Azure file share NTFS permission

Van Huy Tuyen 40 Reputation points
2025-09-23T07:55:35.27+00:00

Dear all,

We are using 2 tenant:

  • Tenant A is used for M365. We sync user/group from on-premises AD
  • Tenant B is used for Azure services.

We plan to migrate on-premises file share to Azure file. We expect user will have the same experience like on-premises, by implementing NTFS permission. Please suggest me how can we implement identity solution with our scenario (2 different tenants).

Thank you!

Azure Files
Azure Files
An Azure service that offers file shares in the cloud.
{count} votes

2 answers

Sort by: Most helpful
  1. JimmySalian-2011 44,716 Reputation points
    2025-09-23T08:32:32.16+00:00

    Hi Van,

    Basically the SMB File share is for local tenant - Hybrid access is allowed from the same AD Sync, Azure SMB file shares are typically associated with a specific Entra ID tenant, which means that they are not directly shareable across different tenants. Azure SMB file shares are designed for use within a single tenant's environment, and access control is managed through Entra ID authentication and authorization mechanisms.

    There you can setup B2B guest users and invite users to access the data however this is between the 2 tenants, AD Users will require testing.

    https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-external-users

    Also check this thread for similar query - https://learn.microsoft.com/en-us/answers/questions/2121225/cross-tenant-smb-access-for-data-delivery

    My view and suggestion will be to migrate to Sharepoint and allow B2B sharing if possible but you can plan it for phase 2.

    Hope this helps.

    JS

    ==

    Please Accept the answer if the information helped you. This will help us and others in the community as well.

    0 comments No comments

  2. Thanmayi Godithi 1,885 Reputation points Microsoft External Staff Moderator
    2025-09-23T11:11:41.7033333+00:00

    Hi @Van Huy Tuyen,

    Thank you for reaching out on Microsoft Q&A forum and also thanks to @JimmySalian-2011 for sharing useful input.

    Azure Files (SMB) identity-based access is scoped to a single tenant. The storage account’s authentication method (Active Directory DS, Microsoft Entra Domain Services, or Microsoft Entra Kerberos for hybrid identities) can only resolve users and groups that exist in the same tenant.

    You can try the below steps:

    1. Sync on-premises identities into Tenant B (recommended for “same NTFS experience”)

    • Deploy a supported identity sync (second Entra Connect, Cloud Sync, or Cross-tenant synchronization) so that the same on-prem AD objects exist in Tenant B.
    • Then configure Azure Files with a supported identity provider.

    This ensures ACL SIDs map correctly, giving the same experience as on-prem.

    2. Use cross-tenant B2B or cross-tenant sync (limited for NTFS)

    3. Stage migration with Azure File Sync

    • If you want a phased cutover, you can deploy Azure File Sync on your on-prem server. Users continue to access files locally (NTFS ACLs enforced as-is), while the data syncs to Azure Files in Tenant B-What is Azure File Sync?

    Kindly let us know if the above helps or you need further assistance on this issue.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.