Free live webinar · Oct 8 — Get your Microsoft 365 AI-ready before Copilot reads the wrong file. Reserve a seat →
Polaris Governance

Field note

Restricted Content Discovery and the pre-Copilot cleanup: what actually reduces reach

Restricted Content Discovery hides sites from Copilot and search — but Microsoft's own docs say it doesn't change a single permission. A practitioner's playbook for the pre-Copilot cleanup: what merely hides exposure, and what actually reduces it.

There’s a switch in the SharePoint admin center called Restrict content from Microsoft 365 Copilot. Flip it on a site and that site’s content stops surfacing in Copilot responses and organization-wide search. For a team staring down a Copilot rollout and a decade of accumulated oversharing, it looks like the fix.

Microsoft’s own documentation says otherwise, in plain text, in the notes: “Restricted Content Discovery doesn’t change existing permissions. Users who already have access to content can continue to access that content directly.” And a paragraph later: it “is designed as a temporary governance control that gives organizations time to review and right-size access” (Restricted Content Discovery).

That’s the whole distinction this post is about. RCD reduces discoverability. It does not reduce reach — who can actually access what. Both matter in a Copilot deployment. Only one of them is the fix. Confuse them and you’ll declare victory over exposure you’ve merely hidden.

What RCD actually does — and doesn’t

Read the doc closely and RCD is a well-scoped tool with well-documented edges:

It does: remove a site’s content from organization-wide search and Copilot discovery experiences; remove the AI entry points on the site itself (the Copilot button, AI actions menus including agent creation, “Create pages with AI”); tag the site as Restricted; log enable/disable events and justifications to the Purview audit log.

It doesn’t: change any permission; stop a user with access from opening content directly or from a link; remove anything from the search index (Purview eDiscovery and auto-labeling keep working); affect searches from site context or content already in use, like summarizing an open document; apply to OneDrive sites at all.

And it isn’t instant: the setting must propagate through indexing. For sites with more than 500,000 items, Microsoft says an update “could take more than a week to fully process.” The docs also carry an explicit caution against overuse — restrict too much and you degrade the completeness of search and Copilot for everyone, which is the tool’s cost side.

None of this is a flaw. It’s what the feature is for: buying review time during a phased rollout. The failure mode is treating the time-buyer as the cleanup.

Why hiding feels like fixing

Before Copilot, most oversharing was invisible in practice — the file shared to “Everyone except external users” in 2019 sat undisturbed because nobody searched for it. AI collapsed that comfortable gap: Copilot will cheerfully synthesize an answer from any file the asking user can technically reach. We’ve written about that shift in Oversharing was always there — AI just made it answerable.

RCD, used alone, rebuilds the old obscurity — this time as a deliberate policy. The grant is still there. Every user who could open the file still can. Every sharing link still works. And the exposure that existed before Copilot — a curious browser, a departing employee, a compromised account, the next AI surface you enable — is untouched. Your effective reach is identical the day after you flip the switch. You’ve changed what’s easy to find, not what’s possible to access.

The sequence that actually reduces reach

Microsoft’s own deployment blueprint for a secure Copilot foundation puts “remediate oversharing” first among its pillars, leaning on SharePoint Advanced Management (included with the Microsoft 365 Copilot license) and Purview. Assembled into an order of operations, the pre-Copilot cleanup looks like this:

1. Measure before you touch anything. Run the Data Access Governance reports: the site permissions snapshot to find sites with the broadest exposure — thousands of users, guests, “Everyone except external users” (EEEU) — plus the sensitivity-label snapshot, and the activity reports for new sharing links and new EEEU grants in the last 28 days. The snapshot is your baseline; the activity reports are the leak you’re re-plugging every month.

2. Fix the grants themselves. This is the unglamorous center of the whole exercise: remove EEEU and “Everyone” where they don’t belong, expire stale sharing links, repair the broken-inheritance sprawl. DAG’s special-SharePoint-groups report exists precisely for this — it lists exactly which items are effectively public and how the access was granted, “so you can accelerate cleanup through scripting instead of depending on site owners.” Grant removal is the only step on this list that shrinks reach for every current and future surface at once — Copilot, search, agents, and plain human browsing.

3. Delegate what you can’t adjudicate centrally. Admins can see that a site is overshared; they usually can’t judge what’s correctly shared. Site access reviews initiated from a DAG report push that judgment to site owners, with a record of who reviewed what.

4. Enforce hard boundaries where review isn’t enough. For genuinely sensitive sites, restricted access control (RAC) is the instrument that actually changes access: users outside the designated groups “can’t access the site or its content, even if they had prior permissions or a shared link” — and search and Copilot honor the policy as a consequence of the access change, not as a substitute for it. That’s the structural difference between RAC and RCD: one closes the door, the other unlists the address.

5. Now use RCD — selectively, with an exit date. Applied to the high-risk sites from step 1 while their reviews run, RCD is doing exactly its documented job. The discipline is the exit: when a site’s review completes, the restriction comes off. A site that’s been “temporarily” restricted for a year isn’t governed — it’s hidden, unreviewed, and quietly excluded from every answer Copilot gives.

The metric that keeps you honest

Track one number through the cleanup: effective reach — how many people can access each site, resolved through group membership, sharing links, and inherited grants, not just direct permissions. Steps 2–4 move that number. RCD doesn’t, and won’t, and its own documentation tells you so.

When we’ve scored effective reach across real estates — hundreds of sites, permissions accreted over a decade — the pattern is consistent: the sites everyone worries about are rarely the sites with the widest actual reach, and nobody can tell the difference until it’s measured. Discoverability is what your users experience. Reach is what your auditor, your attacker, and your next AI rollout experience. Clean up the second one; use RCD to buy the time to do it right.


Polaris Governance Hub runs inside your own Microsoft 365 tenant and measures effective reach — who can actually access what, resolved through groups, links, and inheritance — so you can see whether cleanup is reducing exposure or relocating it. We’re taking a small number of design partners. See what Copilot can reach in your estate.

More field notes · Full archive · RSS · How the product works