Microsoft has rolled back a new Microsoft 365 Copilot feature that let admins exclude up to 1,000 web domains from its web-grounded answers.
The Register reported on 6 August that Microsoft withdrew Domain Exclusion just days after rolling it out for Microsoft 365 Copilot. Microsoft had presented the feature as a way for administrators to limit which public websites could influence Copilot when it used the web to answer questions.
In plain English, this was an admin setting for steering an AI assistant away from specified websites. Its removal matters because Microsoft had framed it as a practical governance tool for organisations trying to use Copilot while keeping its answers aligned with policy, compliance expectations and trusted information sources.
What changed
According to The Register's account of Microsoft's update, Domain Exclusion "has been rolled back at this time". The source says Microsoft did not explain why the feature was withdrawn.
The reported timing is central to the story. Microsoft announced Domain Exclusion in July 2026, then reversed course within days of the rollout, leaving organisations that may have been preparing to use it without that control for now.
The same report says Microsoft stated: "We understand the importance of this capability and are actively evaluating next steps." That indicates the company has not abandoned the problem, but it does not establish when or whether the same feature will return.
What Domain Exclusion was supposed to do
Microsoft 365 Copilot can use the public web as part of how it answers questions. That means its responses may be influenced not only by internal company data, but also by information found on websites. The Register said Domain Exclusion was intended to give administrators a way to stop certain sites from shaping those answers.
The feature was designed as a block list. Administrators could upload a CSV file through PowerShell to exclude up to 1,000 web domains. In practical terms, that means an IT team could name websites it did not want Copilot to rely on, rather than switching off all web use or approving only a small set of trusted sites.
The report quotes Microsoft's earlier positioning of the tool as a way to help administrators reduce the influence of unwanted or non-compliant web sources. That matters because the problem here is not just bad answers in the abstract. The source explicitly ties the feature to organisational policies, compliance expectations and trusted-source strategies.
Why enterprise IT teams cared
This rollback lands in a specific context: Microsoft is asking businesses to use Copilot in work settings, including important workflows. As The Register notes from Microsoft's own language, the company had said admins need practical controls to keep web-grounded experiences aligned with organisational requirements.
That makes Domain Exclusion more than a minor settings change. For IT, security and compliance teams, it was presented as one of the mechanisms for managing how an AI assistant uses outside information. Its removal means one less available control for organisations that may want Copilot's web access but also want tighter oversight of which sources can affect results.
The source does not say how many organisations had adopted the feature before it was withdrawn, and it does not report any customer reactions from named companies. So it would go too far to claim a broad enterprise response. What the source does support is that Microsoft itself had framed the feature as relevant to governed AI adoption, and that this governance option is currently unavailable.
Limits of the design, even before the rollback
The Register also highlights an important limitation in the feature's original design. Because it was a block list, administrators would have had to identify domains they did not trust and keep adding them over time. The report argues that this could become an ongoing "Whac-A-Mole" problem.
The same source points out that a maximum of 1,000 domains may be modest compared with the scale of the public web. It also raises a further concern: staff could potentially use Copilot to pull in information from sites that organisational policy would not allow them to visit directly. The report presents that as a risk, not as something known to have happened.
The article contrasts this approach with an allow list, where only pre-approved sources could be used. That suggestion appears in the report's analysis and in a quoted comment from a commenter reacting to the original announcement. It is not presented as a Microsoft plan. Still, it helps explain why some administrators may have seen the original feature as useful but incomplete.
Why it matters
What is known now is narrow but important. Microsoft introduced an admin control for limiting which public web domains could influence Microsoft 365 Copilot answers, then rolled it back within days, and has said only that it is evaluating next steps, according to The Register's report.
For general readers, the underlying issue is straightforward: when an AI assistant can use the public web, organisations may want controls over which websites it listens to. For IT and business leaders, this episode suggests that the administrative guardrails around enterprise AI products may still be changing quickly. A likely implication is that teams assessing Copilot for policy-sensitive work may need to treat recently announced controls cautiously until they are clearly available and stable.
What remains open is equally important. The source does not establish why Microsoft removed the feature, whether it will return in the same form, or whether the company might replace it with a different model such as an allow list. For now, the only firm point is that a governance feature Microsoft had just promoted is no longer in place.