Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft 365 Copilot generally uses the signed-in user’s existing access to Microsoft 365 content. To control what Copilot can draw on, first fix access to SharePoint and OneDrive content; then choose whether to restrict access itself or only reduce discoverability. These are different goals, and search-scope controls are not substitutes for permissions.

How Copilot permissions work

Copilot can use organizational content that the signed-in user is permitted to access. That means a user who can open an overshared SharePoint file may also expose its content in a Copilot interaction. Copilot does not correct an overly broad permission model: access governance has to start in the repositories where the content lives. Microsoft explains this in its Secure and govern Microsoft 365 Copilot guidance and its documentation for SharePoint agents.

Separate two questions when choosing a control:

  • Who is allowed to access the content? Change permissions or apply Restricted Access Control.
  • Should content users can access be surfaced in Copilot or organization-wide search? Consider Restricted Content Discovery, which affects discoverability rather than granting or revoking access.

Which control should you use?

Control What it changes Scope and effect Key limitation
Existing permissions and sharing settings Actual access to sites, files, and other content Applies the permissions users already rely on; Copilot and agents follow those user permissions. Broad or unintended permissions remain broad until administrators remediate them.
Restricted Access Control (restricted site access control) Actual access to a SharePoint site or OneDrive, by adding an additional group-based gate Users need both ordinary permission to the content and membership in a configured Microsoft 365 or Microsoft Entra security group. Copilot and organization-wide search honor the policy. It does not grant normal content permission by itself. Search-index changes may take time, especially on larger sites.
Restricted Content Discovery Whether site content is discoverable through Copilot and organization-wide search Suitable when site permissions should remain in place but the content should not be broadly surfaced. It does not change who has site access.
Restricted SharePoint Search Limits SharePoint search scope using an allow list Microsoft documents an allow list of up to 100 SharePoint sites; the setting can also reduce information available to Copilot and affect general search. It is temporary, does not change site permissions, and is not a security boundary. Microsoft documentation says new enablement is blocked starting July 31, 2026.

The distinctions and limits in this table are described in Microsoft Learn’s Restrict SharePoint site access with Microsoft 365 groups and Microsoft Entra security groups, Restricted Content Discovery, and Restricted SharePoint Search documentation. Verify feature availability in your tenant before making operational changes.

How to review and tighten access

Use a governance pass to identify exposure before applying a discovery or access restriction. Microsoft’s Get ready for Microsoft Copilot with SharePoint Advanced Management guidance recommends reviewing broad access and unnecessary content as part of Copilot readiness.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Inventory sites and sharing. Use SharePoint data access governance reports, site permission and sharing reports, and site-owner access reviews to locate sites with large audiences, broad links, sensitive material, no active owner, or no clear business need.
  2. Correct the underlying permissions. Review SharePoint and OneDrive sharing settings. Remove organization-wide or “Anyone” access, broad audiences, or inherited access where it is not intended. Recheck who can open the content after the change.
  3. Choose the policy that matches the goal. Apply Restricted Access Control when only members of designated groups should be able to access a site or OneDrive. Use Restricted Content Discovery when normal site access should remain but the content should not appear in Copilot or organization-wide search.
  4. Configure channel sites independently. Private and shared Teams channels have separate SharePoint site collections. A restriction on the parent team site does not automatically apply to those channel sites, so review and configure them separately.
  5. Validate behavior and communicate changes. Confirm access with representative accounts and monitor governance reports. Search-index updates can lag after a restriction, so do not treat an immediate search result as proof that a policy is or is not working. Tell users when a change will alter what they can find.

When Restricted Access Control is the right choice

Restricted Access Control adds a group-based access condition to a SharePoint site or OneDrive. Microsoft says users outside the configured group cannot access the site or its content even if they had earlier permissions or a sharing link. However, group membership alone is insufficient: a user must also have the ordinary site or file permission.

Microsoft documents support for up to 10 groups per site. The policy is honored by Copilot and organization-wide search, but index updates may not be immediate. Plan for that delay when validating a change, especially for large sites.

For a shared Teams channel, Microsoft notes that external participants from another tenant are not checked against the resource tenant’s Restricted Access Control group. Their access remains governed by the shared-channel and site permissions, so account for that distinction when reviewing cross-tenant collaboration.

When Restricted Content Discovery is the right choice

Use Restricted Content Discovery when people should retain access through the site’s normal permissions, but the content should not be broadly discoverable through Copilot or organization-wide search. Microsoft describes it as useful for content that must remain accessible but should not be broadly discoverable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review sites with broad sharing links, large permission audiences, broken permission inheritance, weak protection for sensitive material, or no clear owner. This control reduces discovery; it does not revoke existing permissions or make an accessible file inaccessible. If users should not be able to open the content, fix permissions or apply an access restriction instead.

Why Restricted SharePoint Search is not a long-term security control

Restricted SharePoint Search is a temporary search-scope measure, not a permissions boundary. Microsoft states that it does not change SharePoint site permissions and does not guarantee that only allow-listed content can appear. A user’s recent access to content, or content shared with them through Teams or Outlook, can still affect what they see.

Microsoft’s documentation, checked October 4, 2026, says the feature is retiring and that new enablement is blocked starting July 31, 2026. If it is already enabled in your tenant, confirm its live admin-center status and current Microsoft guidance before changing it. Microsoft recommends moving toward comprehensive governance, validating the replacement controls, and then disabling Restricted SharePoint Search.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to govern SharePoint agents and sensitive files

SharePoint agents use users’ underlying data permissions, like Copilot in other Microsoft 365 apps. Administrators can govern access through site controls, content discovery settings, licensing or pay-as-you-go billing-policy groups, and agent availability.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Limit source access: Apply the appropriate site and file permissions or Restricted Access Control.
  • Exclude selected content: Microsoft documents using Purview data loss prevention (DLP) policies, including sensitivity-label conditions, to prevent selected files from being processed by agents. A response citation may identify a file even when its content was not used.
  • Manage agent availability: Tenant admins and AI admins can review actively used agents and block or unblock them in the Microsoft 365 admin center.
  • Account for the agent file format: Microsoft says a .agent file cannot currently receive a sensitivity label directly. DLP governance for that file can use its extension as a condition.

Restricted Content Discovery also hides the agent icon and prevents users from creating or using agents on a site marked for restricted discovery. The relevant behaviors are described in Microsoft Learn’s SharePoint agents and data access guidance.

Use Purview and lifecycle controls alongside permissions

Permissions are only one part of information protection. Use Microsoft Purview sensitivity labels, DLP, auditing, and related controls where they fit your compliance requirements and licensing. Microsoft also recommends archiving or deleting content that is no longer needed: unnecessary, stale material can increase exposure and make Copilot responses less useful.

Controls must match the risk and the user’s need. A label or DLP rule can protect or exclude content, while site and file permissions determine who can access it. Neither search discoverability nor agent availability should be treated as a replacement for the underlying access model.

Check licensing and cloud availability before deployment

Microsoft’s governance guidance distinguishes foundational controls associated with Microsoft 365 admin center, SharePoint Advanced Management, and Purview under A3/E3/G3 licensing from optimized controls associated with Purview and Defender for Cloud Apps under A5/E5/G5. A separate SharePoint Advanced Management availability matrix covers business and government clouds and marks sensitivity labels as requiring E5 or G5 in that matrix.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those statements do not establish entitlement to every Purview feature for every plan. Confirm the specific control, license, and cloud availability against Microsoft’s current licensing documentation and your organization’s tenant before deployment.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.