During target mailbox validation, the following error may appear:
"Invalid target email address ****: EWS API client error occurred (forbidden). Forbidden."
The issue can occur despite all required consents being properly configured and functioning successfully in other target tenants. Regranting the consents does not resolve the issue.
The issue occurs when Exchange Web Services (EWS) is disabled in the target Microsoft 365 tenant. When EWS access is unavailable, mailbox validation requests are rejected with a forbidden error.
Verify the EWS status in the target tenant and ensure that EWS is enabled.
Once EWS is enabled, target mailbox validation should complete successfully.