Microsoft redirects Teams and Copilot traffic
Microsoft is moving Teams and M365 web users to new domains, forcing enterprises to update firewall rules and proxy configurations by early October.
Enterprise network teams are facing a configuration scramble after Microsoft confirmed it will redirect M365 and Teams web users to new destination addresses. The change affects two of the company's most widely used services, and any organization that fails to update its security controls could find users locked out of critical collaboration tools.
Starting this month, Microsoft will begin sending M365 and Teams web users to copilot.cloud.microsoft and teams.cloud.microsoft, respectively. The Teams transition is already underway, and the company has now added M365 to the list of affected services. The announcements came through two MessageCenter posts: MC1465764 and MC1462915.
Two services, two new addresses
The redirects apply to web users of Microsoft 365 and Teams. According to Microsoft's communications, the Teams move is already in progress, while the M365 change is being introduced alongside it. Both services will ultimately resolve to cloud.microsoft subdomains, a domain Microsoft has been steadily adopting for its cloud services.
For administrators, the practical effect is that existing allowlists and blocklists that reference older Teams and M365 endpoints may no longer match traffic destined for the new addresses. If those rules are not updated, users could be prevented from reaching the services even though their credentials and licenses remain valid.
Microsoft has advised organizations to review configurations on client devices, proxies, firewalls, secure web gateways, or other enterprise network controls to confirm that users can connect to the new addresses. The company also directed customers experiencing connection trouble to ensure their environment aligns with the recommended network requirements for Microsoft 365 Copilot.
Tenant restrictions replace blunt blocks
One point of friction for enterprises has been the Copilot address itself. Some organizations had been blocking the new Copilot domain to stop employees from accessing their personal Microsoft accounts on corporate networks. Microsoft has now offered an alternative: instead of blocking the address outright, administrators can use the company's TenantRestrictions control to achieve the same goal.
That approach allows enterprises to keep personal account access in check without cutting off legitimate access to Copilot for work. It is a more surgical method than a blanket domain block, which would have the side effect of disabling the service for all users, including those with valid corporate accounts.
Microsoft's guidance suggests the company expects network teams to treat the domain shift as a configuration update rather than a reason to maintain broad restrictions. Organizations that had relied on blocking the new Copilot address will need to migrate to TenantRestrictions to preserve their security posture while keeping the service available.
Deadline set for early October
All redirects should be completed by early October, Microsoft said. Companies that cannot meet that deadline are advised to contact their account representative for assistance.
For Teams specifically, Microsoft noted that limited exceptions to the redirect are possible until Dec. 31, 2026. After that date, no further delays will be possible, according to the company's MessageCenter posts. That extended window gives organizations with complex network architectures additional time to complete their updates, but it is not indefinite.
The two-stage timeline means administrators have a near-term deadline for the bulk of the work and a longer stopgap for edge cases. Even so, the message is clear: the old addresses are being retired, and network controls must be updated to match the new ones.
What administrators need to check
Microsoft's guidance points to several layers of enterprise infrastructure that may need attention. Client devices may have local firewall rules or application-level restrictions that reference the old domains. Proxies and secure web gateways often maintain their own allowlists, which may need to be expanded or modified.
Perimeter firewalls are another common point of failure. If an organization has pinned rules to specific IP ranges or domain names associated with Teams and M365, those rules will need to be revisited. The same applies to any documentation or runbooks that reference the previous addresses.
- Redirect completion deadline for all services: early October
- Limited exceptions for the Teams redirect available until Dec. 31, 2026
- Two MessageCenter posts announce the changes: MC1465764 and MC1462915
Organizations that use Microsoft's TenantRestrictions control can block personal Microsoft accounts without blocking the new Copilot address. That option is specifically aimed at enterprises that had been using domain blocks as a workaround.
For companies that find themselves unable to connect after the changes take effect, Microsoft's advice is to verify that the environment matches the recommended network requirements for Microsoft 365 Copilot. That documentation covers the network conditions Microsoft expects for Copilot to function correctly.
Why the domain change matters
Microsoft has been consolidating its service endpoints under the cloud.microsoft domain for some time, and these redirects are part of that broader effort. For end users, the change should be largely invisible if their organization's network is configured correctly. For administrators, it represents a mandatory maintenance task with a hard deadline.
The risk is not hypothetical. A firewall or proxy rule that was correct last month may silently block traffic to the new addresses, producing connection failures that look like service outages. Troubleshooting those failures can consume time and resources, especially if the root cause is not immediately obvious.
Enterprises that had blocked the Copilot address to prevent personal account access now face a choice: migrate to TenantRestrictions or risk disrupting legitimate Copilot usage. Microsoft's guidance makes clear that the TenantRestrictions control is the intended mechanism for that use case.
With the early October deadline approaching and the Teams exception window extending to the end of 2026, network teams have a defined period to audit their configurations. The work involves checking client devices, proxies, firewalls, secure web gateways, and any other controls that might reference the old destinations.
This article first appeared on Computerworld.
Sources
- CSO Online Original source
- MC1465764 Also reporting
- MC1462915 Also reporting
- recommended network requirements for Microsoft 365 Copilot Also reporting
- TenantRestrictions Also reporting
Continue Reading
Khosla Ventures Looks Beyond Sand Hill
The firm is opening its first office outside Menlo Park, on 14th Street in New York, with an unusual briefing center attached.
Roblox pushes AI game creation beyond its walls
Roblox expands its generative AI Build tool, adds creator payouts via Wallet, and plans to let games run outside the platform by year-end.
ARM Windows apps fixed after patch
Microsoft resolved a launch bug hitting Teams and Outlook on ARM-based Windows 11 devices with September's Patch Tuesday update.