What you need to know
Restricted Access Control can require both normal SharePoint permission and membership in an allowed Microsoft 365 or Entra group before a user opens site content.
Potentially affected
Sensitive SharePoint sites, including Microsoft 365 group-connected, Teams-connected, and nongroup-connected sites in tenants licensed for SharePoint Advanced Management.
DSE recommendation
Inventory existing permissions and sharing, validate licensing, enable the tenant control, apply a reviewed allow group to one pilot site, test every access path, and retain rollback.
Source fact: what Microsoft documents
SharePoint Restricted Access Control lets an organization designate Microsoft Entra security groups or Microsoft 365 groups whose members are eligible to access a site. The control applies when a user attempts to open the site or content. A user must have both ordinary SharePoint permission and membership in an allowed group. Adding a user to the restricted-access group does not grant site or file permission by itself.
Microsoft documents support for Microsoft 365 group-connected, Teams-connected, and nongroup-connected sites. Up to 10 Entra security or Microsoft 365 groups can be configured for a site, including supported dynamic security groups. The organization-level feature must be enabled before site configuration and can take up to one hour to become effective. In Multi-Geo tenants, enablement is performed separately for each intended geographic location.
Restricted site access control is enforced when users open sites or files and in organization-wide search and Microsoft 365 Copilot experiences. Users denied by the policy cannot view protected site content through search or Copilot. Enforcement in those experiences can lag while the search index updates, and larger sites can take longer. By default, SharePoint sharing does not follow the restricted-access policy; preventing sharing with users outside the allowed groups is a separate opt-in tenant control.
Licensing and applicability
Microsoft requires an eligible base subscription—Office 365 E3, E5, or A5; Microsoft 365 E1, E3, E5, or A5; or Microsoft 365 GCC, GCC High, or DoD—and one of these entitlement paths: at least one user in the organization is assigned a Microsoft 365 Copilot license; the subscription includes SharePoint K, P1, or P2 and the organization purchases the SharePoint Advanced Management Plan 1 add-on; or the organization has Microsoft 365 E7. External users do not require a license. Tenant and site administration permissions, dynamic-group licensing, Teams and Microsoft 365 group behavior, guest access, applications, automation identities, search, and Multi-Geo scope must be evaluated. The feature is an additional access boundary, not a replacement for correct SharePoint permissions, site ownership, information classification, or guest governance.
DSE recommendation: production-safe operational steps
- Select one sensitive test site with accountable owners, known applications, documented business users, and a supportable rollback window.
- Export site owners, members, visitors, direct permissions, sharing links, guest access, Teams or group relationships, automation identities, and sensitivity or retention settings.
- Create or validate allowed groups. Confirm group ownership, membership source, dynamic rules, guest inclusion, emergency access, and the process for urgent membership correction.
- Enable the tenant feature, wait for documented propagation, and apply the restriction to the pilot site.
- Test owners, members, nonmembers, guests, Teams access, browser access, synchronized content, search and Copilot after index updates, sharing, applications, workflows, service identities, and mobile clients.
- Decide separately whether to prohibit sharing outside the allowed groups and test that change before enablement.
- Monitor denied-access reports and support requests, correct group or permission errors, and expand only after all required workflows pass.
DSE recommends treating the allowed group as a security boundary with an owner, review cadence, and change record. Preserve the prior site state and exact removal command or procedure. If a critical integration fails, remove the pilot restriction, verify access restoration, and investigate rather than broadly adding identities to bypass the control.
Official references
- Restrict SharePoint site access with Microsoft 365 groups and Microsoft Entra security groups — tenant enablement, allowed groups, permission interaction, Search and Copilot enforcement, and sharing behavior.
- Prerequisites for SharePoint Advanced Management — eligible base subscriptions, entitlement paths, administrative roles, and external-user licensing.
Review the official source
Microsoft Learn: Restrict SharePoint site access with Microsoft 365 groups and Microsoft Entra security groups · Published July 15, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE