# Why your SharePoint search shows too much, and the one line that fixes it

> Someone searches from your intranet and gets files from half the company. It looks like a permissions leak. It usually isn't. Here is what actually changed, the one command that puts it back, and the part most people are never told: this makes search tidier, not safer.

[Home](https://tenantcraft.ca/)  [Insights](https://tenantcraft.ca/insights)  SharePoint

Govern Aug 30, 2026  7 min read

Geri Crroj

Microsoft 365 consultant, Niagara, Ontario

Someone in finance types a word into the search box on your intranet. Up comes a budget file from another department. Then a contract. Then a folder they have never heard of.

They screenshot it and send it to IT with one line: _how am I seeing this?_

It looks like a permissions leak. It almost never is.

Search never shows anyone a file they could not already open. If it came up in their results, they already had access to it. Nothing leaked. What changed is how wide the search box looks by default.

![A SharePoint search results page for the word contoso, opened from the Mark 8 Project Team site. Two results appear: a PowerPoint in Mark 8 Project Team, and an image in a separate site called IntraTeam. There is no scope trail above the tabs.](https://tenantcraft.ca/images/search-scope-01-tenant-wide.png)

What people report

This is one site's search box. The second result lives in a different site. Nothing on the screen tells the user how wide they just searched.

## Why it searches everything

There is no single tenant switch for this. How wide the box looks depends on the kind of site you are standing on.

| Site type | What the box searches |
| --- | --- |
| Normal site | Just that site |
| Hub site | Every site in the hub |
| **Home site** | **Everything in the company** |

Look at the home site row. A home site is the one you set as the front door of your intranet. The moment someone makes a site the home site, its search box changes. It stops searching that site and starts searching everything.

Nobody broke anything. That is what a home site does. The problem is the timing. It changes the day you set it, and nobody notices until weeks later, when someone searches for a common word and gets a shock.

Hubs do a smaller version of the same thing. Join ten sites to a hub and all ten search boxes now cover all ten sites.

You can check any site without PowerShell. Paste this into your browser with your own site URL:

```
https://yourtenant.sharepoint.com/sites/YourSite/_api/web?$select=SearchScope
```

You get one number back. **0** means the site type decides. **1** is everything, **2** is the hub, **3** is just this site.

The two second version

Look at the grey hint text inside the search box. “Search this site” means it is locked to the site. “Search in SharePoint” means it is not.

## Step 1: connect to the site

You need to be a **site owner**. You do not need to be a tenant admin, which saves you a ticket.

```
Connect-PnPOnline -Url https://yourtenant.sharepoint.com/sites/YourSite -Interactive
```

The first run on a new machine takes longer

PnP PowerShell used to come with a sign-in app built in. It does not any more. So on a machine that has never run it, `-Interactive` just fails.

You fix that once by running `Register-PnPEntraIDAppForInteractiveLogin`, which an admin has to approve. After that, connecting is one line every time. Set aside ten minutes for the first go.

## Step 2: change the scope

One line:

```
Set-PnPSearchSettings -SearchScope Site
```

You can pass `DefaultScope`, `Site`, `Hub` or `Tenant`. `Site` locks the box to the site you are on, even if it is a home site, even if it sits in a hub. `DefaultScope` puts things back to normal, so that is your undo.

It only affects that one site. There is no version that covers a whole site collection at once, so if you have subsites, run it on each one.

It works straight away. Nothing to publish, nothing to wait for.

## Step 3: check it worked

Reload the site and search the same word.

![The same search for contoso from the same site, now showing only one result from Mark 8 Project Team. A trail above the tabs reads Organization, then Mark 8 Project Team. The row of tabs is shorter than before.](https://tenantcraft.ca/images/search-scope-02-site-scoped.png)

After the change

Same word, same person, seconds apart. Two results became one, and a small trail appeared above the tabs.

Three things look different, and you can check all of them in about ten seconds.

-   **The hint text** changes from “Search in SharePoint” to “Search this site”.
-   **The web address** of the results page changes. Before, it ends in `/search.aspx/?q=`. After, it ends in `/search.aspx/siteall?q=`.
-   **The row of tabs gets shorter.** Before, you get All, Files, Sites, People, News, Messages, Images and Videos. After, you get All, Files, Sites, News and Images.

