on-premises Active Directory Domain Services authentication over SMB for Azure file shares

romero 85 Reputation points
2023-05-08T14:50:29.5166667+00:00

hi

I am having a problem.

I am trying to follow the link below

https://learn.microsoft.com/en-us/azure/storage/files/storage-files-identity-auth-active-directory-enable

The documentation says "AD DS identities used for Azure Files on-premises AD DS authentication must be synchronized to Azure AD or use a default share-level permission. Password hash synchronization is optional."

I was wondering if my understanding of this is correct.

I think I can use "use a default share-level permission" if I don't sync on-premises AD DS to Azure AD.

However, the diagram in the image in the link below shows "Sync AD to Azure AD with Azure AD Connect" as a prerequisite.

https://learn.microsoft.com/en-us/azure/storage/files/media/storage-files-active-directory-domain-services-enable/diagram-files-ad.png

I was wondering if it is possible to connect to an Azure file share without "Sync AD to Azure AD with Azure AD Connect" if I use the "default share-level permission" with just the on-premises AD user on a virtual machine joined to the on-premises AD DS.

Thanks for reading and have a great day.

Azure Files
Azure Files
An Azure service that offers file shares in the cloud.
1,163 questions
Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,687 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Silvia Wibowo 2,851 Reputation points Microsoft Employee
    2023-05-11T23:40:18.2333333+00:00

    Hi @romero , answer to your question: Yes.

    "Assigning a default share-level permission allows you to work around the sync requirement because you don't need to specify the permission to identities in Azure AD." from first bullet point of this document.

    Follow this step-by-step to set default share-level permission.

    Please let me know if you have issues. Thank you.

    0 comments No comments