A temporary allow-list for rollout: Restricted SharePoint Search

Completed

Restricted Content Discovery hides a site from search. Restricted Access Control locks a site's front door to one group. Both apply site by site. Relecloud's Copilot rollout is about to stop being a Finance-only pilot and become a company-wide switch—and the data access governance reports from earlier in this module didn't surface one overshared site, they surfaced dozens, scattered across a tenant where the permissions review isn't finished yet. Reviewing every one of those sites before Copilot goes live for everyone isn't realistic on the rollout's timeline. In that position, an admin historically reached for something broader: a single, tenant-wide allow-list that covers the whole rollout at once, instead of a decision per site.

What Restricted SharePoint Search was designed to do

Restricted SharePoint Search (RSS) maintains a tenant-wide allow-list of up to 100 SharePoint sites. Add a site to that list, and it participates in organization-wide search results and in Copilot's chat and agentic answers. Leave a site off the list, and it drops out of those broad, tenant-wide experiences. An admin building this list for Relecloud might start with sites already confirmed clean—the company intranet, HR's public policy site, a couple of departmental sites with a straightforward permission model—and use that shortlist as a temporary net for the rollout while the rest of the review continues in the background.

That's the appeal: one setting, applied once, covering the entire tenant, instead of a per-site decision. RSS is the tenant-wide counterpart to what Restricted Content Discovery does one site at a time.

That 100-site limit is looser than the number alone suggests, though. When you add a hub site to the allow-list, every site associated with that hub is covered too, and the associated sites don't count against the 100. Building the allow-list around a few well-configured hubs lets a single slot cover a whole family of associated sites—which is how many organizations stretched RSS further than 100 individual entries would allow. The catch that goes with it: those associated sites inherit their spot on the allow-list from the hub, so their permissions have to be as clean as the hub's before you enroll it.

RSS also takes effect within about an hour of being enabled, much faster than the search-index propagation delays that RCD and RAC can hit on large sites.

Like Restricted Content Discovery, RSS is not a security boundary, and it doesn't change a single permission. A site left off the allow-list doesn't become inaccessible—it only drops out of broad, organization-wide search and Copilot discovery. Someone who owns a document, opened it recently, or received it through a direct share or a working link still reaches it, and Copilot can still surface that content to them individually, allow-list or not. RSS narrows what shows up in broad discovery. It was never a way to lock a site down—that job belongs to Restricted Access Control.

The retirement, stated plainly

Important

Restricted SharePoint Search is retiring. Starting July 31, 2026, new enablement is blocked. Microsoft's current guidance points organizations to Restricted Content Discovery—covered earlier in this module—as the comprehensive control for content discoverability going forward, alongside SharePoint Advanced Management and Microsoft Purview more broadly.

If Relecloud's rollout wraps up before that date, RSS technically remains available for the time being, but this unit doesn't teach it as a forward-looking option. Plenty of admins inherit a tenant that configured RSS before the cutoff, and for them, understanding what the allow-list does still explains real behavior they troubleshoot today. Past that, treat RSS as a retired control: don't plan new adoption of it, don't build a rollout strategy around it, and don't recommend it to a colleague designing governance from scratch.

Why a temporary control gets retired

Look at what RSS actually solved: a tenant-wide shortcut for a moment when the site-by-site review isn't finished. That's exactly the profile of a control with a limited shelf life—it addresses a transition, not a destination. Restricted Content Discovery now gives admins a discoverability control at the scope that matches most real hardening decisions: the individual site, not the entire tenant at once. Once that option existed, an all-or-nothing tenant-wide allow-list stopped being the sharper tool for a tenant where some sites need hiding and others need the harder access boundary that Restricted Access Control provides.

Guiding question: RSS solved a real problem—reviewing every site before a company-wide Copilot rollout isn't realistic on a tight timeline. Why might Microsoft retire a control that solves a real problem like that, instead of keeping it running alongside Restricted Content Discovery?

Every control this module covers so far—Restricted Content Discovery, Restricted Access Control, and now Restricted SharePoint Search—describes itself as an interim measure. None of them fix a permission. None of them replace the work of getting a site's sharing settings and access model right in the first place—the work Units 2 through 4 cover. RSS's retirement doesn't undercut that lesson; it's the clearest proof of it. A bridge control that outlives its bridge gets replaced by a sharper bridge, or the destination gets close enough that the bridge isn't needed anymore.

What this means for Relecloud today

For a company-wide rollout, the honest plan doesn't lean on a tenant-wide allow-list that closes to new adoption in a matter of weeks. The reports from Unit 4 already show which sites are overshared. Restricted Content Discovery pulls each of those out of broad search and Copilot discovery right away. Restricted Access Control locks down the handful that need a real permission boundary, not just reduced visibility. Neither one depends on a feature with an expiration date.

Learn more about Restricted SharePoint Search, including the 100-site limit, the retirement timeline, and the move to Restricted Content Discovery.

Restricted Content Discovery hides. Restricted Access Control locks. Restricted SharePoint Search allow-listed, tenant-wide, only until July 31, 2026. Three controls, three different jobs, one of them already sunsetting. The next unit lines them up side by side and answers the question every admin actually needs answered: given a specific requirement, which one of these does the job—today, not a version of today that assumes a retiring feature is still an option?