# Complete both sides of a JSON-based Blob object-replication policy

> Creating a destination policy does not automatically configure the source; both sides must use the destination-generated policy ID.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-383-complete-both-sides-of-a-json-based-blob-object-replication-policy/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:33+00:00
- Modified: 2026-09-10T02:01:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Creating a destination policy does not automatically configure the source; both sides must use the destination-generated policy ID.

## Potentially affected

Azure block-blob object replication configured through separate source and destination account owners.

## DSE recommendation

Track the destination policy and matching source configuration as one coordinated handoff.

## Article

## Source facts

In the JSON workflow, Azure generates the destination policy ID and includes it in the downloaded definition. The source account must use that same ID. Uploading the destination definition through the portal does not create its source counterpart; the source policy must exist before replication starts.

Object replication requires versioning on both accounts and change feed on the source. A source blob’s object-replication properties are populated only after replication completes or fails, so an empty status is not proof of completed copying. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/blobs/object-replication-configure).

## Applicability

Identify both account owners, approved containers, policy rules and applicable account support. This brief excludes the separate preview for replicating blob index tags.

## DSE recommendation

DSE recommends a handoff record containing the reviewed destination policy and the corresponding source import. Confirm the actual account and container identities before applying it, especially across administrative boundaries. Keep permission to configure replication tied to approval for the resulting data copy. Do not close the task when only one owner’s portal operation succeeds.

## Verification

Use an approved harmless blob that meets the configured rules. Compare both policy IDs, then verify the source’s eventual replication result and the intended destination object. Preserve failure or incomplete status explicitly and investigate missing policy or container dependencies. Avoid broadening the selected containers merely to make a test object appear.

## Official references

[Microsoft Learn: Configure object replication](https://learn.microsoft.com/en-us/azure/storage/blobs/object-replication-configure). Source retrieved September 9, 2026.

## Primary reference

- Name: Configure object replication - Azure Storage | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/storage/blobs/object-replication-configure
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Complete both sides of a JSON-based Blob object-replication policy,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-383-complete-both-sides-of-a-json-based-blob-object-replication-policy/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
