{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values/",
        "slug": "dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values/"
        },
        "title": "Decide whether an FSRM classification rule may replace existing values",
        "summary": "When should an automatic FSRM classification rule re-evaluate an already classified file?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:15:22+00:00",
        "modified_at": "2026-09-08T18:23:26+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 201,
        "potentially_affected": "Administrators configuring automatic FSRM file classification rules.",
        "dse_recommendation": "Prepare example files representing an unset property, a matching existing value, and a conflicting value.",
        "primary_source": {
            "name": "Create an Automatic Classification Rule",
            "url": "https://learn.microsoft.com/en-us/windows-server/storage/fsrm/create-automatic-classification-rule",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>An FSRM classification rule assigns one property. By default, Microsoft’s procedure leaves files that already have a property value unchanged. Enabling re-evaluation introduces a choice between replacing an existing value and aggregating the new result with it. Microsoft’s Boolean example shows that aggregation can retain Yes when a rule proposes No, while overwrite changes it to No. <a href=\"https://learn.microsoft.com/en-us/windows-server/storage/fsrm/create-automatic-classification-rule\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the property, existing values, rule scope, classifier, and downstream consumers. Ask the data owner whether an earlier classification is authoritative, provisional, or intended to be combined with later evaluation.</p>\n<h2>DSE recommendation</h2>\n<p>Prepare example files representing an unset property, a matching existing value, and a conflicting value. Agree on the desired result for each before selecting overwrite or aggregation. Record the rule’s scope and enabled state and have the owner review any planned replacement of existing labels.</p>\n<h2>Verification</h2>\n<p>Run the approved examples through classification and compare the actual property values with the decision table. Re-run the process to inspect re-evaluation behavior. Preserve before-and-after values and resolve any unexpected aggregation result before expanding the rule to additional folders or using its output for another action.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/storage/fsrm/create-automatic-classification-rule\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Create an Automatic Classification Rule</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nAn FSRM classification rule assigns one property. By default, Microsoft’s procedure leaves files that already have a property value unchanged. Enabling re-evaluation introduces a choice between replacing an existing value and aggregating the new result with it. Microsoft’s Boolean example shows that aggregation can retain Yes when a rule proposes No, while overwrite changes it to No. Microsoft documentation.\nApplicability\nIdentify the property, existing values, rule scope, classifier, and downstream consumers. Ask the data owner whether an earlier classification is authoritative, provisional, or intended to be combined with later evaluation.\nDSE recommendation\nPrepare example files representing an unset property, a matching existing value, and a conflicting value. Agree on the desired result for each before selecting overwrite or aggregation. Record the rule’s scope and enabled state and have the owner review any planned replacement of existing labels.\nVerification\nRun the approved examples through classification and compare the actual property values with the decision table. Re-run the process to inspect re-evaluation behavior. Preserve before-and-after values and resolve any unexpected aggregation result before expanding the rule to additional folders or using its output for another action.\nOfficial references\nMicrosoft Learn: Create an Automatic Classification Rule. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nAn FSRM classification rule assigns one property. By default, Microsoft’s procedure leaves files that already have a property value unchanged. Enabling re-evaluation introduces a choice between replacing an existing value and aggregating the new result with it. Microsoft’s Boolean example shows that aggregation can retain Yes when a rule proposes No, while overwrite changes it to No. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/fsrm/create-automatic-classification-rule).\n\n## Applicability\n\nIdentify the property, existing values, rule scope, classifier, and downstream consumers. Ask the data owner whether an earlier classification is authoritative, provisional, or intended to be combined with later evaluation.\n\n## DSE recommendation\n\nPrepare example files representing an unset property, a matching existing value, and a conflicting value. Agree on the desired result for each before selecting overwrite or aggregation. Record the rule’s scope and enabled state and have the owner review any planned replacement of existing labels.\n\n## Verification\n\nRun the approved examples through classification and compare the actual property values with the decision table. Re-run the process to inspect re-evaluation behavior. Preserve before-and-after values and resolve any unexpected aggregation result before expanding the rule to additional folders or using its output for another action.\n\n## Official references\n\n[Microsoft Learn: Create an Automatic Classification Rule](https://learn.microsoft.com/en-us/windows-server/storage/fsrm/create-automatic-classification-rule). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Decide whether an FSRM classification rule may replace existing values",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values/",
                "headline": "Decide whether an FSRM classification rule may replace existing values",
                "description": "When should an automatic FSRM classification rule re-evaluate an already classified file?",
                "abstract": "When should an automatic FSRM classification rule re-evaluate an already classified file?",
                "articleBody": "Source facts\nAn FSRM classification rule assigns one property. By default, Microsoft’s procedure leaves files that already have a property value unchanged. Enabling re-evaluation introduces a choice between replacing an existing value and aggregating the new result with it. Microsoft’s Boolean example shows that aggregation can retain Yes when a rule proposes No, while overwrite changes it to No. Microsoft documentation.\nApplicability\nIdentify the property, existing values, rule scope, classifier, and downstream consumers. Ask the data owner whether an earlier classification is authoritative, provisional, or intended to be combined with later evaluation.\nDSE recommendation\nPrepare example files representing an unset property, a matching existing value, and a conflicting value. Agree on the desired result for each before selecting overwrite or aggregation. Record the rule’s scope and enabled state and have the owner review any planned replacement of existing labels.\nVerification\nRun the approved examples through classification and compare the actual property values with the decision table. Re-run the process to inspect re-evaluation behavior. Preserve before-and-after values and resolve any unexpected aggregation result before expanding the rule to additional folders or using its output for another action.\nOfficial references\nMicrosoft Learn: Create an Automatic Classification Rule. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:15:22+00:00",
                "dateModified": "2026-09-08T18:23:26+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-109-decide-whether-an-fsrm-classification-rule-may-replace-existing-values/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Decide whether an FSRM classification rule may replace existing values"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 201,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Create an Automatic Classification Rule",
                    "url": "https://learn.microsoft.com/en-us/windows-server/storage/fsrm/create-automatic-classification-rule"
                }
            }
        ]
    }
}