FREE STUDY NOTES · AB-900

Restricted access control for SharePoint sites

How restricted site access limits a site to members of chosen groups, even for users with permission.

From Ultra Transcenders AB-900 by Tony Rough (coming November 2026)

Sometimes a sensitive site can’t wait for a full permissions clean-up. Restricted site access control (also called restricted access control or site access restriction) limits a site and its content to members of specified groups, even if other users already have permissions or a sharing link.

How it works

A user who opens a restricted site passes two gates: permission to the site or content, then membership of one of up to 10 control groups. Failing either gate means no access, and users outside the control groups also don't see the site's content in organisation-wide search or Copilot. Adding someone to a control group grants no permissions.
Figure 8.1: Restricted access control as a second gate

Setting it up

  1. Turn it on for the organisation: SharePoint admin center > Policies > Access control > Site-level access restriction > Allow access restriction.
  2. For each site: Sites > Active sites, select the site, Settings tab, Restricted site access > Edit, select Restrict SharePoint site access to only users in specified groups, add groups and save.
  3. Optionally, delegate management to site admins with PowerShell (off by default); site admins must then give a justification for each change.

For OneDrive there are two variants: restricting a specific user’s OneDrive to members of up to 10 groups, and a tenant setting (Access control > Restrict OneDrive access) that limits OneDrive use to up to 10 security groups. With the tenant setting, users outside the groups lose access to their own OneDrive but can still see files in search and Copilot if they had existing permissions, though they can’t open them.

Common trap: Adding users to the control group to give them access - membership is a second gate, not a permission; users still need site or content permissions as well.

Common trap: Assuming restricted access control on a team’s site also protects its private and shared channel sites - those are separate site collections and need their own policy.

Get the whole book

This note is one section of Ultra Transcenders AB-900: Microsoft 365 Copilot and Agent Administration Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · AB-900 terms in the glossary · All AB-900 study notes

More AB-900 study notes