Microsoft has told administrators that it will stop allowing organizations to turn on Restricted SharePoint Search for the first time after July 31, 2026. The move pushes companies to adopt more permanent content governance tools rather than relying on a temporary safety switch that limits where organization-wide search and Copilot can look.
The shutoff: No new Restricted Search instances after July 31
Restricted SharePoint Search was introduced as a quick-limit mechanism: admins could specify a list of SharePoint sites that would be the only ones available to enterprise-wide search experiences and Microsoft 365 Copilot. Anything outside that list was effectively invisible to AI and broad queries. Starting July 31, 2026, Microsoft will block any tenant from enabling this feature for the first time. Tenants that already have it turned on may continue using it—Microsoft hasn’t said when or if those will be forcibly transitioned yet—but new deployments are off the table. The message is clear: the training wheels are coming off.
Microsoft wants you to use these alternatives instead
In its advisory, Microsoft points organizations toward three key alternatives:
- Restricted Content Discovery: A more surgical tool that lets you hide specific high-risk sites from search and Copilot, rather than blocking everything except an allow-list.
- SharePoint Advanced Management: Suite of governance features including oversharing reports, inactive site policies, and access reviews.
- Microsoft Purview: For sensitivity labeling, data loss prevention, and broader information protection that Copilot respects.
For IT admins: The clock is ticking on your Copilot safety blanket
If your organization turned on Restricted SharePoint Search to prevent Copilot from accidentally surfacing sensitive data while you figured out permissions, you’re now on notice. July 31 isn’t just a feature deprecation—it’s the end of a temporary patch. You need to shift from an allow-list mindset to a proper data classification and permissions model. This means:
- Auditing site permissions and membership groups
- Applying sensitivity labels to critical content
- Reviewing external sharing links
- Identifying ownerless or abandoned sites
- Training content owners on metadata and lifecycle management
The alternative isn’t just losing a feature; it’s the risk that incorrectly shared files suddenly become discoverable by anyone in your org via a natural-language Copilot query. In large tenants, that could expose thousands of documents that were previously hidden only by the restricted list, not by actual access controls.
A note for existing Restricted Search tenants
If you already have Restricted SharePoint Search enabled, July 31 doesn’t force an immediate change. However, Microsoft is clear that this is a dead-end path. You should plan a migration to the recommended alternatives now, before the next compliance audit or Copilot rollout uncovers a governance gap. The longer you wait, the harder the cleanup.
For everyday users: More powerful search, but don’t trust everything
Once Restricted Search is gone (and your admins have done their homework), you’ll likely see Copilot and enterprise search pull from a broader set of corporate knowledge. That means faster answers, but also a need for caution. Always check the source document when Copilot generates a summary, and report anything that looks like it shouldn’t be visible. Your feedback helps governance teams tighten up. If you’re a content owner, expect more frequent reminders about reviewing your files and permissions.
How we got here
When Microsoft launched Copilot for Microsoft 365, it promised that the AI would only reveal information a user already had permission to access. But many organizations realized they had years of accumulated oversharing: broad SharePoint groups, “everyone except external users” permissions, and forgotten confidential files in team sites. To give breathing room, Microsoft created Restricted SharePoint Search in early 2025 as an opt-in setting. It forced Copilot and organization-wide search to only index sites an admin explicitly listed. The idea was that you’d use this while cleaning up permissions, then turn it off.
By mid-2026, Microsoft saw that many had gotten stuck—keeping the restricted list indefinitely instead of fixing the root problem. The company has been signaling this shift for months, pointing to the maturity of Restrict Content Discovery (which entered general availability earlier in 2026) and improvements in SharePoint Advanced Management. The July 31 cutoff is the formal line in the sand.
Five steps to take before the deadline
-
Run an oversharing report
Use SharePoint Advanced Management or PowerShell to identify sites with excessive membership, broken inheritance, or external sharing links that are too permissive. Focus on sites containing financial, HR, legal, or personally identifiable data. The report should list site URLs, owners, and the nature of the risk. -
Implement Restricted Content Discovery for high-risk sites
This is the direct replacement if you have a handful of sensitive repositories. You can hide those specific sites from Copilot and broad search while you remediate, without blocking everything else. It’s more scalable than an allow-list and easier to update as your environment changes. -
Roll out sensitivity labels with protection
Labels that auto-classify documents and enforce encryption or access restrictions work with Copilot. A “Highly Confidential” label, for example, can prevent Copilot from using that content in answers—regardless of site permissions. Start with a pilot on a few libraries before expanding tenant-wide. -
Assign site owners and set up review schedules
Every site needs a human owner. Use PowerShell or the SharePoint admin center to identify ownerless sites, then assign them. Set a cadence (quarterly works) for owners to confirm access and content relevance. Microsoft’s SharePoint Admin Agent (in preview) can help surface sites that haven’t been modified in months. -
Train employees on responsible AI use
Reinforce that Copilot is a tool, not an oracle. Employees should verify critical info against official sources and understand how to flag potential oversharing. This isn’t just a one-time webinar—integrate these habits into the flow of work with quick reference cheat sheets and Teams channel reminders.
Outlook
This July 31 cutoff is one milestone in a larger Microsoft push to weave AI governance into the fabric of Microsoft 365. Expect future capabilities like AI-assisted site audits, automated policy recommendations, and even Copilot agents that monitor sharing patterns. The takeaway: the era of temporary switches is ending. Organizations that invest in information architecture—metadata, authoritative content locations, regular reviews—will not only survive this transition but will get far more value from Copilot. Those that don’t may find their digital workplace is just a faster mirror of its own disorder.