Aug 6, 2026
Policy

Microsoft 365 Copilot Domain Exclusion rolled back a week after launch

Microsoft withdrew its new Copilot web-source blocklist without explaining why, leaving IT teams without the promised governance control.

Renata Fuchs

By Renata Fuchs · Policy Reporter

· 2 min read

Microsoft 365 Copilot Domain Exclusion rolled back a week after launch
Photo: The Register

Microsoft has rolled back Microsoft 365 Copilot Domain Exclusion, an administrator control announced July 28 that was intended to prevent Copilot from using specified public websites in web-grounded answers. In an August 4 update, Microsoft gave no reason for withdrawing the feature or date for its return, saying only that it was evaluating what to do next.

The reversal removes a short-lived option for organizations trying to limit the external sources that can shape responses from Microsoft 365 Copilot and Copilot Chat. Microsoft had positioned the control around policy, compliance and source-governance requirements, but did not disclose how widely the feature had been deployed before it was rolled back.

What did Microsoft 365 Copilot Domain Exclusion do?

Domain Exclusion was an opt-in blocklist for Copilot web grounding, the process by which the assistant can draw on current public-web information when producing an answer. Administrators could list external domains that Copilot should exclude from those web-grounded responses.

The announced design supported up to 1,000 domains per organization. It was not enabled by default: a Search Administrator or Global Administrator had to use a PowerShell script and a CSV file to create, change, export or delete the list. The capability was therefore a tenant-level administrative setting, rather than a user-level preference.

Microsoft's technical documentation also described an important limit: exclusions applied to web-page results, while other answer categories, including news, could still be cited. Domain Exclusion was not an approved-sources system that confined Copilot to a defined set of trusted sites.

What administrators should do now

The dated rollback notice is the current status. Microsoft said Domain Exclusion “has been rolled back at this time” and promised further updates when it has more information. Organizations should not treat the continuing presence of setup instructions in Microsoft Learn as confirmation that the feature remains deployable; the documentation excerpt does not show an update date and does not override Microsoft's August 4 announcement.

The gap matters for teams that have enabled public-web grounding while seeking a narrower control than disabling web access altogether. Source restrictions are one component of an enterprise security program, alongside the policies and operating processes that govern how employees use AI systems.

Third-party coverage noted criticism of the blocklist model, which requires administrators to identify sites to bar, and of the 1,000-domain ceiling. An allowlist would instead limit Copilot to sites an organization selects. Microsoft has not said that customer feedback, a technical issue, or any other factor led to the rollback, and it has not committed to restoring the control in either form.

This story draws on original reporting from The Register.

More from Policy

All Policy →