AI engineering

Replace Restricted SharePoint Search with Restricted Content Discovery

Restricted SharePoint Search is retiring. Inventory the allow list, apply Restricted Content Discovery to the sites that need it, verify propagation, then turn RSS off.

10 min read
On this page

To replace Restricted SharePoint Search (RSS) before it retires, flip your model from an allow list to a deny list: export the current RSS allow list, identify the SharePoint sites that still need to be hidden from organization-wide search and Copilot, turn on Restricted Content Discovery (RCD) for those sites with Set-SPOSite -RestrictContentOrgWideSearch $true, wait for the change to propagate, and then run Set-SPOTenantRestrictedSearchMode -Mode Disabled. Microsoft has already blocked new RSS enablement from July 31, 2026, so plan the move as a one-way change.

Who this is for and what you will have at the end

This guide is for SharePoint and Microsoft 365 administrators who turned on RSS as a stopgap for a Copilot rollout and now need a supported replacement, and for anyone who was planning to use RSS and can no longer enable it.

At the end you will have:

  • A record of how RSS was configured and which sites were on the allow list.
  • A short, deliberate list of high-risk sites protected by RCD instead.
  • A tenant report showing every site where RCD is on.
  • RSS disabled, with users and agent owners told what will change.
  • A plan to remove RCD from each site once its permissions have been fixed.

What is changing

Microsoft's RSS documentation now opens with a retirement notice: Restricted SharePoint Search is retiring, new enablement is blocked starting July 31, 2026, and you should use controls such as Restricted Content Discovery for content discoverability. RSS was always described as a short-term measure "not intended or scalable for long-term use". Check the Microsoft 365 message center in your tenant for the final shutdown timeline that applies to you; this article only relies on the dates published on Microsoft Learn.

The two features answer the same question, "which SharePoint content can organization-wide search and Copilot discover?", from opposite directions.

Restricted SharePoint SearchRestricted Content Discovery
ModelTenant-wide allow listPer-site exclusion
ScaleUp to 100 sites; a hub site counts as one and its associated sites are includedAny number of sites, but Microsoft advises using it selectively
Effect on sites you didn't listExcluded from organization-wide search and CopilotUnaffected; discoverable under normal permissions
Users' own and recent contentStill returned, limited to the last 2,000 entities from frequent sites, direct shares and files viewed, edited or createdAlso hidden: Microsoft's documentation states that RCD covers files users recently interacted with. Users can still open content they have access to directly
Site-scoped searchNot affectedNot affected
AI entry points on the siteNo change documentedRemoved: the Copilot button, AI actions menus (including creating agents) and Create pages with AI
Search indexNot changedNot changed; eDiscovery and auto-labeling continue to work
OneDriveOneDrive files are still returnedCan't be applied to OneDrive
Time to take effectWithin an hourDepends on site size; more than a week for sites with over 500,000 items
StatusRetiringSupported

The practical consequence: with RSS on, every new or unlisted site was hidden by default. With RCD, every site is discoverable by default, so your list has to cover the sites that are risky, not the sites that are safe.

Prerequisites

  • Licensing: RCD requires a Microsoft Copilot licence in the organization and SharePoint Advanced Management (SAM). SAM capabilities for Copilot are available when at least one user has a Copilot licence assigned, or through the SAM Plan 1 add-on or Microsoft 365 E7.
  • Role: SharePoint Administrator or SharePoint Advanced Management Administrator.
  • PowerShell: the latest SharePoint Online Management Shell, connected to your admin URL.
  • Change window: time to let RCD propagate before you disable RSS. Large sites can take more than a week.
Connect-SPOService -Url https://contoso-admin.sharepoint.com

Step 1: Record the current RSS configuration

Before you change anything, capture what RSS is doing today. You can't rely on turning it back on later, because new enablement is blocked.

# Enabled or Disabled
Get-SPOTenantRestrictedSearchMode
 
# Sites currently on the allow list
Get-SPOTenantRestrictedSearchAllowedList | Out-File -FilePath "C:\RSS\rss-allowlist.txt"

Keep the output with your change record. The allow list tells you which sites someone already reviewed and judged safe for organization-wide discovery. Everything outside that list is what RSS was hiding.

