[Introduction]
We’re updating the API endpoints used by Microsoft 365 Copilot to align with Microsoft’s ongoing transition to the cloud.microsoft domain. This change improves service reliability and security by ensuring Copilot-connected workloads use modernized Microsoft 365 network endpoints.
This update is part of a previously announced Microsoft domain unification initiative across Microsoft 365 services. This update does not introduce changes to the Microsoft 365 Copilot user interface and will not impact user experience, provided your environment follows published Microsoft 365 and Copilot network configuration requirements.
[When this will happen:]
General Availability (Worldwide, GCC): Rollout will begin in late April 2026 and is expected to complete by late April 2026.
[How this affects your organization:]
Who is affected:
- Microsoft 365 administrators managing network configurations for Microsoft 365 and Microsoft 365 Copilot
- Organizations using custom firewall, proxy, or endpoint filtering configurations within their tenant environment that restrict or interfere with WebSocket (WSS) connections
What will happen:
- APIs used by Microsoft 365 Copilot will transition from the legacy office.com domain to the cloud.microsoft domain.
- This change occurs at the service infrastructure level and is not visible to users.
- No changes to the Microsoft 365 Copilot user interface or workflows are expected.
- The change is enabled by default and cannot be disabled
- If your organization has followed previously published Microsoft 365 and Microsoft 365 Copilot network connectivity requirements:
- No action is required
- No service impact is expected
- Organizations that restrict access to the cloud.microsoft domain or restrict WSS connectivity may experience Microsoft 365 Copilot performance or reliability issues
[What you can do to prepare:]
- Confirm that traffic to *.cloud.microsoft is included in your Microsoft 365 endpoint allow list.
- Verify that WSS connections to *.cloud.microsoft destinations are not blocked or interfered with.
- Exempt traffic to *.cloud.microsoft from intrusive network actions such as:
- TLS decryption
- Packet inspection
- Network-level DLP
- Review Microsoft 365 network connectivity guidance:
- Communicate this change to your networking and helpdesk teams.
- Run the Microsoft 365 Copilot Network Connectivity Test: Microsoft 365 Copilot Network Connectivity Test.
[Compliance considerations:]
No compliance considerations identified, review as appropriate for your organization.
Source: Microsoft
Latest Posts
- MC1462425: Microsoft 365 Apps Releases Current Channel Update for August 2026

- MC1309743: Viva Engage Stops Email Notifications for Users Without Valid Mailboxes

- AWS Backup adds cross-Region backup copy and logically air-gapped vault support for Amazon DocumentDB in nine additional AWS Regions

- AWS Glue now supports catalog federation for remote Apache Iceberg catalogs in AWS GovCloud (US) regions







