To replace Restricted SharePoint Search (RSS) before it retires, flip your model from an allow list to a deny list: export the current RSS allow list, identify the SharePoint sites that still need to be hidden from organization-wide search and Copilot, turn on Restricted Content Discovery (RCD) for those sites with Set-SPOSite -RestrictContentOrgWideSearch $true, wait for the change to propagate, and then run Set-SPOTenantRestrictedSearchMode -Mode Disabled. Microsoft has already blocked new RSS enablement from July 31, 2026, so plan the move as a one-way change.
Who this is for and what you will have at the end
This guide is for SharePoint and Microsoft 365 administrators who turned on RSS as a stopgap for a Copilot rollout and now need a supported replacement, and for anyone who was planning to use RSS and can no longer enable it.
At the end you will have:
- A record of how RSS was configured and which sites were on the allow list.
- A short, deliberate list of high-risk sites protected by RCD instead.
- A tenant report showing every site where RCD is on.
- RSS disabled, with users and agent owners told what will change.
- A plan to remove RCD from each site once its permissions have been fixed.
What is changing
Microsoft's RSS documentation now opens with a retirement notice: Restricted SharePoint Search is retiring, new enablement is blocked starting July 31, 2026, and you should use controls such as Restricted Content Discovery for content discoverability. RSS was always described as a short-term measure "not intended or scalable for long-term use". Check the Microsoft 365 message center in your tenant for the final shutdown timeline that applies to you; this article only relies on the dates published on Microsoft Learn.
The two features answer the same question, "which SharePoint content can organization-wide search and Copilot discover?", from opposite directions.
| Restricted SharePoint Search | Restricted Content Discovery | |
|---|---|---|
| Model | Tenant-wide allow list | Per-site exclusion |
| Scale | Up to 100 sites; a hub site counts as one and its associated sites are included | Any number of sites, but Microsoft advises using it selectively |
| Effect on sites you didn't list | Excluded from organization-wide search and Copilot | Unaffected; discoverable under normal permissions |
| Users' own and recent content | Still returned, limited to the last 2,000 entities from frequent sites, direct shares and files viewed, edited or created | Also hidden: Microsoft's documentation states that RCD covers files users recently interacted with. Users can still open content they have access to directly |
| Site-scoped search | Not affected | Not affected |
| AI entry points on the site | No change documented | Removed: the Copilot button, AI actions menus (including creating agents) and Create pages with AI |
| Search index | Not changed | Not changed; eDiscovery and auto-labeling continue to work |
| OneDrive | OneDrive files are still returned | Can't be applied to OneDrive |
| Time to take effect | Within an hour | Depends on site size; more than a week for sites with over 500,000 items |
| Status | Retiring | Supported |
The practical consequence: with RSS on, every new or unlisted site was hidden by default. With RCD, every site is discoverable by default, so your list has to cover the sites that are risky, not the sites that are safe.
Prerequisites
- Licensing: RCD requires a Microsoft Copilot licence in the organization and SharePoint Advanced Management (SAM). SAM capabilities for Copilot are available when at least one user has a Copilot licence assigned, or through the SAM Plan 1 add-on or Microsoft 365 E7.
- Role: SharePoint Administrator or SharePoint Advanced Management Administrator.
- PowerShell: the latest SharePoint Online Management Shell, connected to your admin URL.
- Change window: time to let RCD propagate before you disable RSS. Large sites can take more than a week.
Connect-SPOService -Url https://contoso-admin.sharepoint.comStep 1: Record the current RSS configuration
Before you change anything, capture what RSS is doing today. You can't rely on turning it back on later, because new enablement is blocked.
# Enabled or Disabled
Get-SPOTenantRestrictedSearchMode
# Sites currently on the allow list
Get-SPOTenantRestrictedSearchAllowedList | Out-File -FilePath "C:\RSS\rss-allowlist.txt"Keep the output with your change record. The allow list tells you which sites someone already reviewed and judged safe for organization-wide discovery. Everything outside that list is what RSS was hiding.
Step 2: Decide which sites need RCD
Don't invert the allow list blindly. A tenant with 5,000 sites and a 100-site allow list would end up with RCD on 4,900 sites, which Microsoft specifically warns against: excessive use reduces the content available to search and Copilot and degrades answer quality.
Instead, build a risk-based list:
- Run the Data access governance site permissions report (SharePoint admin center > Reports > Data access governance > Site permissions across your organization). Sort by number of users with access, EEEU permission count and Anyone link count.
- Run the activity reports for sharing links and "Everyone except external users" to see where oversharing is happening now.
- Add sensitivity: in the Microsoft Purview portal, use DSPM > Discover > Data risk assessments to find sites that combine broad access with sensitive information types. The Protect tab has a Restrict all items action that applies RCD directly.
- Use the Content Management Assessment (SharePoint admin center > Advanced Management > Start assessment) or the SharePoint Admin Agent if you have them, to surface ownerless, inactive and overshared sites.
Microsoft's own examples of high-risk sites are those where several signals overlap: sensitive data with "Anyone" links, public sites with no owner, and large audiences with broken inheritance. Typical first candidates are finance, HR, legal and executive sites that haven't had a permissions review.
The detailed reporting process is covered in Prepare a tenant for Microsoft 365 Copilot by fixing oversharing first.
Save the final list as a CSV with a Url column, for example C:\RCD\rcd-sites.csv.
Step 3: Apply Restricted Content Discovery
For a handful of sites, use the SharePoint admin center:
- Expand Sites and select Active sites.
- Select the site.
- On the Settings tab, turn Restrict content from Microsoft Copilot on.
- Select Save.
