MC1462915: Microsoft 365 Copilot Redirects to copilot.cloud.microsoft—Ensure Network Access Before Transition

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
67
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Tenant AdminsMicrosoft 365 AdminsSecurity TeamsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
The redirect to copilot.cloud.microsoft begins in September and completes in October, with blocking network controls preventing Copilot access if not addressed. Admin tasks include reviewing and updating firewall, proxy, URL filtering, and conditional access controls, plus coordinating with security teams. User experience is at risk if these updates are missed, as Copilot will fail to load. Urgency and effort are elevated due to fixed timelines, potential service disruption, and mandatory configuration changes across network environments.
72
🛡️ Admin Impact
40
👥 User Impact
78
Urgency
65
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Copilot web app traffic will move from m365.cloud.microsoft to copilot.cloud.microsoft. Check your network settings now or users may lose access when redirects start.
👥

END USERS

Users may lose access if copilot.cloud.microsoft is blocked.
🛡️

IT ADMINS

Review firewall, proxy, and filtering rules to ensure copilot.cloud.microsoft and *.cloud.microsoft are allowed before redirects.
📅

ROLLOUT TIMELINE

Start:
September 2026

📢 Official Microsoft Message Center Announcement


Allow connections to copilot.cloud.microsoft before the Copilot URL redirect
Message ID: MC1462915 (Updated)

[What and why:]

As communicated in MC1454108, beginning in early September, 2026, Microsoft will start redirecting users from m365.cloud.microsoft to copilot.cloud.microsoft in organizations where access to copilot.cloud.microsoft is available. Organizations who may have blocked connection to copilot.cloud.microsoft will be redirected in October. To avoid disruption to Copilot access, review your organization’s network and security controls to confirm that users can connect to copilot.cloud.microsoft.   

[Rollout schedule:]

  • In early September, 2026, Microsoft will redirect users from m365.cloud.microsoft to copilot.cloud.microsoft in organizations where access to copilot.cloud.microsoft is available.  
  • In early October, 2026 Microsoft will redirect the remaining users who had not been redirected in early September. If your organization cannot complete the required configuration before the redirect, contact your Microsoft account representative to discuss available options. 

[Impact on your organization:]

When the Copilot web app transitions from m365.cloud.microsoft to copilot.cloud.microsoft, users will be automatically redirected. If device, network, proxy, firewall, security gateway, or similar controls block or interfere with the new URL, affected users may be unable to use the Copilot web app. Review these controls and allow the required domain before the redirect begins. 

The redirect remains within the *.cloud.microsoft domain and retains its security, compliance, and enterprise allow-listing properties. Organizations that follow the recommendednetwork configurations for Microsoft 365 Copilot do not need additional network changes. 

[Action required / Recommendations:]

  • You can validate connectivity to the *.cloud.microsoft domain by using the Microsoft 365 Connectivity Test tool. Use the connectivity tool to validate connectivity to copilot.cloud.microsoft and confirm that your network and security controls allow access before the redirect applies to your organization. If you find out your organization blocks connection to copilot.cloud.microsoft, contact your Microsoft account representative before September 10, 2026 to discuss available options.
  • Confirm that copilot.cloud.microsoft is not blocked in your environment. Review legacy filtering rules, URL category restrictions, proxy policies, firewall rules, tenant restrictions, Conditional Access policies, and app control policies, and update them if needed. 
  • Add *.cloud.microsoft to your organization’s allow lists. If you have questions about tenant-specific network configurations and allow list requirements, you can contact your Microsoft support team for guidance based on your specific environment. Note: Microsoft does not support allowing partial or only selected Microsoft 365 application URLs within the *.cloud.microsoft domain. Allow the entire *.cloud.microsoft domain to maintain service reliability and avoid disruptions. 
  • Confirm that your environment aligns with the recommended network requirements for Microsoft 365 Copilot
  • Coordinate with teams that manage network security, proxy services, firewalls, secure web gateways, SSE/SASE platforms, or third-party filtering solutions to ensure traffic to *.cloud.microsoft is permitted. 
  • If preventing personal Microsoft account sign-ins is the reason your organization blocks copilot.cloud.microsoft, consider using TenantRestrictions as the targeted control. This control allows your organization to restrict authentication with personal Microsoft accounts on managed networks or devices, while still permitting access to the Copilot service URL. 

Source: Microsoft Message Center • Analysed by MWPro

<<< [MC1462915] Archive
Tooltip: View earlier revisions of this post

Share This Update