{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/",
        "slug": "dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/"
        },
        "title": "Resolve folder and file-ID scope gaps before migrating Cloud Apps file policies",
        "summary": "Which file-policy conditions cannot retain their original scope when moved to Purview?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:21+00:00",
        "modified_at": "2026-09-10T01:40:03+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 244,
        "potentially_affected": "Teams mapping Defender for Cloud Apps file-policy conditions to Microsoft Purview DLP.",
        "dse_recommendation": "Escalate each unsupported or broadened location condition as a protection-design decision before accepting the migrated policy.",
        "primary_source": {
            "name": "Migrate file policies to Microsoft Purview - Microsoft Defender for Cloud Apps | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-cloud-apps/migrate-file-policies-to-purview",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft&#8217;s migration mapping does not preserve every file-policy condition. A parent-folder condition maps only partially to SharePoint site scope, with no folder-level equivalent. File ID has no supported condition mapping. The automated migration tool classifies policies by readiness and presents payload warnings for fields needing manual attention. These are scope differences to resolve, not merely renamed settings. <a href=\"https://learn.microsoft.com/en-us/defender-cloud-apps/migrate-file-policies-to-purview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review for existing Cloud Apps file policies being translated into Purview rules. Inspect the original conditions themselves rather than relying on a policy name or migration count. Check the source&#8217;s current tool eligibility separately; this brief does not assume that every app or environment supports automated migration.</p>\n<h2>DSE recommendation</h2>\n<p>Escalate each unsupported or broadened location condition as a protection-design decision before accepting the migrated policy. Give the data owner a concrete comparison: the originally selected folder or file, the proposed target site or content condition, and the files that would newly enter or leave scope. Record an explicit alternative for a file-ID rule instead of silently dropping that condition.</p>\n<h2>Verification</h2>\n<p>Compare representative files inside the original folder, elsewhere in the same site, and outside the proposed site. Include a file formerly selected only by its identifier. Review the target rule and its observed matches against the approved boundary. Preserve unresolved differences as migration exceptions; a successfully created policy is not the acceptance result for this scope review.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-cloud-apps/migrate-file-policies-to-purview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Migrate file policies to Microsoft Purview</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft’s migration mapping does not preserve every file-policy condition. A parent-folder condition maps only partially to SharePoint site scope, with no folder-level equivalent. File ID has no supported condition mapping. The automated migration tool classifies policies by readiness and presents payload warnings for fields needing manual attention. These are scope differences to resolve, not merely renamed settings. Microsoft Learn.\nApplicability\nUse this review for existing Cloud Apps file policies being translated into Purview rules. Inspect the original conditions themselves rather than relying on a policy name or migration count. Check the source’s current tool eligibility separately; this brief does not assume that every app or environment supports automated migration.\nDSE recommendation\nEscalate each unsupported or broadened location condition as a protection-design decision before accepting the migrated policy. Give the data owner a concrete comparison: the originally selected folder or file, the proposed target site or content condition, and the files that would newly enter or leave scope. Record an explicit alternative for a file-ID rule instead of silently dropping that condition.\nVerification\nCompare representative files inside the original folder, elsewhere in the same site, and outside the proposed site. Include a file formerly selected only by its identifier. Review the target rule and its observed matches against the approved boundary. Preserve unresolved differences as migration exceptions; a successfully created policy is not the acceptance result for this scope review.\nOfficial references\nMicrosoft Learn: Migrate file policies to Microsoft Purview. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft’s migration mapping does not preserve every file-policy condition. A parent-folder condition maps only partially to SharePoint site scope, with no folder-level equivalent. File ID has no supported condition mapping. The automated migration tool classifies policies by readiness and presents payload warnings for fields needing manual attention. These are scope differences to resolve, not merely renamed settings. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-cloud-apps/migrate-file-policies-to-purview).\n\n## Applicability\n\nUse this review for existing Cloud Apps file policies being translated into Purview rules. Inspect the original conditions themselves rather than relying on a policy name or migration count. Check the source’s current tool eligibility separately; this brief does not assume that every app or environment supports automated migration.\n\n## DSE recommendation\n\nEscalate each unsupported or broadened location condition as a protection-design decision before accepting the migrated policy. Give the data owner a concrete comparison: the originally selected folder or file, the proposed target site or content condition, and the files that would newly enter or leave scope. Record an explicit alternative for a file-ID rule instead of silently dropping that condition.\n\n## Verification\n\nCompare representative files inside the original folder, elsewhere in the same site, and outside the proposed site. Include a file formerly selected only by its identifier. Review the target rule and its observed matches against the approved boundary. Preserve unresolved differences as migration exceptions; a successfully created policy is not the acceptance result for this scope review.\n\n## Official references\n\n[Microsoft Learn: Migrate file policies to Microsoft Purview](https://learn.microsoft.com/en-us/defender-cloud-apps/migrate-file-policies-to-purview). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Resolve folder and file-ID scope gaps before migrating Cloud Apps file policies",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/",
                "headline": "Resolve folder and file-ID scope gaps before migrating Cloud Apps file policies",
                "description": "Which file-policy conditions cannot retain their original scope when moved to Purview?",
                "abstract": "Which file-policy conditions cannot retain their original scope when moved to Purview?",
                "articleBody": "Source facts\nMicrosoft’s migration mapping does not preserve every file-policy condition. A parent-folder condition maps only partially to SharePoint site scope, with no folder-level equivalent. File ID has no supported condition mapping. The automated migration tool classifies policies by readiness and presents payload warnings for fields needing manual attention. These are scope differences to resolve, not merely renamed settings. Microsoft Learn.\nApplicability\nUse this review for existing Cloud Apps file policies being translated into Purview rules. Inspect the original conditions themselves rather than relying on a policy name or migration count. Check the source’s current tool eligibility separately; this brief does not assume that every app or environment supports automated migration.\nDSE recommendation\nEscalate each unsupported or broadened location condition as a protection-design decision before accepting the migrated policy. Give the data owner a concrete comparison: the originally selected folder or file, the proposed target site or content condition, and the files that would newly enter or leave scope. Record an explicit alternative for a file-ID rule instead of silently dropping that condition.\nVerification\nCompare representative files inside the original folder, elsewhere in the same site, and outside the proposed site. Include a file formerly selected only by its identifier. Review the target rule and its observed matches against the approved boundary. Preserve unresolved differences as migration exceptions; a successfully created policy is not the acceptance result for this scope review.\nOfficial references\nMicrosoft Learn: Migrate file policies to Microsoft Purview. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:26:21+00:00",
                "dateModified": "2026-09-10T01:40:03+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Resolve folder and file-ID scope gaps before migrating Cloud Apps file policies"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 244,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Migrate file policies to Microsoft Purview - Microsoft Defender for Cloud Apps | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-cloud-apps/migrate-file-policies-to-purview"
                }
            }
        ]
    }
}