Skip to content
Govern 7 min read

Why your SharePoint search shows too much, and the one line that fixes it

Someone searches from your intranet and gets files from half the company. It looks like a permissions leak. It usually isn't. Here is what actually changed, the one command that puts it back, and the part most people are never told: this makes search tidier, not safer.

On this page

Someone in finance types a word into the search box on your intranet. Up comes a budget file from another department. Then a contract. Then a folder they have never heard of.

They screenshot it and send it to IT with one line: how am I seeing this?

It looks like a permissions leak. It almost never is.

Search never shows anyone a file they could not already open. If it came up in their results, they already had access to it. Nothing leaked. What changed is how wide the search box looks by default.

What people report

This is one site's search box. The second result lives in a different site. Nothing on the screen tells the user how wide they just searched.

Why it searches everything

There is no single tenant switch for this. How wide the box looks depends on the kind of site you are standing on.

Site typeWhat the box searches
Normal siteJust that site
Hub siteEvery site in the hub
Home siteEverything in the company

Look at the home site row. A home site is the one you set as the front door of your intranet. The moment someone makes a site the home site, its search box changes. It stops searching that site and starts searching everything.

Nobody broke anything. That is what a home site does. The problem is the timing. It changes the day you set it, and nobody notices until weeks later, when someone searches for a common word and gets a shock.

Hubs do a smaller version of the same thing. Join ten sites to a hub and all ten search boxes now cover all ten sites.

You can check any site without PowerShell. Paste this into your browser with your own site URL:

https://yourtenant.sharepoint.com/sites/YourSite/_api/web?$select=SearchScope

You get one number back. 0 means the site type decides. 1 is everything, 2 is the hub, 3 is just this site.

Step 1: connect to the site

You need to be a site owner. You do not need to be a tenant admin, which saves you a ticket.

Connect-PnPOnline -Url https://yourtenant.sharepoint.com/sites/YourSite -Interactive

Step 2: change the scope

One line:

Set-PnPSearchSettings -SearchScope Site

You can pass DefaultScope, Site, Hub or Tenant. Site locks the box to the site you are on, even if it is a home site, even if it sits in a hub. DefaultScope puts things back to normal, so that is your undo.

It only affects that one site. There is no version that covers a whole site collection at once, so if you have subsites, run it on each one.

It works straight away. Nothing to publish, nothing to wait for.

Step 3: check it worked

Reload the site and search the same word.

After the change

Same word, same person, seconds apart. Two results became one, and a small trail appeared above the tabs.

Three things look different, and you can check all of them in about ten seconds.

  • The hint text changes from “Search in SharePoint” to “Search this site”.
  • The web address of the results page changes. Before, it ends in /search.aspx/?q=. After, it ends in /search.aspx/siteall?q=.
  • The row of tabs gets shorter. Before, you get All, Files, Sites, People, News, Messages, Images and Videos. After, you get All, Files, Sites, News and Images.

The shorter tab row is the part nobody warns you about. People, Messages and Videos are gone, because one site is not where your colleagues and your Teams chats live. If your staff used that box to look up a coworker, they cannot any more. Expect that as the next complaint.

The catch

This is the part to say out loud, especially if someone asked for this because they were worried about security.

Look at the top of the results page again. There is a small trail that reads Organization › Mark 8 Project Team. The hidden label on it, word for word, is “Breadcrumb navigation scope of your search. Select to search wider.”

One click away

Clicking Organization puts the search back across the whole company. Checked in a live tenant in August 2026.

I clicked it. The same search went from one result back to two, and the file from the other site came straight back.

So the setting decides where search starts. It does not decide what anyone is allowed to find.

Microsoft more or less says so themselves. If you set the scope to Tenant, it gets ignored for guest users, because showing guests everything “can lead to unintended oversharing of content.” They treat scope as a convenience. Oversharing is a different job.

And that box is not the only way in. The same person can search from the SharePoint start page, from Office.com, or from Teams, and get the same files back. You have closed one door in a room full of doors.

If you really do need to hide something

Then scope was never going to do it. Here is what does, in the order I would try.

  1. Fix the permissions. If someone can find a finance file they should not read, finding it is not the problem. The access is. It is usually broken inheritance or an old sharing link nobody remembers making.
  2. Take the site out of search. Site settings, then Search, then set Allow this site to appear in search results to No. Blunt, but it works, and it works for everyone.
  3. Restricted Content Discovery, for a site people still need to use but that should stop turning up in company-wide search and Copilot. That whole set of controls is changing right now, which the Restricted SharePoint Search retirement covers.
  4. Hide the search box with Set-PnPSearchSettings -SearchBoxInNavBar Hidden. Read the small print first. It also strips the search box out of every list and library on that site, and if you do it on the root site, search vanishes from the SharePoint start page too.

The first three change what someone can actually reach. The fourth just moves the box out of sight.

Other things the same command does

Change the hint text. Set-PnPSearchSettings -Scope Web -SearchBoxPlaceholderText "Search HR policies" replaces the grey text in the box. If you have just locked a site down, saying so in the box saves a lot of confusion. One catch: this needs custom script turned on for the site, which is off by default. A tenant admin switches it on, you make the change, they switch it back off. Setting the scope needs none of that.

Point it at your own results page. You can build a page around a Search Results web part with the query limited to what you want, and send the box there. This is the bigger job, and it is the one that does get rid of the Organization link, because you are no longer using Microsoft’s page. Before you go down that road: Microsoft warns that a custom page plus Tenant scope breaks people search, and it still does nothing about the start page.

Bottom line

If your intranet search suddenly started showing the whole company, check whether someone made that site the home site. That is usually the answer, and it is working exactly the way Microsoft built it.

One line puts it back:

Set-PnPSearchSettings -SearchScope Site

Then be honest about what you fixed. You made search tidier. You did not make anything more private. Every file in those results was already open to the person who searched, and one click on Organization brings them all back. If the real worry was someone opening a document they should not, this setting hides the symptom and leaves the document sitting right where it was.

Paired with this post

Permissions Cleanup & Governance Prep Checklist

PDF · 7 pages · 45 checkpoints · one email, no drip sequence

One email with the link. No drip sequence, no upsell. Unsubscribe any time.

TWENTY MINUTES, NO PITCH

Tell me what is stuck. I will tell you what it takes.

Same consultant from the first email to the last cutover. If I am not the right fit, I will refer you to someone who is.

Sneak peek

Document preview

100%

Loading the document…