The shorter tab row is the part nobody warns you about. People, Messages and Videos are gone, because one site is not where your colleagues and your Teams chats live. If your staff used that box to look up a coworker, they cannot any more. Expect that as the next complaint.

## The catch

This is the part to say out loud, especially if someone asked for this because they were worried about security.

Look at the top of the results page again. There is a small trail that reads **Organization › Mark 8 Project Team**. The hidden label on it, word for word, is _“Breadcrumb navigation scope of your search. Select to search wider.”_

![The site scoped results page with the word Organization circled in red. It sits just above the row of tabs, to the left of the site name.](https://tenantcraft.ca/images/search-scope-03-search-wider.png)

One click away

Clicking Organization puts the search back across the whole company. Checked in a live tenant in August 2026.

I clicked it. The same search went from one result back to two, and the file from the other site came straight back.

So the setting decides where search **starts**. It does not decide what anyone is **allowed** to find.

Microsoft more or less says so themselves. If you set the scope to `Tenant`, it gets ignored for guest users, because showing guests everything “can lead to unintended oversharing of content.” They treat scope as a convenience. Oversharing is a different job.

And that box is not the only way in. The same person can search from the SharePoint start page, from Office.com, or from Teams, and get the same files back. You have closed one door in a room full of doors.

## If you really do need to hide something

Then scope was never going to do it. Here is what does, in the order I would try.

1.  **Fix the permissions.** If someone can find a finance file they should not read, finding it is not the problem. The access is. It is usually broken inheritance or an old sharing link nobody remembers making.
2.  **Take the site out of search.** Site settings, then Search, then set _Allow this site to appear in search results_ to **No**. Blunt, but it works, and it works for everyone.
3.  **Restricted Content Discovery**, for a site people still need to use but that should stop turning up in company-wide search and Copilot. That whole set of controls is changing right now, which [the Restricted SharePoint Search retirement](https://tenantcraft.ca/insights/restricted-sharepoint-search-retirement) covers.
4.  **Hide the search box** with `Set-PnPSearchSettings -SearchBoxInNavBar Hidden`. Read the small print first. It also strips the search box out of every list and library on that site, and if you do it on the root site, search vanishes from the SharePoint start page too.

The first three change what someone can actually reach. The fourth just moves the box out of sight.

## Other things the same command does

**Change the hint text.** `Set-PnPSearchSettings -Scope Web -SearchBoxPlaceholderText "Search HR policies"` replaces the grey text in the box. If you have just locked a site down, saying so in the box saves a lot of confusion. One catch: this needs custom script turned on for the site, which is off by default. A tenant admin switches it on, you make the change, they switch it back off. Setting the scope needs none of that.

**Point it at your own results page.** You can build a page around a Search Results web part with the query limited to what you want, and send the box there. This is the bigger job, and it is the one that does get rid of the Organization link, because you are no longer using Microsoft’s page. Before you go down that road: Microsoft warns that a custom page plus `Tenant` scope breaks people search, and it still does nothing about the start page.

## Bottom line

If your intranet search suddenly started showing the whole company, check whether someone made that site the home site. That is usually the answer, and it is working exactly the way Microsoft built it.

One line puts it back:

```
Set-PnPSearchSettings -SearchScope Site
```

Then be honest about what you fixed. You made search tidier. You did not make anything more private. Every file in those results was already open to the person who searched, and one click on Organization brings them all back. If the real worry was someone opening a document they should not, this setting hides the symptom and leaves the document sitting right where it was.

If search turned up something it should not have, the permissions audit is the real fix.

Permissions Cleanup & Governance Prep Checklist

PDF · 7 pages · 45 checkpoints

[Email me the PDF](https://tenantcraft.ca/resources/guides/permissions-cleanup-prep)

TWENTY MINUTES, NO PITCH

## Tell me what is stuck. I will tell you what it takes.

Same consultant from the first email to the last cutover. If I am not the right fit, I will refer you to someone who is.

[Book a 20-min call](https://tenantcraft.ca/contact) [See published rates](https://tenantcraft.ca/pricing)

---

_Canonical HTML: https://tenantcraft.ca/insights/scope-sharepoint-search-box-to-one-site · Agent guide: https://tenantcraft.ca/llms.txt · Site map: https://tenantcraft.ca/sitemap-index.xml_
