the source for changes. Default is 7 days.Netwrix recommends using default values.
PrioritySet the crawl priority for this data source. Select the priority level from the list values:
  • Highest
  • High
  • Normal
  • Low
  • Lowest
Document TypeSpecify a value to restrict queries when using the Netwrix Data Classification search index.