Step 2: Decide which sites need RCD

Don't invert the allow list blindly. A tenant with 5,000 sites and a 100-site allow list would end up with RCD on 4,900 sites, which Microsoft specifically warns against: excessive use reduces the content available to search and Copilot and degrades answer quality.

Instead, build a risk-based list:

  1. Run the Data access governance site permissions report (SharePoint admin center > Reports > Data access governance > Site permissions across your organization). Sort by number of users with access, EEEU permission count and Anyone link count.
  2. Run the activity reports for sharing links and "Everyone except external users" to see where oversharing is happening now.
  3. Add sensitivity: in the Microsoft Purview portal, use DSPM > Discover > Data risk assessments to find sites that combine broad access with sensitive information types. The Protect tab has a Restrict all items action that applies RCD directly.
  4. Use the Content Management Assessment (SharePoint admin center > Advanced Management > Start assessment) or the SharePoint Admin Agent if you have them, to surface ownerless, inactive and overshared sites.

Microsoft's own examples of high-risk sites are those where several signals overlap: sensitive data with "Anyone" links, public sites with no owner, and large audiences with broken inheritance. Typical first candidates are finance, HR, legal and executive sites that haven't had a permissions review.

The detailed reporting process is covered in Prepare a tenant for Microsoft 365 Copilot by fixing oversharing first.

Save the final list as a CSV with a Url column, for example C:\RCD\rcd-sites.csv.

Step 3: Apply Restricted Content Discovery

For a handful of sites, use the SharePoint admin center:

  1. Expand Sites and select Active sites.
  2. Select the site.
  3. On the Settings tab, turn Restrict content from Microsoft Copilot on.
  4. Select Save.

For a list of sites, use PowerShell:

$sites = Import-Csv -Path "C:\RCD\rcd-sites.csv"
 
foreach ($site in $sites) {
    Set-SPOSite -Identity $site.Url -RestrictContentOrgWideSearch $true
    Get-SPOSite -Identity $site.Url | Select-Object Url, RestrictContentOrgWideSearch
}

Sites with RCD applied show a Restricted tag.

Optional: let site administrators manage it

By default only SharePoint administrators can change RCD. If you want site administrators to manage the setting on their own sites, for example to remove it after a permissions review, turn on delegation:

Set-SPOTenant -DelegateRestrictedContentDiscoverabilityManagement $true
Get-SPOTenant | Select-Object DelegateRestrictedContentDiscoverabilityManagement

Site administrators must enter a justification when they change the setting, and both the change and the justification are recorded in the Purview audit log.

Step 4: Confirm coverage and propagation

Generate the tenant-wide RCD report to confirm the setting is on where you expect:

Start-SPORestrictedContentDiscoverabilityReport
 
# Check status and get the report ID
Get-SPORestrictedContentDiscoverabilityReport
 
# Download when complete
Get-SPORestrictedContentDiscoverabilityReport -Action Download -ReportId <ReportGUID>

Compare the downloaded list with your CSV. Then allow time for search to catch up. RCD is a site-level property that has to propagate through the indexing systems; latency depends on the number of items in the site and how many sites are being updated at the same time. For sites with more than 500,000 items, expect more than a week.

Test with a pilot account that has access to an RCD site:

  • Search for a distinctive term from that site on SharePoint home or Office.com. It shouldn't appear.
  • Ask Microsoft 365 Copilot Chat a question that only that site can answer. It shouldn't use that site's content.
  • Open the site directly. The user should still have access, and the Copilot button and AI actions should be gone.

Once RCD is effective on your high-risk sites, disable RSS:

Set-SPOTenantRestrictedSearchMode -Mode Disabled
Get-SPOTenantRestrictedSearchMode

Before you run it, tell users, Copilot agent owners and the service desk what will change. Microsoft's own guidance notes that search and Copilot results change when RSS is disabled: content from every site a user has permission to, other than RCD sites, becomes discoverable again. That is the intended outcome, but people will notice more results, and some will notice content they didn't know they could open. Treat those reports as oversharing findings and feed them into Step 6.

Because new enablement is blocked from July 31, 2026, assume you won't be able to turn RSS back on after you disable it. That is why Steps 3 and 4 come first.

