# Treat File Sync authoritative upload as a namespace mirror, not a merge

> Authoritative upload can delete cloud files that no longer exist on the server used to seed the share.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-406-treat-file-sync-authoritative-upload-as-a-namespace-mirror-not-a-merge/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:10+00:00
- Modified: 2026-09-10T02:04:57+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Authoritative upload can delete cloud files that no longer exist on the server used to seed the share.

## Potentially affected

Azure File Sync server-endpoint creation after a supported pre-seeding migration.

## DSE recommendation

Verify the authoritative server path and cloud-only differences before selecting authoritative upload.

## Article

## Source facts

Authoritative upload is reserved for a migration in which the same server path seeded the Azure file share and the server has newer changes. It mirrors the server namespace to the share: new or updated content is uploaded, while files and folders no longer on the server are deleted from the share.

Provisioning in this mode requires data in the server location as a safeguard against accidental misconfiguration. Merge instead combines the two namespaces and automatically resolves matching-name conflicts. File Sync creates a pre-endpoint share snapshot that is not automatically removed. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/file-sync/file-sync-server-endpoint-create).

## Applicability

These Initial sync options are available only for the first server endpoint in a sync group. Identify the actual pre-seed source, subsequent writes at both locations and the desired owner of namespace state. Do not choose authoritative upload merely to avoid investigating merge conflicts.

## DSE recommendation

DSE recommends comparing cloud-only and server-only content before approving this mode. Have the data owner explicitly accept any proposed cloud deletions and confirm the source path is the one used for seeding. Review the retained snapshot and recovery plan without treating their existence as permission to discard valuable independent changes.

## Verification

In a representative test, include an updated source file and a cloud-only file whose disposition is known in advance. Compare the resulting namespace and metadata with the approved mirror decision. Preserve differences and errors until reconciled. Verify recovery evidence separately, and do not remove the pre-endpoint snapshot until its retention and recovery purpose has been reviewed.

## Official references

[Microsoft Learn: Create an Azure File Sync Server Endpoint](https://learn.microsoft.com/en-us/azure/storage/file-sync/file-sync-server-endpoint-create). Source retrieved September 9, 2026.

## Primary reference

- Name: Create an Azure File Sync Server Endpoint | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/storage/file-sync/file-sync-server-endpoint-create
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Treat File Sync authoritative upload as a namespace mirror, not a merge,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-406-treat-file-sync-authoritative-upload-as-a-namespace-mirror-not-a-merge/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
