Your input shapes our product. Suggest a feature now →
  1. Home
  2. Alerts
  3. RAC Search Enforcement MC1429019

SharePoint Restricted Access Control Is Now Enforced in Microsoft 365 Search

Published: 24 July 2026. Source: MC1429019: SharePoint Online Restricts Microsoft 365 Search (mwpro.co.uk)

Before this update, Restricted Access Control policies on SharePoint sites controlled who could open a site but did not always suppress those sites from appearing in Microsoft 365 search results. A user blocked from visiting a RAC-restricted site could still see references to its content in a tenant-wide or SharePoint search query. That gap closes with this rollout.

What Restricted Access Control actually does

Restricted Access Control (RAC) is a SharePoint Advanced Management feature that constrains a site's access to a specific Entra ID security group. Any user outside that group is blocked from the site regardless of any other direct permission grant they hold on items within it. RAC is typically applied to sites containing sensitive content: HR records, merger-related document libraries, legal matter files, or executive project workspaces where standard SharePoint permission inheritance is not tight enough.

The original design enforced RAC at the site and item level but left search indexing largely unaffected. A user excluded by a RAC policy could still receive references to restricted-site content in Microsoft 365 search, even if clicking through to those results returned an access-denied error. With MC1429019, Microsoft closes that gap by extending RAC enforcement into the search index itself.

What changes with MC1429019

Before the updateAfter the update (late July 2026)
RAC blocks site access; Microsoft 365 search may still surface restricted content to non-permitted users RAC blocks both site access and search result visibility; restricted content is filtered from search entirely for non-permitted users
A blocked user clicks a search result from a RAC site and receives an access-denied error A blocked user's search query returns no results for content on RAC-restricted sites
Restricted site names and document titles may appear in search previews Restricted site names and document titles are removed from the search index for non-group members

Microsoft rates this as a medium-impact change with an operational impact score of 36/100. No admin action is required for the enforcement to take effect; it applies automatically to existing and new RAC-enabled sites without any change to RAC configurations themselves. The rollout reaches Worldwide, GCC High, and DoD environments in late July 2026.

Illustration: a shield intercepting a flagged document.
SharePoint RAC Now Enforced Across Microsoft 365 Search

What admins should review before the rollout completes

Tenants without any RAC policies can skip this review entirely; nothing changes for unprotected sites. For organisations that do use RAC, three things are worth checking now.

Security group membership. RAC group membership is now the single determinant of search visibility for protected sites. Any user mistakenly excluded from the permitted group will no longer see relevant search results, even if they previously had a direct item-level permission on content within the site. Confirm that each RAC policy's security group contains the right people before the rollout arrives in your tenant.

Service desk preparation. Users inside a restricted group will see no change. Users outside a RAC group who previously encountered access-denied errors after clicking search results will now find those results absent entirely. Expect a small number of support tickets from users who cannot locate content they previously at least glimpsed in search previews.

Policy intent alignment. Some RAC policies may have been applied as a lightweight access control measure without the intent to suppress search visibility entirely. Review whether the extended enforcement matches your current governance requirements for each protected site, and adjust RAC group membership or remove RAC from sites where full search suppression is unintended.

Tip: Run a permission export with Report Master before the rollout completes. A permission matrix across your key sites gives you a clear picture of who holds direct access grants inside RAC-protected sites, so you can confirm that group membership and individual permissions are aligned before search enforcement tightens.

How this fits alongside broader access governance

RAC operates at the site level. Oversharing at the item level, such as anonymous links to individual files or guest accounts with direct document access, remains outside RAC's scope. Those exposures need a separate audit of shared links and unique permissions, particularly in sites that are not RAC-protected.

ShareMaster's Shared Links & Permissions tool exports every active shared link and unique permission grant across a site, letting you identify access that no RAC policy or permission boundary covers. For a full view of how access is distributed before finalising any governance configuration, see the SharePoint permissions audit guide.

Source: MC1429019: SharePoint Online Restricts Microsoft 365 Search (mwpro.co.uk), published 15 July 2026.

Frequently Asked Questions

What is Restricted Access Control in SharePoint Online?

RAC is a SharePoint Advanced Management feature that limits access to a site to a specific Entra ID security group. Any user outside that group is blocked regardless of other direct permission grants they may hold on content within the site.

Does this search enforcement change affect all SharePoint tenants?

Only tenants with RAC policies configured on one or more sites. Tenants without any RAC configuration see no change in search behaviour. Only content on explicitly RAC-restricted sites is filtered from search results for non-permitted users.

Do I need SharePoint Advanced Management to enable RAC?

Yes. RAC is a SharePoint Advanced Management feature, included with Microsoft 365 E5 and Microsoft 365 Copilot licences, and available as a standalone add-on. Confirm current licensing on Microsoft Learn before configuring policies.

Try ShareMaster free for 14 days