Skip to content
Govern 6 min read

Restricted SharePoint Search is retiring, and the cheap Copilot fix just became a project

Microsoft blocked new enablement of Restricted SharePoint Search on July 31, 2026. If you switched it on to make Copilot safe, you now own an unwinding project, and Microsoft has published the order to do it in.

On this page

If you rolled out Copilot in the last two years and someone on the project asked “how do we stop it surfacing the HR folder,” there’s a good chance the answer was Restricted SharePoint Search. It was the quick one. An allow list of sites, a couple of PowerShell commands, done in an afternoon.

That option closed on July 31, 2026. Microsoft’s own documentation now opens with a retirement notice: new enablement is blocked, and the recommended replacement is Restricted Content Discovery.

If you never turned it on, this costs you nothing, go straight to doing the permissions work properly. If you did turn it on, you have something more awkward: a control you can keep running for now, that Microsoft has stopped investing in, sitting between your users and their search results. Unwinding it is a real piece of work, and it needs a communication plan more than it needs PowerShell.

What it actually did

Restricted SharePoint Search let an administrator maintain an allow list of up to 100 SharePoint sites. Enterprise search and Copilot would draw on those sites, plus whatever the user personally touched, and leave the rest of the tenant alone.

The appeal is obvious. A tenant with 4,000 sites and no permissions hygiene could ship Copilot on Monday by allow-listing the 60 sites everyone agreed were fine.

The catch is in the second half of that sentence. Here’s Microsoft’s own list of what still surfaces with the feature switched on:

  • Sites on the allow list, honouring existing permissions
  • The user’s own OneDrive files, chats, emails, and calendar
  • Files from sites the user frequently visits
  • Files shared directly with the user
  • Files the user has viewed, edited, or created

The last three bullets are where it leaks. If someone was mistakenly granted access to the payroll site in 2023 and has opened it since, Restricted SharePoint Search does not stand between them and it. The oversharing is untouched. What changes is only whether Copilot volunteers the content to people who never went looking.

It shrinks the blast radius of Copilot. It does nothing to shrink the blast radius of a wrong permission.

Microsoft says this in plainer language than vendors usually manage: “it’s important to note that Restricted SharePoint Search isn’t a security boundary and doesn’t change any permissions on SharePoint sites.”

Why it’s going away

Three reasons, all in the documentation, and all of them things practitioners noticed early.

01 The 100-site cap doesn't survive contact with a real tenant

The allow list tops out at 100 sites. Hub sites help, since associated sites come along without counting against the limit, but any organization that keeps scaling Copilot runs out of room. Microsoft's phrasing is that it "isn't sustainable as your organization scales Copilot and agentic operations."

02 It degrades search for everyone, not just Copilot users

This is the one that surprises people. Restricted SharePoint Search is not a Copilot setting that happens to touch search; it is a search setting. Anyone doing an ordinary org-wide search gets the restricted result set, whether or not they have a Copilot licence. Any product where enterprise search can return SharePoint content is affected.

03 It starves Copilot of the thing you bought it for

With the allow list on, Copilot has materially less to reason over, which shows up as vaguer, less useful answers. You end up paying full price for a Copilot deliberately kept short-sighted, and because the degradation is invisible, nobody connects the disappointing answers to the setting that caused them.

The exit, in Microsoft’s order

The documentation lays out a sequence. The order is the important part, because doing it backwards is how this goes wrong.

  1. Keep RSS on for now if you have it, as a temporary limit while you work. Don’t lead with switching it off.
  2. Find and fix the oversharing using SharePoint Advanced Management: broad access, unmanaged sharing links, the Everyone Except External Users group, sites with broken inheritance.
  3. Apply Purview controls: sensitivity labels, DLP, auditing.
  4. Disable Restricted SharePoint Search once permissions and governance genuinely hold up.
  5. Tell people first. Copilot and search will start returning results they haven’t seen in a year or more. Microsoft explicitly calls out notifying Copilot agent owners and IT.

Step 5 is the one that gets cut for time, and it’s the one that generates the support tickets. The day you disable RSS, search behaviour changes for the entire organization at once. If nobody was warned, your service desk spends a week fielding “why is search different” from people who assume something broke.

What replaces it

Nothing replaces it one-for-one, which is the point. Microsoft is steering people from a blunt tenant-wide filter toward two narrower tools plus the actual remediation work.

Restricted Content Discovery is the closest analogue and the one the retirement notice names. It’s per-site rather than tenant-wide: flag a sensitive site and it stops appearing in Copilot, agents, and org-wide search, while permissions stay exactly as they were. It also strips the AI entry points from that site, so no Copilot button and no agent creation. It’s a better-shaped tool, though it shares the same fundamental honesty problem, it hides content from Copilot without fixing who can reach it. The full read on where RCD helps and where it quietly hurts goes deeper.

Restricted Access Control is the one that’s an actual boundary. It locks a site to members of a named Entra security group, so stray sharing links stop mattering. When a site genuinely must be sealed, this is the control, not RCD.

And underneath both: the permissions work. Neither tool substitutes for it.

If you’re starting Copilot now

The nicest thing about this retirement is what it removes: the cheap option that let organizations skip the boring part. There’s no longer a switch that makes Copilot feel safe without making it safe.

So the sequence for a new rollout is the one it always should have been. Run the oversharing assessment before you buy a single licence. Fix the broad-access sites, clear the stray Everyone Except External Users grants, sort out the sharing links nobody remembers creating. Use Restricted Content Discovery for the handful of sites that stay sensitive after all that. Label what needs labelling.

It’s slower. Microsoft frames data-governance remediation as a four-to-eight week phase for a reason. What you get for the extra weeks is a Copilot that answers properly and a permissions model you can put in front of an auditor.

Bottom line

Restricted SharePoint Search was a reasonable answer to an urgent question in 2024. It bought time. The bill for that time is now due, and it’s payable in the permissions work that was deferred.

If it’s running in your tenant, don’t rush to switch it off. Find out what’s overshared, fix it, tell your users what’s about to change, and only then turn the limit off. Done in that order it’s a scheduled piece of work with a communication plan attached. Done in any other order you find out what was overshared by watching Copilot tell people.

Paired with this post

Copilot Readiness Governance Checklist

PDF · 7 pages · 44 checkpoints · one email, no drip sequence

One email with the link. No drip sequence, no upsell. Unsubscribe any time.

TWENTY MINUTES, NO PITCH

Tell me what is stuck. I will tell you what it takes.

Same consultant from the first email to the last cutover. If I am not the right fit, I will refer you to someone who is.

Sneak peek

Document preview

100%

Loading the document…