How restricted site access limits a site to members of chosen groups, even for users with permission.
From Ultra Transcenders AB-900 by Tony Rough (coming November 2026)
Sometimes a sensitive site can’t wait for a full permissions clean-up. Restricted site access control (also called restricted access control or site access restriction) limits a site and its content to members of specified groups, even if other users already have permissions or a sharing link.
For OneDrive there are two variants: restricting a specific user’s OneDrive to members of up to 10 groups, and a tenant setting (Access control > Restrict OneDrive access) that limits OneDrive use to up to 10 security groups. With the tenant setting, users outside the groups lose access to their own OneDrive but can still see files in search and Copilot if they had existing permissions, though they can’t open them.
Common trap: Adding users to the control group to give them access - membership is a second gate, not a permission; users still need site or content permissions as well.
Common trap: Assuming restricted access control on a team’s site also protects its private and shared channel sites - those are separate site collections and need their own policy.
This note is one section of Ultra Transcenders AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · AB-900 terms in the glossary · All AB-900 study notes
Verify explicitly, use least privilege access and assume breach, and the pillars they apply to.
How Conditional Access turns sign-in signals into block or grant decisions, and what licence it needs.
What the score measures, how often it is recalculated and which recommendations raise it.
What each Exchange Online mailbox permission allows and which recipients and groups can hold it.
Sharing-link, permission and Everyone except external users reports for finding oversharing.
What the two built-in reasoning agents are for, how they are deployed and when a custom agent fits.
How billing policies connect metered Copilot Chat and SharePoint agent use to an Azure subscription, and what budgets do.