MC1286300 Low
Microsoft 365 Copilot transition to the cloud.microsoft domain
Summary AI-generated
Microsoft 365 Copilot APIs will use cloud.microsoft domain instead of office.com for improved security/reliability; orgs must allow network access to *.cloud.microsoft by late April 2026.
Suggested actions AI-generated
- Add *.cloud.microsoft to endpoint allow list
- Ensure WSS connections to *.cloud.microsoft are allowed
- Exclude *.cloud.microsoft from TLS decryption/inspection/DLP
- Communicate changes to networking/helpdesk teams
- Run Copilot network connectivity test
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1462915 (Updated) Allow connections to copilot.cloud.microsoft before the Copilot URL redirect
- MC1162275 Product transitions to the cloud.microsoft domain – September 2025
- MC1456610 (Updated) Microsoft 365 Copilot Chat: Updated commercial Copilot endpoint for Microsoft Edge
- MC1454108 (Updated) Microsoft 365 Copilot app update: Simpler Copilot access
- MC1465764 Teams web client users will be redirected to teams.cloud.microsoft
- MC1392563 (Updated) OneDrive transitions to the cloud.microsoft domain
Original post from Microsoft
[Introduction]
We're updating the API endpoints used by Microsoft 365 Copilot to align with Microsoft’s ongoing transition to the cloud.microsoft domain. This change improves service reliability and security by ensuring Copilot-connected workloads use modernized Microsoft 365 network endpoints.
This update is part of a previously announced Microsoft domain unification initiative across Microsoft 365 services. This update does not introduce changes to the Microsoft 365 Copilot user interface and will not impact user experience, provided your environment follows published Microsoft 365 and Copilot network configuration requirements.
[When this will happen:]
General Availability (Worldwide, GCC): Rollout will begin in late April 2026 and is expected to complete by late April 2026.
[How this affects your organization:]
Who is affected:
- Microsoft 365 administrators managing network configurations for Microsoft 365 and Microsoft 365 Copilot
- Organizations using custom firewall, proxy, or endpoint filtering configurations within their tenant environment that restrict or interfere with WebSocket (WSS) connections
What will happen:
- APIs used by Microsoft 365 Copilot will transition from the legacy office.com domain to the cloud.microsoft domain.
- This change occurs at the service infrastructure level and is not visible to users.
- No changes to the Microsoft 365 Copilot user interface or workflows are expected.
- The change is enabled by default and cannot be disabled
- If your organization has followed previously published Microsoft 365 and Microsoft 365 Copilot network connectivity requirements:
- No action is required
- No service impact is expected
- Organizations that restrict access to the cloud.microsoft domain or restrict WSS connectivity may experience Microsoft 365 Copilot performance or reliability issues
[What you can do to prepare:]
- Confirm that traffic to *.cloud.microsoft is included in your Microsoft 365 endpoint allow list.
- Verify that WSS connections to *.cloud.microsoft destinations are not blocked or interfered with.
- Exempt traffic to *.cloud.microsoft from intrusive network actions such as:
- TLS decryption
- Packet inspection
- Network-level DLP
- Review Microsoft 365 network connectivity guidance:
- Communicate this change to your networking and helpdesk teams.
- Run the Microsoft 365 Copilot Network Connectivity Test: Microsoft 365 Copilot Network Connectivity Test.
[Compliance considerations:]
No compliance considerations identified, review as appropriate for your organization.
Additional details from Microsoft
- Summary
- Microsoft 365 Copilot APIs will transition from office.com to cloud.microsoft domain by late April 2026, improving reliability and security without UI changes. Admins must ensure network configurations allow *.cloud.microsoft traffic and WebSocket connections to avoid service issues. No compliance impacts expected.