If your organization turned on Restricted SharePoint Search to keep Microsoft 365 Copilot away from your permission sprawl, you have two dates to care about. On July 31, 2026 — three weeks from now — Microsoft stops letting tenants enable it. On January 31, 2027, it is retired outright. And the part most teams have missed, buried in message center notice MC1395311: your configuration does not carry over to the replacement. When the feature goes, the fence goes with it, and everything it was hiding becomes findable again — by search, and by Copilot.
This is a guide for the teams who used RSS as their Copilot guardrail: what actually changes, what Restricted Content Discovery does and doesn't replace, and a migration plan that treats the retirement as the forcing function it really is.
Last verified: July 11, 2026 against Microsoft's Restricted SharePoint Search documentation and the Restricted Content Discovery documentation.
What Restricted SharePoint Search was actually doing for you
RSS was Microsoft's pressure-release valve for the Copilot oversharing problem. When it became clear that Copilot would happily surface any file a user technically had access to — the salary spreadsheet on an open site, the M&A folder shared with "Everyone except external users" years ago — Microsoft offered a blunt fix: restrict organization-wide search, and therefore Copilot's tenant grounding, to a curated allowlist of up to 100 SharePoint sites. Everything off the list disappeared from org-wide discovery.
It was always described as temporary. The docs said "interim," the field said "training wheels," and everyone deployed it anyway, because it let you ship Copilot before finishing a permissions cleanup that most tenants had been deferring for a decade. That is exactly why the retirement stings: for a lot of organizations, RSS didn't buy time for the cleanup — it replaced it.
The dates that matter
| Date | What happens | What it means for you |
|---|---|---|
| July 31, 2026 | New RSS enablement blocked | If you planned to turn it on as part of a Copilot rollout this year, that option is gone in three weeks. Your rollout plan needs a different guardrail. |
| January 31, 2027 | RSS retired for all tenants | The allowlist stops working. Sites it was hiding return to org-wide search and Copilot grounding. |
| Retirement day, if you do nothing | Silent expansion of what Copilot can see | No banner, no admin alert per site — content that was undiscoverable on January 30 is discoverable on February 1. Every oversharing problem RSS was masking comes back at once. |
Read that last row twice. RSS never changed permissions — the files were always accessible to anyone with a direct link. What it suppressed was discoverability. Retirement doesn't create new access; it restores the search index's honesty about the access you already granted. Copilot is simply the fastest reader of that index.
Restricted Content Discovery replaces it — but it's not a migration
Microsoft's successor is Restricted Content Discovery (RCD), part of SharePoint Advanced Management — which is now included with Microsoft 365 Copilot licenses. It is a better-designed control, and understanding the difference explains why there is no automatic migration:
| Restricted SharePoint Search (retiring) | Restricted Content Discovery (replacement) | |
|---|---|---|
| Model | Tenant-wide allowlist — everything hidden except ≤100 approved sites | Site-level flag — you mark specific sites as excluded from tenant-wide search and Copilot |
| Default posture | Deny by default, allow by exception | Allow by default, deny by exception |
| Scale | Hard cap of 100 allowed sites | No meaningful cap — flag as many sites as you need |
| Effect on users | Users lose search results on their own sites too — the collateral damage that made RSS unpopular | Users keep search within sites they work in; only tenant-wide discovery is suppressed |
| Licensing | Free | SharePoint Advanced Management — included with Copilot licensing |
The polarity flip is the whole story. RSS asked "which 100 sites are safe to show?" RCD asks "which sites are dangerous to show?" — and answering the second question requires knowing where your risky content actually lives. That is a discovery exercise, not a settings toggle, and it is why Microsoft cannot migrate your config for you: an allowlist of safe sites contains no information about which of the other ten thousand sites are the problem.
The five-step migration plan
- Export your current state this month. Record the RSS allowlist and, more importantly, generate the full inventory of sites outside it. That outside-the-fence list is your risk universe — every one of those sites becomes discoverable at retirement.
