Hide it from search, not from access: Restricted Content Discovery

Completed

You know which switch you flipped. Now find out what it actually flipped.

Go back to the moment from the introduction: you turned on "Restrict content from Microsoft 365 Copilot" for the Finance site, and within a day the site dropped out of organization-wide search and stopped showing up in Copilot's answers to general prompts. Before you learn what that setting really does, make a prediction.

Guiding question: When you turn on "Restrict content from Microsoft 365 Copilot" for a site, does that setting change who has permission to the site's content, or does it only change where that content can show up? Guess before you keep reading.

If you guessed the setting changes permissions, you're in good company—that's the answer most administrators give, because a setting called "restrict content" sounds like an access control. It isn't one.

Restricted content discovery changes visibility, not access

Restricted Content Discovery (RCD) never touches a site's permissions. It doesn't remove anyone from a group, revoke a sharing link, or change who's an owner, member, or visitor. What it does is narrower and more specific: it pulls a site's content out of organization-wide search and out of the broad, general-purpose discovery that Microsoft 365 Copilot relies on when it grounds answers to open-ended prompts. Turn it on for the Finance site, and that site stops appearing when someone across the company asks Copilot something unrelated and Copilot goes looking for anything that might be relevant.

That's exactly what you saw. The Finance site vanished from general search and from Copilot's broad answers. Job half done—the part RCD is actually built to do.

Here's the part it was never built to do, and the part that explains your marketing employee. That person already had access to the Finance site, almost certainly through the same broad "Anyone" or "Everyone except external users" sharing that got the site flagged as overshared in the first place. RCD doesn't check for that kind of access and doesn't revoke it. On top of that, RCD explicitly still allows Copilot to surface content a user owns or has recently interacted with, even on a restricted site—so if that marketing employee had ever opened, edited, or otherwise touched the file Copilot cited, RCD's restriction doesn't apply to that file for that person. Two gaps, same result: permissions nobody removed, plus a documented exception for owned or recently touched content. Add them together, and "hidden from search" quietly stops meaning "inaccessible."

What restricted content discovery leaves untouched

RCD's scope is narrower than a single phrase like "restrict content" suggests, and it's worth knowing exactly where the boundary sits so you don't assume it covers more than it does. RCD explicitly doesn't affect any of the following:

  • Site-context search — a user browsing directly inside the Finance site can still search within it and find everything they're permitted to see.
  • Microsoft 365 Feed and Recommendations — content can still surface there for people with existing access.
  • Microsoft Purview capabilities — eDiscovery, auto-labeling, and similar compliance features keep working against the site exactly as before, because those tools were never part of what RCD was designed to gate.

Line those exclusions up against what marketing employee actually did, and the picture holds together. RCD only ever promised to shrink the surface area of general search and Copilot discovery—not to seal the site off from everyone who could already reach it through some other path.

A per-site remediation control, not a permanent lock

Restricted Content Discovery operates one site at a time, which makes it a fast, targeted response to a specific site you've flagged, not a blanket policy you set once across the tenant. That scope is deliberate: it's meant as an interim remediation step, something you apply to a site while you sort out its underlying sharing problem, not a substitute for fixing that sharing problem.

Because it's meant to be applied and adjusted as circumstances change, SharePoint lets you delegate the decision to site administrators instead of routing every change through central IT—but every change still requires a documented justification, so there's a record of why a given site was restricted or unrestricted at a given time. That accountability matters more once you remember RCD isn't instant. For most sites the change reflects quickly, but for large sites—those with 500,000 items or more—the setting has to propagate through search indexes across the tenant, and that can take more than a week to fully take effect. Turn on RCD for a site that size and assume it's already working, and you can spend days operating on a false sense of security.

None of this would be available to you yet if Relecloud hadn't already cleared one licensing bar. Restricted Content Discovery is one of the SharePoint Advanced Management capabilities that unlocks the moment at least one user in the organization holds a Microsoft 365 Copilot license—a condition the previous unit confirmed Relecloud's company-wide rollout already satisfies. That's why the toggle was there for you to flip on the Finance site at all.

Learn more about restricted content discovery, including delegation, justification requirements, and PowerShell management for the feature.

Hidden isn't the same as locked down

Put it all together, and the marketing employee's answer stops looking like a mystery. RCD did exactly what it was built to do: it pulled the Finance site out of organization-wide search and general Copilot discovery. It was never built to do the other thing its name might suggest—govern who can reach the site's content at all. The employee could still see that Finance data because RCD isn't an access control and never claimed to be one. That's not a bug in the feature; it's the entire difference between a discovery control and an access control.

Which leaves the Finance site's real problem still open. If RCD can hide a site from search without ever locking it down, what control actually restricts who can reach the content in the first place?