Step 6: Fix the permissions and remove RCD

RCD, like RSS, is meant to buy time. For each site you protected:

  1. Start a site access review from the relevant Data access governance report so the site owner removes EEEU grants, broad groups and organization-wide links.
  2. When the review is complete, rerun the reports to confirm the exposure has dropped.
  3. Remove RCD so the content is available to Copilot again:
Set-SPOSite -Identity https://contoso.sharepoint.com/sites/finance -RestrictContentOrgWideSearch $false

For sites that must stay limited to a defined audience permanently, restricted access control (access limited to members of up to 10 Microsoft 365 or Entra security groups) or Purview DLP for Copilot are longer-term controls than RCD.

Troubleshooting

SymptomCause and fix
A site with RCD still appears in search or CopilotPropagation isn't finished. Latency depends on the number of items and how many sites are being updated; sites with more than 500,000 items can take more than a week. Also check whether the user is searching from within the site or asking Copilot about a document they already have open, which RCD doesn't affect.
Content from an RCD site still appears in site searchExpected. RCD doesn't affect searches that start in the site's own context, or Microsoft 365 Feed and Recommendations.
You can't apply RCD to a OneDrive URLNot supported. RCD applies only to SharePoint sites.
The RCD setting is missing from the admin centerThe organization doesn't meet the licensing prerequisite: a Copilot licence and SAM.
Copilot answers got noticeably worse after rolloutToo many sites have RCD. Remove it from sites that aren't high risk and fix permissions instead.
You need to turn RSS on for a new tenant or pilotNot possible: new RSS enablement is blocked from July 31, 2026. Use RCD.
eDiscovery can't find content on an RCD siteRCD doesn't remove content from the index, so check the search query and locations rather than RCD.

Closing checklist

  • RSS mode and allow list exported and stored with the change record.
  • High-risk sites identified from Data access governance reports and DSPM, not by inverting the allow list.
  • RCD applied with PowerShell or the admin center and confirmed with the RCD report.
  • Propagation tested with a pilot account.
  • Users, agent owners and the service desk told before RSS is disabled.
  • Set-SPOTenantRestrictedSearchMode -Mode Disabled run and confirmed.
  • Site access reviews started for every RCD site, with a date to remove RCD.

If you also build your own retrieval applications over SharePoint content, see RAG over SharePoint documents with permission trimming kept intact for how those applications respect the same permissions.

References

Questions people ask

Is Restricted SharePoint Search being retired?

Yes. Microsoft's documentation states that Restricted SharePoint Search is retiring and that, starting July 31, 2026, new enablement is blocked. Microsoft directs customers to Restricted Content Discovery and other SharePoint Advanced Management and Purview controls instead.

What is the difference between Restricted SharePoint Search and Restricted Content Discovery?

Restricted SharePoint Search is a tenant-wide allow list of up to 100 sites; everything else is excluded from organization-wide search and Copilot. Restricted Content Discovery works the other way round: it is a per-site setting that hides only the sites you flag, and everything else stays discoverable according to normal permissions.

Does Restricted Content Discovery remove permissions or delete content from the index?

No. It changes discoverability only. Users who already have access can still open the content directly, and the content stays in the search index so Purview features such as eDiscovery and auto-labeling keep working.

Can I apply Restricted Content Discovery to OneDrive?

No. Restricted Content Discovery applies only to SharePoint sites. For OneDrive exposure, use sharing settings, Data access governance reports and restricted access control instead.

SharePoint Advanced ManagementMicrosoft 365 CopilotSharePoint OnlinePowerShell
  1. Prepare a Tenant for Microsoft 365 Copilot by Fixing Oversharing First

    Find overshared SharePoint and OneDrive content with Data access governance reports and DSPM, contain it with RCD and RAC, then hand cleanup to site owners before Copilot rollout.

    AI engineering14 min read
  2. Audit, Retain and Search Microsoft 365 Copilot Prompts with Purview

    Find Copilot interactions in the Purview audit log, keep or delete prompts and responses with a retention policy, and search or purge them with eDiscovery when something goes wrong.

    AI engineering11 min read
  3. Build RAG Over SharePoint Documents Without Breaking Permissions

    Ground an internal AI assistant on SharePoint files so each user only gets answers from documents they can open, using the Copilot Retrieval API or Azure AI Search with ACL ingestion.

    AI engineering12 min read