Microsoft Rolls Back Domain Exclusion for Microsoft 365 Copilot

The decision leaves IT admins waiting for clarity on future controls over external sources used in Copilot responses.

Hero approved Microsoft 365

Key Takeaways:

  • Microsoft has withdrawn Domain Exclusion for Microsoft 365 Copilot shortly after introducing it.
  • The feature was designed to let organizations exclude specific websites from influencing web-grounded responses.
  • Some IT administrators argued that an allow-list model would be more effective than the original blocklist approach.

Microsoft has pulled the plug on Domain Exclusion for Microsoft 365 Copilot just days after introducing the feature to give organizations greater control over web-grounded AI responses. This rollback highlights the growing challenges of balancing Copilot’s access to external information with the security, reliability, and governance demands of enterprise customers.

Last month, Microsoft announced Domain Exclusion for Microsoft 365 Copilot. This feature was intended to give organizations more control over the external websites that could influence Copilot’s web-grounded responses. When Copilot searched the public web to supplement its answers, administrators could specify domains to exclude, which helped ensure that AI-generated content was less likely to rely on sources that conflicted with the organization’s policies, compliance requirements, or trust standards.

The idea behind Domain Exclusion was to provide a middle ground between allowing unrestricted web access and disabling web grounding completely. Microsoft positioned this capability as part of its broader effort to help businesses adopt AI with stronger governance and oversight.

Why did Microsoft pull the Copilot web-grounding control?

Microsoft has rolled back Domain Exclusion only days after promoting it as a new control for IT administrators. The company didn’t provide a detailed explanation for the withdrawal, and said that it was evaluating future options and recognizing the importance of the capability.

“We want to inform the community that the Domain Exclusion for Microsoft 365 Copilot feature described in this post, More control over web grounding with Domain Exclusion for Microsoft 365 Copilot, has been rolled back at this time. We understand the importance of this capability and are actively evaluating next steps. We will share additional updates with the community as soon as more information becomes available,” Microsoft explained.

Blocklist approach drew criticism from IT administrators

The Domain Exclusion feature received mixed reactions from IT administrators. Many welcomed the added control over the external sources Microsoft 365 Copilot could use when generating responses. However, others criticized its blocklist-based approach, which required organizations to identify and maintain a list of domains they wanted Copilot to avoid. They argued that an allow-list model would be more effective, which would limit the AI assistant to information from a predefined set of trusted websites.

Microsoft’s decision to roll back the feature has created additional uncertainty for customers. Administrators who saw Domain Exclusion as a valuable governance control are now waiting for further clarification, while critics of the original design view the rollback as an opportunity for Microsoft to rethink the feature and explore alternatives, such as allow-listing trusted domains.