Skip to main content

Exchange Server (EWS)

Use the Exchange Server (EWS) source configuration screen to crawl and classify multiple Exchange mailboxes from the same Exchange server, using the Exchange Web Services (EWS). "Microsoft is deprecating EWS for Exchange Online and will fully disable it in April 2027. Netwrix recommends using Exchange Server (Graph) for any new sources intended to crawl Exchange Online.

note

Automatic detection, crawling, and classification of multiple Exchange mailboxes from the same Exchange server—and therefore the Exchange Server (EWS) content source—works only with Exchange Server 2013 or later, due to limitations in the Microsoft APIs. For earlier versions, consider using the Exchange Mailbox (EWS) content source.

You can use Match Rules to include or exclude specific mailboxes.

To configure an Exchange Server (EWS) source, follow these steps.

Step 1 – In Netwrix Data Classification management console, open the Sources view and click Add.

Step 2 – Select the Exchange Server (EWS) source type and in the properties window specify the necessary settings.

Step 3 – To display all settings, click the "wrench" icon next to Settings in the bottom-left corner.

Authentication type: Modern authentication​

If you plan to use this authentication type, specify the following:

OptionDescription
Authentication typeSelect Modern (O365)
Admin UsernameSpecify the administrative account for the required Exchange Online organization. The user must have a mailbox connected to it to crawl Exchange.
Tenant IDEnter the Tenant ID you obtained at Step 5: Obtain Tenant ID.
Certificate thumbprintEnter the certificate thumbprint you prepared at Step 4: Configure Certificates & secrets.
Application IDEnter the app ID you got at application registration at Step 2: Create and Register a new app in Azure AD (you can find it in the Azure AD app properties >Overview).

Authentication type: Basic​

note

For Email Address / Password, use an Administrator account that has the Discovery Management role and the Mailbox Search and MailboxSearchApplication permissions.

To use this authentication type, specify the following:

OptionDescription
Email Address / PasswordAdministrator account with the Impersonation right and the Discovery Management role. See Configure Microsoft Exchange for Crawling and Classification for details on the rights assignment.

Other configuration settings​

Both authentication types also require the following settings:

OptionDescription
Exchange API URLBy default, the crawling engine uses the Exchange AutoDiscover functionality to locate the Exchange Web Services API URL, so you can typically leave this field blank. If Exchange AutoDiscover isn't available, specify the Exchange API URL explicitly: https://<servername>/EWS/Exchange.asmx.
Crawl RangeDefine which portions of data to retrieve from the Exchange server:
  • Select Date Range to crawl a static set of data within the required interval.
  • Select Since if you want to periodically re-crawl content from the specified date, taking into account the last crawl date for each artifact.
Match RulesDefine rules with regular expressions to limit which mailboxes the product crawls. You must define at least one match rule. Examples: 1. .*@netwrix.com— enter the wildcard (*) and the domain (here netwrix.com) to restrict crawling to a set of domain mailboxes 2. .*—enter to crawl all mailboxes
Detection PeriodSpecify how often to check the source for changes. Default period is 1 day.

After specifying all the necessary settings, click Save.