- Run an oversharing assessment before you touch anything. Purview's DSPM for AI oversharing assessment and SharePoint Advanced Management's reports will show you which sites carry sensitive content with broad access — "Everyone" links, org-wide sharing, stale permissions. This tells you which sites need RCD flags versus which just need their permissions fixed.
- Fix permissions at the source where you can. RCD, like RSS, hides symptoms. Site access reviews, killing "Everyone except external users" defaults, and expiring stale sharing links reduce the number of sites you need to flag at all — and unlike discovery suppression, permission fixes also stop the person with a direct link.
- Apply RCD to what remains, then stage the cutover. Flag the genuinely sensitive sites, run a pilot group with RSS-style expectations, and disable RSS on your own schedule — before January — rather than letting the retirement date do it for you. A controlled cutover in November beats a surprise one in February.
- Verify with Copilot's own eyes. After cutover, test what Copilot actually returns for the risky queries you can imagine — payroll, restructuring, credentials, board materials. The audit trail of what it surfaced, and to whom, is the evidence your CISO will ask for anyway.
The uncomfortable truth RSS was hiding
Restricted SharePoint Search let a lot of organizations tell themselves their Copilot deployment was governed when what they actually had was a smaller search index. The permission sprawl — a decade of open sites, inherited access, and links shared to "Everyone" — never went anywhere. Copilot didn't create that problem, and hiding sites from Copilot didn't fix it; humans with the URL, malware with a session token, and the next AI feature Microsoft ships all still walk right past discoverability controls.
The retirement is Microsoft forcing the honest version of the work: know where your sensitive content is, fix who can reach it, restrict discovery of what remains, and watch what your AI actually returns. If there is a silver lining, it is that the deadline finally puts the permissions cleanup on a calendar — with an executive sponsor called Copilot.
That last leg — watching what AI actually returns — is where AccuroAI picks up: response-side inspection that catches sensitive content in Copilot answers regardless of which discovery control missed it, with the audit trail attached. Discovery controls decide what AI can find; we watch what it actually says.
FAQ
Does RSS retirement give people access to files they couldn't open before?
No — and this is worth being precise about internally. Permissions are untouched. What changes is findability: files that were reachable-but-buried become reachable-and-surfaced, through search and through Copilot. If your risk model relied on nobody knowing the file existed, that model expires January 31.
Is Restricted Content Discovery a one-to-one replacement?
Functionally it covers the same intent — keeping sensitive sites out of tenant-wide search and Copilot grounding — but with an inverted model: site-level exclusions instead of a tenant-wide allowlist. Nothing migrates automatically, and building the exclusion list requires an oversharing assessment RSS never asked you to do.
We never enabled RSS. Does any of this matter to us?
The July 31 date does: if RSS was in your Copilot rollout plan as the interim guardrail, you have three weeks to enable it or — more sensibly at this point — skip straight to the RCD-plus-permissions approach, since anything you build on RSS now has a seven-month shelf life.
Do we need extra licensing for RCD?
RCD lives in SharePoint Advanced Management, which Microsoft now includes with Microsoft 365 Copilot licenses. If you have Copilot, you have the replacement — most teams just haven't turned it on.
Will fixing permissions break collaboration?
Done bluntly, yes — which is why the sequencing above puts the oversharing assessment first. Site access reviews routed to the data owners who understand the content, rather than blanket IT lockdowns, fix the dangerous 5% of sites without touching the collaboration everyone depends on.
Sources: Microsoft Learn — Restricted SharePoint Search · Microsoft Learn — Restricted Content Discovery · SharePoint Advanced Management for Copilot readiness · Microsoft 365 Copilot oversharing blueprint · Purview DSPM oversharing assessments · Microsoft 365 message center MC1395311.
Related: Microsoft 365 Copilot Oversharing: How to Find and Fix It · Does Copilot Respect Permissions? What Microsoft Really Says · Copilot vs ChatGPT Enterprise: Security Comparison.