For a list of sites, use PowerShell:
$sites = Import-Csv -Path "C:\RCD\rcd-sites.csv"
foreach ($site in $sites) {
Set-SPOSite -Identity $site.Url -RestrictContentOrgWideSearch $true
Get-SPOSite -Identity $site.Url | Select-Object Url, RestrictContentOrgWideSearch
}Sites with RCD applied show a Restricted tag.
Optional: let site administrators manage it
By default only SharePoint administrators can change RCD. If you want site administrators to manage the setting on their own sites, for example to remove it after a permissions review, turn on delegation:
Set-SPOTenant -DelegateRestrictedContentDiscoverabilityManagement $true
Get-SPOTenant | Select-Object DelegateRestrictedContentDiscoverabilityManagementSite administrators must enter a justification when they change the setting, and both the change and the justification are recorded in the Purview audit log.
Step 4: Confirm coverage and propagation
Generate the tenant-wide RCD report to confirm the setting is on where you expect:
Start-SPORestrictedContentDiscoverabilityReport
# Check status and get the report ID
Get-SPORestrictedContentDiscoverabilityReport
# Download when complete
Get-SPORestrictedContentDiscoverabilityReport -Action Download -ReportId <ReportGUID>Compare the downloaded list with your CSV. Then allow time for search to catch up. RCD is a site-level property that has to propagate through the indexing systems; latency depends on the number of items in the site and how many sites are being updated at the same time. For sites with more than 500,000 items, expect more than a week.
Test with a pilot account that has access to an RCD site:
- Search for a distinctive term from that site on SharePoint home or Office.com. It shouldn't appear.
- Ask Microsoft 365 Copilot Chat a question that only that site can answer. It shouldn't use that site's content.
- Open the site directly. The user should still have access, and the Copilot button and AI actions should be gone.
Step 5: Turn off Restricted SharePoint Search
Once RCD is effective on your high-risk sites, disable RSS:
Set-SPOTenantRestrictedSearchMode -Mode Disabled
Get-SPOTenantRestrictedSearchModeBefore you run it, tell users, Copilot agent owners and the service desk what will change. Microsoft's own guidance notes that search and Copilot results change when RSS is disabled: content from every site a user has permission to, other than RCD sites, becomes discoverable again. That is the intended outcome, but people will notice more results, and some will notice content they didn't know they could open. Treat those reports as oversharing findings and feed them into Step 6.
Because new enablement is blocked from July 31, 2026, assume you won't be able to turn RSS back on after you disable it. That is why Steps 3 and 4 come first.
Step 6: Fix the permissions and remove RCD
RCD, like RSS, is meant to buy time. For each site you protected:
- Start a site access review from the relevant Data access governance report so the site owner removes EEEU grants, broad groups and organization-wide links.
- When the review is complete, rerun the reports to confirm the exposure has dropped.
- Remove RCD so the content is available to Copilot again:
Set-SPOSite -Identity https://contoso.sharepoint.com/sites/finance -RestrictContentOrgWideSearch $falseFor sites that must stay limited to a defined audience permanently, restricted access control (access limited to members of up to 10 Microsoft 365 or Entra security groups) or Purview DLP for Copilot are longer-term controls than RCD.
Troubleshooting
| Symptom | Cause and fix |
|---|---|
| A site with RCD still appears in search or Copilot | Propagation isn't finished. Latency depends on the number of items and how many sites are being updated; sites with more than 500,000 items can take more than a week. Also check whether the user is searching from within the site or asking Copilot about a document they already have open, which RCD doesn't affect. |
| Content from an RCD site still appears in site search | Expected. RCD doesn't affect searches that start in the site's own context, or Microsoft 365 Feed and Recommendations. |
| You can't apply RCD to a OneDrive URL | Not supported. RCD applies only to SharePoint sites. |
| The RCD setting is missing from the admin center | The organization doesn't meet the licensing prerequisite: a Copilot licence and SAM. |
| Copilot answers got noticeably worse after rollout | Too many sites have RCD. Remove it from sites that aren't high risk and fix permissions instead. |
| You need to turn RSS on for a new tenant or pilot | Not possible: new RSS enablement is blocked from July 31, 2026. Use RCD. |
| eDiscovery can't find content on an RCD site | RCD doesn't remove content from the index, so check the search query and locations rather than RCD. |
Closing checklist
- RSS mode and allow list exported and stored with the change record.
- High-risk sites identified from Data access governance reports and DSPM, not by inverting the allow list.
- RCD applied with PowerShell or the admin center and confirmed with the RCD report.
- Propagation tested with a pilot account.
- Users, agent owners and the service desk told before RSS is disabled.
Set-SPOTenantRestrictedSearchMode -Mode Disabledrun and confirmed.- Site access reviews started for every RCD site, with a date to remove RCD.
If you also build your own retrieval applications over SharePoint content, see RAG over SharePoint documents with permission trimming kept intact for how those applications respect the same permissions.
References
- https://learn.microsoft.com/en-us/sharepoint/restricted-sharepoint-search
- https://learn.microsoft.com/en-us/sharepoint/restricted-sharepoint-search-admin-scripts
- https://learn.microsoft.com/en-us/sharepoint/restricted-sharepoint-search-allowed-list
- https://learn.microsoft.com/en-us/sharepoint/restricted-content-discovery
- https://learn.microsoft.com/en-us/sharepoint/sharepoint-advanced-management-prerequisites
- https://learn.microsoft.com/en-us/sharepoint/data-access-governance-reports
- https://learn.microsoft.com/en-us/sharepoint/site-access-review
- https://learn.microsoft.com/en-us/sharepoint/restricted-access-control
- https://learn.microsoft.com/en-us/microsoft-365/copilot/get-ready-copilot-sharepoint-advanced-management
- https://learn.microsoft.com/en-us/purview/data-security-posture-management-oversharing