# Resolve folder and file-ID scope gaps before migrating Cloud Apps file policies

> Which file-policy conditions cannot retain their original scope when moved to Purview?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:21+00:00
- Modified: 2026-09-10T01:40:03+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Which file-policy conditions cannot retain their original scope when moved to Purview?

## Potentially affected

Teams mapping Defender for Cloud Apps file-policy conditions to Microsoft Purview DLP.

## DSE recommendation

Escalate each unsupported or broadened location condition as a protection-design decision before accepting the migrated policy.

## Article

## Source facts

Microsoft’s migration mapping does not preserve every file-policy condition. A parent-folder condition maps only partially to SharePoint site scope, with no folder-level equivalent. File ID has no supported condition mapping. The automated migration tool classifies policies by readiness and presents payload warnings for fields needing manual attention. These are scope differences to resolve, not merely renamed settings. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-cloud-apps/migrate-file-policies-to-purview).

## Applicability

Use this review for existing Cloud Apps file policies being translated into Purview rules. Inspect the original conditions themselves rather than relying on a policy name or migration count. Check the source’s current tool eligibility separately; this brief does not assume that every app or environment supports automated migration.

## DSE recommendation

Escalate each unsupported or broadened location condition as a protection-design decision before accepting the migrated policy. Give the data owner a concrete comparison: the originally selected folder or file, the proposed target site or content condition, and the files that would newly enter or leave scope. Record an explicit alternative for a file-ID rule instead of silently dropping that condition.

## Verification

Compare representative files inside the original folder, elsewhere in the same site, and outside the proposed site. Include a file formerly selected only by its identifier. Review the target rule and its observed matches against the approved boundary. Preserve unresolved differences as migration exceptions; a successfully created policy is not the acceptance result for this scope review.

## Official references

[Microsoft Learn: Migrate file policies to Microsoft Purview](https://learn.microsoft.com/en-us/defender-cloud-apps/migrate-file-policies-to-purview). Source reviewed September 9, 2026.

## Primary reference

- Name: Migrate file policies to Microsoft Purview - Microsoft Defender for Cloud Apps | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-cloud-apps/migrate-file-policies-to-purview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Resolve folder and file-ID scope gaps before migrating Cloud Apps file policies,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-335-resolve-folder-and-file-id-scope-gaps-before-migrating-cloud-apps-file-policies/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
