Microsoft has restored Domain Exclusion for Copilot, the administrative feature that briefly disappeared during its rollout about a month ago. The return gives Microsoft 365 admins another way to control how web content flows into Copilot’s cloud processing.
The feature, which vanished during testing, is now back according to reporting by Neowin. For organizations that depend on granular data-governance controls, that’s a meaningful fix to a gap in their Copilot setup.
What Domain Exclusion for Copilot actually does
Domain Exclusion lets administrators specify particular web domains that should be kept out of Copilot’s data pipeline. When Copilot pulls information from the web during a session, content from excluded domains is not forwarded to Microsoft’s cloud for processing.
This is primarily a data-governance and privacy tool. If your organization handles sensitive information hosted on specific sites, excluding those domains ensures that data never leaves your tenant’s control for Copilot to analyze. It’s the kind of safeguard that matters most in regulated industries, where even the act of sending web content to a third party can trip compliance rules.
In practical terms, it works like a blocklist for web content. Rather than letting Copilot freely browse and process any page it encounters, admins can draw a hard line around certain sources. That distinction can be the difference between a routine research task and an unintended data exposure.
Why Microsoft pulled it in the first place
The feature briefly disappeared roughly a month ago as Microsoft worked through its rollout. Microsoft has not published an extensive explanation for the temporary removal, but features that vanish mid-rollout are typically pulled to address stability concerns, refine behavior, or correct configuration issues found during testing.
For admins who had begun planning around the feature, that gap meant a hole in their expected controls. Its return suggests Microsoft finished whatever work prompted the removal and is now comfortable making it available again.
The episode also highlights a broader pattern with Copilot’s rapid feature expansion. As Microsoft ships new capabilities at a fast pace, some controls get introduced, quietly adjusted, or temporarily withdrawn before they’re ready for widespread use. Admins managing a fleet have learned to treat mid-rollout changes as temporary rather than permanent.

What this means for you
For most Copilot users, this feature lives entirely on the admin side. You won’t toggle it yourself, but it directly affects how your organization’s data is handled. If your company excludes sensitive domains, Copilot simply won’t send that content to the cloud, which keeps private information contained within your tenant.
The return of the feature is a good sign for IT teams that wanted these controls but held back while the setting was unstable. Now that it’s back, they can confidently configure their data-governance policies without worrying about a feature that might disappear again.
It’s also a reminder that governance options in Copilot are still maturing. If you’re evaluating Copilot for your organization, the availability of controls like this one should factor into how much trust you place in its data handling by default.
How to get it
Domain Exclusion for Copilot is an administrative control, so it’s managed through the Copilot admin settings rather than a per-user option. If you’re an admin looking to enable it, head to the Microsoft 365 Copilot admin center and look for the data-governance or content-handling controls where domain exclusions can be configured.
Because Microsoft is still refining how these settings are presented, the exact location may shift between updates. If you can’t find the option right away, check the Copilot admin center periodically, as Microsoft tends to surface newly stabilized features there.
For organizations that need tight control over what Copilot can access, this return closes a real gap. It’s a small but concrete step toward the kind of granular data governance that enterprises expect when deploying Copilot at scale.
Microsoft has not released an official blog post detailing the return, so the details here are drawn from the original reporting by Neowin. Keep an eye on the Copilot admin center and Microsoft’s official documentation for the authoritative confirmation and any updated guidance on enabling the feature.
Source: Neowin
Over to you: Does your organization use Domain Exclusion for Copilot, or have you been waiting for it to come back?



