An approach to using Restricted SharePoint Search
I believe that organisations should be reviewing their security frequently and especially performing audits prior to launching Copilot.
However, I do also understand that this takes time and being able to allow some sites to work within Copilot ensures that your organisation can continue to improve and modernise, whilst security is being resolved in parallel.
A good place to start would be reviewing the SharePoint Admin Centre and seeing which sites hold the most data, and which are the most frequently and recently used.
This will then give an indication of the appropriate sites that you should definitely consider allowing, as lots of old empty sites will not be beneficial for Copilot engagement.
The sites that you are considering adding to the “allowed list” should be risk assessed.
Essentially asking the question as to “If someone who we think should not have access to this site does, how much concern/damage would this cause?” – any sites that are high risk should be added to a backlog for proper security review, and may essentially form a phase 2 set of sites for you to add to the “allowed list” e.g. Human Resources.
Note that you can only currently add up to 100 allowed sites, so do be cautious if you have a large quantity of site collections and decide to switch this on, as it could become a limiting factor for your Copilot usage – if this is the case it can always be switched back off again as it is by default.
Whilst going through this exercise I would also advise that less frequently used sites and those contain zero or very minor amounts of data should also be reviewed, with archival or deletion being a sensible approach. Any of these sites that remain then for a phase 3 set of sites to be added to the “allowed list”.
Governance will need to be in place for each new site collection that is built, if Restricted SharePoint Search is enabled. This is because any new site created will not be added to the “allowed list” by default, so deciding whether it is or is not to be added would need to occur during the site build phase.
Finally, if the right governance, security measures, frequent security audits and more is in place, I would be advising that the Restricted SharePoint Search is switched back to its default state of being disabled, so as to avoid the 100 site limit and reduce additional time to update and configure this functionality. Leading to an organisation that is AI embedded, security conscious and administration efficient.