Summary
You can now govern SharePoint and OneDrive so that Microsoft 365 Copilot surfaces only what a user's own permissions already allow, and you can pick the right control when a site needs tighter discoverability or access than those permissions provide.
What you learned
- Site creation and permissions: Team sites and communication sites use different permission models, and deliberately assigning owners, members, and visitors—not a Copilot setting—sets a site's real exposure boundary.
- Sharing settings and the Copilot boundary: Copilot grounds only on content a user's permissions and sharing settings already allow, so the organization-wide external sharing settings for SharePoint and OneDrive set a ceiling that sites can restrict but never exceed.
- Data access governance reports: Snapshot reports establish a baseline of existing oversharing, and activity reports catch new oversharing as it happens. Microsoft 365 E5 alone includes only the activity reports (capped at 10,000 sites and requiring data collection to be enabled first); the snapshot reports—including the site permissions report—require SharePoint Advanced Management, which Relecloud's Copilot rollout unlocks.
- Restricted Content Discovery: Restricted Content Discovery hides a site from organization-wide search and Copilot's broad discovery, without changing a single permission or blocking anyone who already has access.
- Restricted Access Control: Restricted Access Control limits a site to members of designated Microsoft Entra or Microsoft 365 groups, overriding existing permissions and sharing links for everyone else.
- Restricted SharePoint Search: Restricted SharePoint Search maintains a tenant-wide allow-list of up to 100 sites, but it's retiring—new enablement blocks starting July 31, 2026—so plan around Restricted Content Discovery instead.
- Choosing the right control: Matching a requirement to the right control comes down to whether the goal is hiding content, blocking access outright, or applying a temporary tenant-wide allow-list.