This post explains why Microsoft 365 Copilot surfaces sensitive SharePoint and OneDrive content that was already exposed, and why organizations relying on Restricted SharePoint Search to hold that content back are facing a deadline in January 2027. It covers what actually happens when the control retires, how Copilot handles permissions and why the permission model is not the problem, the specific ways oversharing accumulates in a tenant without anyone doing anything wrong, what Microsoft's native tooling genuinely finds and fixes, and the real limits on that tooling that determine how long a cleanup actually takes. If you have enabled Copilot, or plan to, the sequencing matters more than the licensing.
The Deadline Most Tenants Have Not Planned For
Restricted SharePoint Search is retiring.
It was the tenant-wide control that kept SharePoint content out of organization-wide search and Copilot unless a site sat on an administrator-curated allowed list. Microsoft always described it as a short-term measure that gives administrators time to review and audit site and file permissions, and stated plainly that it is not intended or scalable for long-term use.
The retirement schedule is set. New enablement was blocked from July 31, 2026. The feature stops functioning after January 31, 2027, with no extensions. The associated PowerShell cmdlets stop working after February 28, 2027.
Read that as a sequencing problem rather than a licensing one. If your organization turned on Restricted SharePoint Search to buy time while permissions were cleaned up, the clock on that borrowed time runs out in January, and whatever was hidden behind it becomes findable again unless somebody acts.
The replacement is Restricted Content Discovery, a site-level control that keeps a site's content out of organization-wide search and Copilot without changing permissions. It requires a SharePoint Advanced Management subscription, cannot be applied to OneDrive sites, and Microsoft warns that overusing it can degrade performance across search, SharePoint, and Copilot because there is less content available to ground on.
Note what both controls have in common. Neither changes who has access. They hide content from discovery. Anyone with permission can still open it directly. These are curtains, not repairs.
Not sure if this even applies to you? We can confirm whether Restricted SharePoint Search is enabled in your tenant, usually in under a day.
Check My Tenant →Copilot Is Not Creating the Risk
This is the belief worth correcting before anything else, because it sends organizations after the wrong problem.
Copilot presents only data that each individual can access, using the same underlying controls for data access used in other Microsoft 365 services. The semantic index it grounds on honors the user identity-based access boundary, so the retrieval process only reaches content the current user is already authorized to access. Copilot also honors Conditional Access and multifactor authentication, and where content is encrypted with sensitivity labels it honors the usage rights those labels grant.
The permission model is identical before and after a Copilot rollout. Nobody gains access to anything.
What changes is findability, and that distinction is the whole argument.
Before Copilot, over-permissioned content was protected by obscurity. A user technically had rights to a site or a file but had no reason to navigate there and no idea it existed. Keyword search required knowing what to look for and opening results one at a time. Copilot removes that friction. A plain-language question is matched against everything the user can reach and returned as a synthesized answer assembled from scattered sources.
Microsoft's own illustration of the problem is a query about organizational structure returning confidential details of an upcoming reorganization that the person asking was never meant to see.
Which is why “no user has complained” is not evidence of good governance. It is evidence that obscurity held. Absence of complaints measured how hard content was to find, not whether the permissions on it were correct.
One thing to know about the mechanism: semantic indexing is an improvement to Microsoft 365 search and cannot be disabled, and no administrative involvement is required to enable it. There is no switch that opts your tenant out while you get organized.
What Readiness Assessments Actually Turn Up
The findings repeat across tenants, and they are rarely anybody's fault. They are the sum of defaults and years of ordinary use.
Broad access groups on sites nobody audited. All users added to your organization automatically become members of the Everyone Except External Users group. On a group-connected team site set to Public, it carries Edit permission by default. Microsoft's own guidance states that adding it to a site's membership makes the entire content of that site public and more prone to oversharing. Microsoft has already run automated removal of this group from OneDrive root sites and default document libraries, but SharePoint sites remain a manual cleanup item.
Broken inheritance. Permissions can be set at site, library, folder, and item level. Once inheritance is broken, a single item carries unique permissions that diverge from its parent, which is how one sensitive file inside an otherwise controlled library ends up broadly reachable. Assessments surface these as counts, and the counts are usually higher than anyone expects.
Organization-wide sharing links, accumulated over years. A link scoped to people in your organization is usable by any internal user who obtains it, not just the person it was sent to. Company-wide links historically had no expiration, so they build up indefinitely.
Orphaned sites. A site becomes ownerless when the owner's account is deleted or disabled. Microsoft recommends a minimum of two owners per site and provides policies to enforce it, but a group with no members and no owners at all has to be handled manually. Inactive sites remain indexed and remain groundable until they are archived.
Departed employees' OneDrive. Content shared broadly from a personal OneDrive stays reachable by whoever holds access after the person leaves.
None of these required a mistake. That is why the assumption that permissions must be fine because nobody has raised a problem holds up right until somebody runs the report.
