Lock it down for real: Restricted Access Control
You just found where Restricted Content Discovery draws its line: it hides a site from search and Copilot's broad discovery, but it never touches a single permission. That gap matters most when hiding isn't good enough—and Relecloud has a site where hiding isn't good enough.
The legal team just opened an M&A due-diligence site to track a potential acquisition. A handful of people need it: the deal lead, two lawyers, and a finance director. Nobody else in the company—not another admin, not a well-meaning colleague with an old sharing link, not even someone who technically still holds direct permission from a project two years ago—should open that site. Turning on Restricted Content Discovery for this site pulls it out of general search, but anyone who already holds a permission or a link still walks straight through the front door. You need a control that closes the door itself, not one that just removes the site from the directory.
Restricted Access Control closes the door
Restricted Access Control (RAC) limits who can reach a site to members of one or more designated Microsoft Entra security groups or Microsoft 365 groups—up to 10 groups per site. Turn it on for the due-diligence site, add the deal team's security group, and everyone outside that group loses access to the site and its content. That block applies even to users who already hold direct permission to a file, and even to users who hold a valid, previously working sharing link. Restricted Content Discovery leaves every existing permission and link intact; RAC overrides them.
That's the difference that matters for a site like this one. Hiding the due-diligence site from search doesn't stop a lawyer from a prior deal, still holding a two-year-old link, from opening a file today. RAC does stop that, because it checks group membership before it evaluates any permission or link.
Predict before you configure it
Before you turn on RAC, work through one scenario. Suppose the finance director isn't in the deal team's security group yet, and you add them to that group.
Guiding question: If you add a user to a site's Restricted Access Control group, does that user now have access to the site's content? Make your prediction before you keep reading.
No. Group membership alone doesn't grant access. RAC narrows the population of people who are allowed to use their existing permissions—it doesn't hand out new ones. The finance director still needs a permission to the site or its content, granted the normal way, on top of belonging to the RAC group. Add someone to the group without a permission, and they gain nothing: they're allowed through the door, but there's no key in their hand. RAC filters on top of your permission model. It doesn't replace it.
Give search time to catch up
RAC is honored in organization-wide search and Copilot experiences—users outside the RAC group can't see the restricted site's content in either surface. Enforcement of the file itself is immediate (the click fails right away), but the search index takes time to reflect the new policy, and the delay scales with the site's size. Small sites usually catch up quickly. Larger sites, especially those with hundreds of thousands of items, can leave stale titles in search results for hours or longer while the index propagates. Verify from a test account whose access RAC should block before you assume the restriction is fully in effect everywhere.
Learn more about search and Copilot behavior under Restricted Access Control, including the index-propagation caveat.
Turn on RAC for a site
- In the SharePoint admin center, open Active sites and select the due-diligence site.
- Open the site's Policies settings and select Restricted Access Control.
- Select Restrict access, then choose the Microsoft Entra security group or Microsoft 365 group that represents the deal team.
- Add up to 10 groups total if more than one team needs access—for example, the deal team plus outside counsel.
- Save the policy to apply the restriction.
Like Restricted Content Discovery, this setting doesn't have to sit with central IT. You can delegate RAC to site administrators so they restrict or lift access on their own sites, but every change still requires a documented justification, so there's a record of why the due-diligence site was locked down and who approved it.
Learn more about Restricted Access Control, including group limits, the permission-and-membership rule, and PowerShell management for the feature.
A precise fix, not a tenant-wide one
RAC solves the due-diligence site properly: only the deal team reaches it, no matter what permissions or links exist elsewhere. That precision is also its limit. Relecloud doesn't have one overshared site—the data access governance reports from earlier in this module surfaced dozens of them, scattered across the tenant. Configuring RAC site by site, group by group, doesn't scale to that number, and it's more restriction than most of those sites need.
What Relecloud needs next is broader and lighter: a single, tenant-wide switch that controls what shows up in search and in Copilot's answers for the entire rollout—not a group membership rule you apply one site at a time.