Microsoft has announced that the Application Impersonation role in Exchange Online will be retired in February 2025. This role has traditionally been used for migration tools to access mailboxes during Exchange migrations. Customers using Quest ODM have expressed concerns about the potential impact of this change on their ongoing or upcoming migrations.
The Application Impersonation role will no longer be assignable or usable in Exchange Online as part of Microsoft's efforts to streamline and secure permissions.
Quest ODM is unaffected by the retirement of the Application Impersonation role.
Permissions Used by ODM:
full_access_as_app permission, which provides application-level access to all mailboxes within a customer’s organization.Support from Microsoft:
full_access_as_app permission is supported through Microsoft’s Application Access Policy for Exchange Web Services (EWS).Testing and Validation:
Customers can proceed with their migration projects without the need for any changes related to the retirement of this role.