What Native Tooling Finds, and Where It Stops
SharePoint Advanced Management capabilities that support a Copilot deployment are available once at least one user in the organization is assigned a Microsoft Copilot license, and that user does not need to be a SharePoint administrator. Most of the tooling below comes with that. Restricted site creation by apps does not, and needs the SharePoint Advanced Management Plan 1 add-on.
The tooling is real. The limits are the part that determines your timeline.
Site permissions snapshot gives an organization-wide baseline: permissioned users, broad-access groups, broken inheritance, guest access, sharing link counts
The web view shows only the top 100 sites by user count. Going further means downloading a CSV and analyzing it offline. The report excludes locked and archived sites
Reports can be re-run to track progress
The first snapshot can take up to five days, data can be up to 48 hours stale, and you can only re-run every 30 days. Activity reports look back 28 days, so older oversharing that has not been recently active does not appear
Site access reviews delegate item-level decisions to site owners, who are the only people who know whether access is appropriate
You can start reviews for up to 100 sites from the web view, and up to 1,000 reviews per calendar month. SharePoint sites only, not OneDrive
Restricted Content Discovery and Restricted Access Control cut exposure quickly
Neither changes permissions. Authorized users still open content directly. Restricted Content Discovery cannot be applied to OneDrive, and overuse degrades search and Copilot answer quality
Purview data risk assessments for AI find overshared content and recommend remediation
The full capability requires Microsoft 365 E5 or E5 Compliance, and the default assessment covers only the top 100 SharePoint sites by usage
Sensitivity labels and auto-labeling protect content at scale, and Copilot honors the rights they enforce
Labeling protects content going forward. It does not change who already has permission. A label deployment is not a permissions fix
Ownership and inactive site policies remediate sprawl
Inactive site policies never delete sites. Removing a broad-access group from a site half the company legitimately uses remains a per-site judgment call
The pattern in the right column is worth naming. The reports tell you where the exposure is. They do not tell you whether any given person should have access, and no tool can, because that is a question about the business rather than the tenant. Site access reviews exist precisely because that judgment has to go to the people who own the content.
Want the specific list, not just the categories? A readiness assessment shows you exactly which sites, files, and links are exposed in your tenant.
See What We’d Find →What the Exposure Actually Costs You
The risk here is unintended internal access, and it is worth being precise about why that matters on its own, with no external breach involved.
The content organizations most regret surfacing is consistent: HR and personnel files, compensation data, reorganization and acquisition material, legal and contract documents, financial forecasts, and customer or patient records. These are exactly the categories that sit in departmental sites with permissions nobody has revisited since the site was created.
Three consequences follow, and they are separate problems.
Where personal data falls under regimes such as GDPR, or where health or financial records carry sector obligations, unintended internal access is a governance failure in its own right. Regulators do not require that data left the building for it to count.
An employee discovering their own salary band relative to a colleague's, or learning about a restructure before it is announced, is a real harm to real people and it does not need a regulator to be damaging.
The version that hurts most is not a headline. It is the moment employees stop trusting that the organization handles their information carefully, which also slows adoption of the tool you just paid for.
On numbers: no reliable Microsoft-published figure exists for how common oversharing is. Figures do circulate, but they come from vendors with governance products to sell, so we are not repeating them. The absence of a statistic is not the absence of a problem. It just means the honest answer is to measure your own tenant rather than trust somebody else's average.
What to Do Before January
Check first whether Restricted SharePoint Search is enabled in your tenant. If it is not, this deadline does not apply to you and the rest still does.
If it is, list the sites currently on your allowed list. Those are the sites your organization already decided were safe to surface, which means everything not on it is content somebody chose to hide. That list is your remediation queue, and it is a better starting point than a blank assessment.
Then run the permissions baseline and work the report caps into your plan rather than around them. A 30-day re-run cadence and a 1,000-review monthly ceiling mean a large estate is a multi-month program, not a sprint. Organizations that discover this in December have a problem.
Apply Restricted Content Discovery to genuinely high-risk sites as a bridge, with a named owner and an exit date on each one. Treat it as temporary, because Microsoft does, and because leaving it on degrades the thing you bought Copilot for.
Push the actual access decisions to site owners through access reviews. They are the only people who can judge whether the marketing team should still reach a folder somebody shared with them in 2021.
One caution on cleanup. Deleting an ownerless group also removes its SharePoint site, group mailbox, and plans. They sit in the recycle bin for 30 days and then they are gone. This is the item most often unpicked afterwards, and often it cannot be.
WME runs Copilot readiness assessments covering permission baselining, oversharing remediation, and a sequenced plan that fits the reporting limits rather than ignoring them.
Sequencing matters more than licensing.
Find out exactly where your tenant stands, and get a sequenced remediation plan, before the clock runs out.
REQUEST A READINESS ASSESSMENT →

