Defender for Cloud Apps: Migrate file policies to Purview

Microsoft has set a clear date for Microsoft Defender for Cloud Apps: file policies retire on January 6, 2027. Organizations should recreate existing file policies as Microsoft Purview data loss prevention policies or auto-labeling policies before that date. For organizations with 10 to 250 users, this is not an abstract platform change. Many smaller IT teams use these rules to find externally shared files, detect sensitive content, or apply sensitivity labels automatically. Starting the migration shortly before retirement risks gaps in file-based protection.

What Microsoft retires on January 6, 2027

According to Microsoft Learn, the change affects file policies in Defender for Cloud Apps. These policies need to be rebuilt in Microsoft Purview before the deadline. Defender for Cloud Apps itself is not going away: Microsoft still lists SaaS app discovery, posture management, and threat detection as continuing capabilities of the service. What moves is the file-based protection logic. Rules that inspect content, evaluate sharing, notify owners, quarantine files, or apply sensitivity labels belong in Microsoft Purview going forward.

Which policies to inventory first

The first practical step is an inventory in the Microsoft Defender portal under Cloud Apps, Policies, and Policy management, filtered to File policy. Microsoft names the fields to capture: policy name, description, target apps, inspection method, sensitive information types or labels, context filters, and governance actions. Those details determine whether a rule should become a Purview DLP policy, an auto-labeling policy, or a combination of both.

  • Policies with detection and protective actions belong in Data Loss Prevention.
  • Policies that apply sensitivity labels belong in auto-labeling.
  • Combined rules should be documented separately so detection, labeling, and action remain traceable.
  • Rules for SharePoint and OneDrive are especially important because Microsoft documents direct Purview locations for them.

What does not migrate one to one

Microsoft provides a capability mapping, but it is not a simple export and import path. Some capabilities are equivalent, while others are only partial matches. For example, Purview supports DLP rules, user notifications, alerts, and quarantine for SharePoint and OneDrive. For folder filters, Microsoft points to site-level scoping as the closest equivalent. For File ID, the table lists no Purview equivalent. Actions such as transferring ownership or expiring a shared link also have no direct replacement according to Microsoft. These gaps need to be reviewed before enforcement, otherwise the new policy may only appear equivalent.

Why parallel operation is risky

One important warning is explicit in the Microsoft documentation: equivalent policies in Defender for Cloud Apps and Purview should not run at the same time because they can create enforcement conflicts. The safe sequence is therefore not to disable old rules immediately. First create the Purview policies, run them in simulation or test mode, and compare them with the existing file policies. Only after the new policy works reliably should the old file policy be disabled and later deleted. This sequence fits a controlled Microsoft Security Assessment because it separates evidence, ownership, and technical effect.

Concrete next steps before the deadline

  • Export or document every existing file policy with conditions, actions, and target apps.
  • Map each rule to DLP, auto-labeling, or a combination of both.
  • Review required roles and permissions for Purview and Defender for Cloud Apps.
  • Create new Purview policies in simulation or test mode first.
  • Compare matches, alerts, notifications, and quarantine behavior with the existing rule.
  • Disable the Defender file policy only after validated Purview enforcement.

For SMBs, a short and complete list is often more useful than a large migration plan. The key question is whether every active file rule has a clear target state: Purview DLP, auto-labeling, a manual alternative, or intentional retirement. This technical migration does not replace licensing or compliance assessments; it clarifies how existing protection logic continues to operate in Microsoft 365.

Official Microsoft sources

If you want to identify which Defender for Cloud Apps file policies in your tenant are affected and how the technical migration to Purview should work, we can support inventory, mapping, simulation, and clean decommissioning. Talk to us before old rules expire close to the deadline.

Recommended Next Step

What does this mean for your environment?

Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

Sebastian Kerssen, Managing Director of ReByteIT

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.

Leave a comment