Microsoft 365 Message Center item MC1462915
MC1462915 - Allow connections to copilot.cloud.microsoft before the Copilot URL redirect
Starting September 2026, Microsoft will redirect users from m365.cloud.microsoft to copilot.cloud.microsoft. Organizations must ensure network and security controls allow access to copilot.cloud.microsoft to avoid service disruption. Review and update firewall, proxy, and allow lists to permit *.cloud.microsoft traffic before October 2026.
- Message Center ID
- MC1462915
- Category
- plan For Change
- Severity
- normal
- Services
- Microsoft Copilot (Microsoft 365), Microsoft 365 Copilot Chat
- Tags
- Admin impact
- Published
- 2026-08-27
- Last updated
- 2026-08-27
- Expires
- 2026-12-14
[What and why:]As communicated in MC1454108, beginning in early September, 2026, Microsoft will start redirecting users from m365.cloud.microsoft to copilot.cloud.microsoft in organizations where access to copilot.cloud.microsoft is available. Organizations who may have blocked connection to copilot.cloud.microsoft will be redirected in October. To avoid disruption to Copilot access, review your organization's network and security controls to confirm that users can connect to copilot.cloud.microsoft. [Rollout schedule:]In early September, 2026, Microsoft will redirect users from m365.cloud.microsoft to copilot.cloud.microsoft in organizations where access to copilot.cloud.microsoft is available. In early October, 2026 Microsoft will redirect the remaining users who had not been redirected in early September. If your organization cannot complete the required configuration before the redirect, contact your Microsoft account representative to discuss available options. [Impact on your organization:]When the Copilot web app transitions from m365.cloud.microsoft to copilot.cloud.microsoft, users will be automatically redirected. If device, network, proxy, firewall, security gateway, or similar controls block or interfere with the new URL, affected users may be unable to use the Copilot web app. Review these controls and allow the required domain before the redirect begins. The redirect remains within the *.cloud.microsoft domain and retains its security, compliance, and enterprise allow-listing properties. Organizations that follow the recommendednetwork configurations for Microsoft 365 Copilot do not need additional network changes. [Action required / Recommendations:]You can validate connectivity to the *.cloud.microsoft domain by using the Microsoft 365 Connectivity Test tool. Use the connectivity tool to validate connectivity to copilot.cloud.microsoft and confirm that your network and security controls allow access before the redirect applies to your organization. If you find out your organization blocks connection to copilot.cloud.microsoft, contact your Microsoft account representative before September 10, 2026 to discuss available options.Confirm that copilot.cloud.microsoft is not blocked in your environment. Review legacy filtering rules, URL category restrictions, proxy policies, firewall rules, tenant restrictions, Conditional Access policies, and app control policies, and update them if needed. Add *.cloud.microsoft to your organization’s allow lists. If you have questions about tenant-specific network configurations and allow list requirements, you can contact your Microsoft support team for guidance based on your specific environment. Note: Microsoft does not support allowing partial or only selected Microsoft 365 application URLs within the *.cloud.microsoft domain. Allow the entire *.cloud.microsoft domain to maintain service reliability and avoid disruptions. Confirm that your environment aligns with the recommended network requirements for Microsoft 365 Copilot. Coordinate with teams that manage network security, proxy services, firewalls, secure web gateways, SSE/SASE platforms, or third-party filtering solutions to ensure traffic to *.cloud.microsoft is permitted. If preventing personal Microsoft account sign-ins is the reason your organization blocks copilot.cloud.microsoft, consider using TenantRestrictions as the targeted control. This control allows your organization to restrict authentication with personal Microsoft accounts on managed networks or devices, while still permitting access to the Copilot service URL.