We are sorry for the disruption. Yes, the update changed how Aqua Mail connects to Microsoft 365 accounts.

 

Previously, Aqua Mail used EWS for many Microsoft 365 accounts. Microsoft is removing/retiring the old EWS access method for Exchange Online in favor of Microsoft Graph this year, so Aqua Mail has to move to Graph to remain compatible with Microsoft 365.

 

Because of this change, Microsoft now sees Aqua Mail as needing Graph permissions for your organization. If your tenant is configured to require admin approval for third-party apps, Microsoft will block the sign-in and show “Administrator approval required.”

 

This approval cannot be bypassed by Aqua Mail. It is enforced by Microsoft’s tenant security policy.

 

The authentication process and permissions changed because Aqua Mail now uses Microsoft Graph instead of the old EWS method.

 

This is affecting Microsoft 365 organizational accounts where admin consent is required for third-party apps.

 

There is currently no corrected update or workaround that avoids Microsoft admin approval. The Microsoft 365 admin must approve Aqua Mail for Graph access, either for the organization or according to your company’s approval process.

 

Your admin does not necessarily need to weaken security globally. They can review the requested Aqua Mail permissions in Microsoft Entra/Azure and approve only this app if they are comfortable with it.

 

I understand the account worked for years, but the change is due to Microsoft’s protocol transition. Aqua Mail must comply with Microsoft’s current authentication requirements.