question

LouieBlackman-8425 avatar image
0 Votes"
LouieBlackman-8425 asked BadushaK-3530 answered

Sync Azure AD Users & Groups to a local PC for file sharing

Hi There,

We are a small business with an extremely simple on premise file & printer shares. Quite literally Windows built in sharing. This works absolutely perfect for us.

However, I have ran into an issue today.

We use M365 for email, SharePoint etc, however, our on premise printers & copiers are all setup to the network share created by our file server.

We are looking to create a new share, for 'finance' where invoices, bank statements etc can be scanned to. The issue is, I only want people that are in the Azure AD group 'Finance' to be able to access this share.

The problem of course is, without the file server actually being a server, I do not have the same tools available to others and also (by my knowledge) Azure Connect will be pointless.

Is it possible to only allow AzureAD{Group} to access certain shares if I Azure Join the file server?

Thanks all!

azure-ad-user-management
· 3
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

To support authentication with Azure AD credentials and access a file share by using Azure AD credentials, you must enable Azure AD Domain Services for your Azure AD tenant and your machine must be domain-joined to Azure AD DS. Then you could assign the group permissions as described here: https://docs.microsoft.com/en-us/azure/storage/files/storage-files-identity-auth-active-directory-domain-service-enable?tabs=azure-portal

Otherwise user writeback from Azure AD to on-prem is not yet supported.

0 Votes 0 ·

Need some more details. Do you have AAD connect server at onperm? Or whether onperm and cloud users will use different credentials for login?

0 Votes 0 ·

No, there is no on premises active directory.

It's essentially a Micro-PC which uses Windows built in file & printer sharing, however, all of our other computers (Surfaces, ThinkPads etc) are Azure AD Joined so that our employees log in with their email address & password.

That's as basic as it is! The file server currently has no Azure affiliation and is just using Windows login.

0 Votes 0 ·

1 Answer

BadushaK-3530 avatar image
0 Votes"
BadushaK-3530 answered

Azure AD join only possible with windows 11 and windows 10 OS. In the server OS 2019 VM running on Azure cloud will support Azure AD join.

https://docs.microsoft.com/en-us/azure/active-directory/devices/concept-azure-ad-join

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.