What and why:
As communicated in MC1454108, beginning in early September, 2026, Microsoft will start redirecting users from m365.cloud.microsoft to copilot.cloud.microsoft in organizations where access to copilot.cloud.microsoft is available. Organizations who may have blocked connection to copilot.cloud.microsoft will be redirected in October. To avoid disruption to Copilot access, review your organization's network and security controls to confirm that users can connect to copilot.cloud.microsoft.
Rollout schedule:
- In early September, 2026, Microsoft will redirect users from m365.cloud.microsoft to copilot.cloud.microsoft in organizations where access to copilot.cloud.microsoft is available.
- In early October, 2026 Microsoft will redirect the remaining users who had not been redirected in early September. If your organization cannot complete the required configuration before the redirect, contact your Microsoft account representative to discuss available options.
Impact on your organization:
When the Copilot web app transitions from
m365.cloud.microsoft to copilot.cloud.microsoft, users will be automatically
redirected. If device, network, proxy, firewall, security gateway, or similar
controls block or interfere with the new URL, affected users may be unable to
use the Copilot web app. Review these controls and allow the required domain
before the redirect begins.
The redirect remains within the *.cloud.microsoft domain and
retains its security, compliance, and enterprise allow-listing properties.
Organizations that follow the recommendednetwork configurations for Microsoft 365 Copilot do not need additional
network changes.
Action required / Recommendations:
- You can validate connectivity to the *.cloud.microsoft domain by using the Microsoft 365 Connectivity Test tool. Use the connectivity tool to validate connectivity to copilot.cloud.microsoft and confirm that your network and security controls allow access before the redirect applies to your organization. If you find out your organization blocks connection to copilot.cloud.microsoft, contact your Microsoft account representative before September 10, 2026 to discuss available options.
- Confirm
that copilot.cloud.microsoft is not blocked in your environment. Review legacy
filtering rules, URL category restrictions, proxy policies, firewall rules,
tenant restrictions, Conditional Access policies, and app control policies, and
update them if needed.
- Add
*.cloud.microsoft to your organization’s allow lists. If you have questions
about tenant-specific network configurations and allow list requirements, you
can contact your Microsoft support team for guidance based on your specific
environment. Note: Microsoft does not support allowing partial or only selected
Microsoft 365 application URLs within the *.cloud.microsoft domain. Allow the
entire *.cloud.microsoft domain to maintain service reliability and avoid
disruptions.
- Confirm
that your environment aligns with the recommended network requirements for Microsoft 365 Copilot.
- Coordinate
with teams that manage network security, proxy services, firewalls, secure
web gateways, SSE/SASE platforms, or third-party filtering solutions to
ensure traffic to *.cloud.microsoft is permitted.
- If preventing personal Microsoft account
sign-ins is the reason your organization blocks copilot.cloud.microsoft,
consider using TenantRestrictions as the targeted control. This control allows your organization
to restrict authentication with personal Microsoft accounts on managed networks
or devices, while still permitting access to the Copilot service URL.