Skip to main content
Valto — Keep ahead of tomorrow

News

What is Restricted SharePoint Search?

Explore how Microsoft’s Restricted SharePoint Search tool helps organisations control which SharePoint sites can be included in Microsoft Copilot experiences, providing a balance between data security and Copilot adoption.

CopilotSharePoint
Published
6 January 2025
What is SharePoint Restricted Search

Preparing Copilot: Restricted SharePoint Search

To support preparation for Copilot activities, Microsoft have provided Microsoft 365 admins with a new set of functionalities to assist in minimising content that is made available to your users.

In this blog article I am going to explore what this new functionality provides and why it is beneficial to those who are starting off on their Microsoft Copilot journey.

What is Restricted SharePoint Search?

Quite simply, Restricted SharePoint Search is a tool that can be used (enabled and configured using PowerShell by SharePoint Administrators and above) to define which of your SharePoint Sites can participate in organisation wide search activities and Copilot experiences.

Interestingly, although the tool is labelled “Restricted” you will actually find that you are defining sites that are ALLOWED, therefore making any site that is not on a configured “allowed list” to actually be restricted – but who am I to make any mention of oddities in Microsoft naming approaches!

What is SharePoint Restricted Search

Why use Restricted SharePoint Search?

The easy answer is so that specific content does not appear when working with Copilot. However, this defeats the object of utilising artificial intelligence (AI) to provide answers, knowledge and support in your day-today work activities. If this is the case, what do I think the real answer to this question is: In my opinion it is all to do with the speed of adopting the Copilot service within your organisation. I have spoken to many clients and been at many events in which a large red flag is raised surrounding Copilot permissions and data/document security, with the most common statement (or versions of this statement) being “What if Microsoft Copilot lets users access documents that they should not see?” – so, let's explore this. Microsoft Copilot does not alter permissions. Microsoft Copilot does not allow users to access anything that they do not already have access to. If a user views the wrong thing, then this is not an error made by Microsoft Copilot but made by your organisation. In reality, Copilot is just uncovering potential security breaches in a quicker fashion, therefore presenting the opportunity for organisations to plug these gaps and think about their security, which is a good thing! To use an analogy, as I like to do so frequently, consider an extremely large maze of which sits a set of data in the centre. Majority of your organisation will struggle to find their way through the maze or will not even consider entering in the first place. Some of your organisation will have a map, so as to easily make their way to the central point and the data it holds. In this scenario both groups of individuals have access, it is just that one set knows where to look. This may be the same in your organisation, as you may think specific data is secure but in reality, it has always been accessible just not that easy to find if you don’t know where to look. The difference with AI is that it will easily breakthrough the maze. How often have you audited this in your own Microsoft 365 tenancy? So why do I think “speed of adoption” is a key driver here? The reason is that Restricted SharePoint Search allows for areas to be completely removed from the Copilot experience, so as to avoid the need of auditing the permissions of those sites. I do not think this should be depended on, but I do believe it buys you some extra time to review security without having to miss out on Microsoft Copilot. As an example, Management, Human Resources and Finance Sites may be left out of your “allowed sites” initially so that you are 100% that confidential data remains this way when working with Copilot. Remember, this only applies to Organisational Search and Copilot, so if you have users that have access when they shouldn’t then you still have organisational risk which is just as sever, albeit not as likely to happen.

An approach to using Restricted SharePoint Search

I believe that organisations should be reviewing their security frequently and especially performing audits prior to launching Copilot.

However, I do also understand that this takes time and being able to allow some sites to work within Copilot ensures that your organisation can continue to improve and modernise, whilst security is being resolved in parallel.

A good place to start would be reviewing the SharePoint Admin Centre and seeing which sites hold the most data, and which are the most frequently and recently used.

This will then give an indication of the appropriate sites that you should definitely consider allowing, as lots of old empty sites will not be beneficial for Copilot engagement.

The sites that you are considering adding to the “allowed list” should be risk assessed.

Essentially asking the question as to “If someone who we think should not have access to this site does, how much concern/damage would this cause?” – any sites that are high risk should be added to a backlog for proper security review, and may essentially form a phase 2 set of sites for you to add to the “allowed list” e.g. Human Resources.

Note that you can only currently add up to 100 allowed sites, so do be cautious if you have a large quantity of site collections and decide to switch this on, as it could become a limiting factor for your Copilot usage – if this is the case it can always be switched back off again as it is by default.

Whilst going through this exercise I would also advise that less frequently used sites and those contain zero or very minor amounts of data should also be reviewed, with archival or deletion being a sensible approach. Any of these sites that remain then for a phase 3 set of sites to be added to the “allowed list”.

Governance will need to be in place for each new site collection that is built, if Restricted SharePoint Search is enabled. This is because any new site created will not be added to the “allowed list” by default, so deciding whether it is or is not to be added would need to occur during the site build phase.

Finally, if the right governance, security measures, frequent security audits and more is in place, I would be advising that the Restricted SharePoint Search is switched back to its default state of being disabled, so as to avoid the 100 site limit and reduce additional time to update and configure this functionality. Leading to an organisation that is AI embedded, security conscious and administration efficient.

Using Canvas Apps to Create Business Applications

SharePoint Restricred Search – Our Expert Says

Restricted SharePoint Search is in placed to safeguard data that is high risk and avoid it being located by Microsoft Copilot. Making use of this service will enable Copilot to be rolled out sooner into your organisation whilst minimising concern for users accessing confidential data.

Restricted SharePoint Search should not be considered a replacement of good governance and security practice, so if it has not already then let the need for Microsoft Copilot and artificial intelligence be your wake-up call to ensure your Microsoft 365 tenancy is fully prepared and secure.

Remember, Microsoft Copilot does not cause the security concerns, it just discovers those that are already in place!

Trusted by Leading Brands

“We work with organisations across many sectors of different shapes and sizes from 10 to 100,000 employees.”

Contact Form

Contact our team today!

Talk to our team

Contact Us

Share this

Related reading