ACL's for AzureFiles
I've started experimenting with Azure Files. One of the features I'm lacking is the fact that you cannot give access to Folders/Files on AzureFiles based on Active Directory credentials. If you setup a typical fileshare one would like to be able to grant/revoke access to folders and files based on information of users in AD.

Hi folks,
We announced earlier today the public preview of Active Directory authentication and authorization support for Azure Files. With this feature, just like a traditional on-premises file server, you can domain join your storage account to your regular Active Directory domain and set file/folder ACLs on your file shares just like you expect! This preview release makes it seamless for Azure Files to work with existing Active Directory with no change in the client environment.
To learn more, please see our blog post here: https://azure.microsoft.com/blog/preview-of-active-directory-for-authentication-on-azure-file
Our public preview for Azure Files and AD DS is distinct from our existing support for Azure AD DS, which we will continue to support as generally available feature.
Please don’t hesitate to reach out to us if you have further questions about how to setup and deploy this feature or about other features. You can reach us at AzureFiles@microsoft.com.
Thanks,
Will Gries
Senior Program Manager, Azure Files
128 comments
-
Juanjo commented
I am also interested in what the colleague testing-sgjapan has commented:
see:
- Ability to create an Azure File Share, and assign permissions to folders based on Azure AD Accounts
- Ability to have Azure AD joined devices to have access to file shares without using the storage "key".Is there any update of these? Do you intend for it to be supported in the near future?
-
Testing sGJapan commented
I am not sure about everyone else, but this is what we would like to see:
- Ability to create an Azure File Share, and assign permissions to folders based on Azure AD Accounts
- Ability to have Azure AD joined devices to have access to file shares without using the storage "key"
- Ability to access to map the file share in a similar method to the Windows OneDrive software (in the event that port 445 cannot be utilized)
- Proper file locking and/or versioning
- File Access Auditing would be a bonusIt would be great if collaboration/access to files via web browser was also available, but for us, it's not a priority.
I personally like the functionality of Sharepoint/OneDrive, and I see the benefits when using it, but the file and folder count limitations are a no go for us and for many of our clients.
Many companies just want a file server in the cloud without the hassle of having to build/run a VM, or using VPNs, or using some 3rd party syncing software. I am surprised that Microsoft hasn't done this as of yet.
-
Anonymous commented
I do not think this was the intended outcome of this request. Azure ADDS is large undertaking and involves domain joining devices. Not everyone is is doing this. Some are Azure AD joined only. It would be nice to simply have NTFS/ACL function in Azure Files directly so when mapped drive are mounted for a specific user they can see everything but would be denied access to files/folders that they are not privy to. Kind of like the legacy file server shares of years past.
-
Anonymous commented
Can we just have security groups in Azure AD applied to files/folders in Azure File? Azure AD DS seems a bit overkill?
-
Brett commented
Standard AD Authentication is sorely needed for many use cases.
As an example, looking to implement Windows Virtual Desktop, with FSLogix Profiles containers. I want to store these containers in Azure Files, but it is not possible at current, unless I create a PaaS Virtual Machine with File Sync installed to "Proxy" the File Share.
This wouldn't be an issue, except that the profile VHDX will always be in use, and never Tier off, so will need to duplicate the storage between file server, and azure files. (Costly)
-
Paul L commented
This really needs added for this service to be a realistic migration alternative to on site file shares.
-
Anonymous commented
Adding Azure AD (native) support would also be great
-
Tim Nagels commented
Also very interested in an update on when this will be possible from On Premise joined AD devices.
Also wondering: is RBAC role based access possible without Azure AD DS AD Join?
-
MikeN commented
Is there any rough estimate for a roadmap goal of when you'll be able to mount a drive from user endpoints running Windows and MacOS that are not Virtual Machines running in Azure? This is a requirement to seriously consider using Azure Files to replace on-premises SMB/CIFS shares.
-
Simon Harris commented
Any update to this as the comments stretch back a number of months now and into last year?
-
Sascha Goeke commented
Is this solution supposed to work together with Azure file sync (local caching servers)?
-
Oleg commented
waiting for a solution to mount Azure file shares ON-PREMISES with our AAD identity. This is a key feature that's preventing us from migrating more workloads to Azure. An update would be appreciated.
-
Chad commented
Any plan to integrate manage service identity (MSI / User Assigned Managed Identities) support into this feature to control access via a cloud managed identity?
-
Anonymous commented
Why are there no details on the product roadmap for this thing?
We already have a functional AAD synching with on-prem AD. Why should we have to set up AADDS on top of that? Is there any plan to leverage AAD without the other overhead?
-
Bryan Brinegar commented
We've been waiting for a solution to mount Azure file shares on-premises with our AAD identity. This is a key feature that's preventing us from migrating more workloads to Azure. An update would be appreciated.
-
Wim Didden commented
Hi,
I am also very interested in a solution to mount the Azure file shares on-premises with your AAD identity.
At the moment, the only way to use SMB shares is to create a mapping with a Storage account name and key. This solution isn't very fit for an enterprise.
I asked around on an Ignite The Tour event but still no information about this feature.
Is there anything you can share on this matter? -
Luke commented
Hi
Still intereste in this. Most recent user-update seems to be around Nov time.
I think this should be a priroty for MS as it would allow easy movement of current SMB-based solution for LOB apps and user file repository on-premise into the cloud. Right?(user Nam said: contacted to Microsoft Azure Files Team yesterday, and got some the details about the Private Preview of Azure Files that support integration with Azure AD DS. Unfortunately, the preview version needs Azure VM to provide AADS ACL, the external share still uses Storage account name and key for accessing, and does not fit our needs currently.)
-
Anonymous commented
enable deploy file share with GPO
-
Ed Williams commented
How will this apply to Guest accounts who are in the Active Directory?
-
Anonymous commented
Hi,
I wanted to hop into this conversation to get an update if this feature is ready or if it's still in development
Quote :
One of the features I'm lacking is the fact that you cannot give access to Folders/Files on AzureFiles based on Active Directory credentials