Who decides on Microsoft 365 shutdowns when there is no IT department?
From 1 October 2026 Microsoft blocks access via Exchange Web Services in tenants without their own allow list. Companies without an IT department need a named owner for deadlines like this and a list of the applications affected.
Management does, and it needs one person who reads Microsoft’s announcements and turns them into a list of the applications affected. Expert knowledge of Exchange is not part of that role. What is part of it is the authority to commission a service provider before a deadline passes.
The current case is 1 October 2026. On that day Microsoft starts switching off access via Exchange Web Services in Microsoft 365. What is affected is not people but programs: archiving, backup, migration tools, room booking, calendar synchronisation from the CRM, fax gateways and older scripts. Exchange in your own server room is untouched.
This article explains what happens on that date, who makes the call in a company without an IT department, and how a reliable list of affected applications comes about.
What happens to Exchange Web Services on 1 October 2026?
Microsoft switches off tenant by tenant from that day. Anyone who filed an allow list for the permitted applications by the end of August 2026 and explicitly enabled access is exempt from the automatic shutdown. For every other tenant, Microsoft has been building a list itself since September, based on usage over the previous 60 days. Access is switched off permanently for everyone on 1 April 2027.
The deadline for filing your own list has therefore passed. That is not a reason to rush, it is a reason to check: the list Microsoft generates is a snapshot of the business, not the truth about it.
Why the automatically generated list is misleading
It only sees what ran in the 60 days before. Anything that runs less often is missing. The year-end export, the quarterly archiving run, the tool that once a year secures the mailbox of a departed colleague, the migration that was planned for the summer and postponed.
For a company with 80 employees that is usually two to four applications. They do not fail on 1 October, they fail on the day they are next due to run, and that can be 31 December. If nobody has been named by then, the search for the cause happens during the year-end close.
The second flaw in the automatic list points the other way. It picks up everything that had access, including the tool from a finished project and the account of a service provider nobody needs any more. An inherited list is not a clean-up.
Who makes this decision when there is no IT department?
Management carries it and delegates the day-to-day handling to a named person with three things: access to the Microsoft messages in the admin centre, an overview of the programs in use, and the right to commission a service provider. In companies between 20 and 500 employees this role usually sits with the commercial lead or with whoever coordinates data protection.
What goes wrong in practice is rarely the technology. It is the question of who read the message at all. Microsoft announces changes like this in the message centre of the admin centre, and in many companies without an IT department that inbox belongs to nobody. Where an owner for AI tools has already been named, this task belongs there too. How to cut that role is covered in Who is responsible for AI when there is no IT department.
How does the list of affected applications come about?
Through the question of which program accesses mailboxes or calendars without a person at the keyboard. Finance, the assistants and sales answer that better than any report, because they know their own tools.
Four questions are enough for a first pass:
- Which tool backs up or archives our email, and who set it up?
- Does another system write appointments into Outlook, such as the CRM, time tracking or room booking?
- Is there a migration or an export running somewhere that is only triggered occasionally?
- Which service provider has technical access to our mailboxes, and which project does that access date back to?
The answers become a table with application, responsible area, vendor and contact. That table is the real value of the exercise, because it outlives October. At the next deadline it is already there.
The technical reconciliation with the provider who looks after the tenant comes afterwards. They check what Microsoft wrote into the list and compare it against the table. Only at that point is Exchange knowledge needed, and it can be bought in.
What does it cost not to do this?
The bill is not in the Microsoft announcement. It arrives on the day a process that depends on a deadline fails. An archiving tool that stops in December costs the time to find the cause, the time to switch, and in the bad case a gap in retention.
The effort for the other route is half a day inside the business for the four questions plus a short meeting with the service provider. That is the cheapest option this deadline offers.
Conclusion
1 October is not the problem. The problem is a tenant nobody owns, because then Microsoft decides on the basis of 60 days of usage data which programs may keep working. For a company without an IT department that decision is repairable, as long as somebody reviews the list.
To get started, put the four questions above on the agenda of the next management meeting and write the answers into a table. If it remains unclear which programs technically access the mailboxes, that is the point for a conversation with the provider who looks after the tenant. Where else an inventory like this uncovers gaps is what the Digital Check is for.