Eric Irestone

My feedback

  1. 3,091 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Microsoft
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    125 comments  ·  Storage » Files  ·  Flag idea as inappropriate…  ·  Admin →

    Hi everyone,

    We recently announce the General Availability of Azure Active Directory Domain Services (Azure AD DS) authentication for Azure Files! By enabling integration with Azure AD DS, you can mount your Azure file share over SMB using Azure AD credentials from Azure AD DS domain joined Windows VMs with NTFS ACLs enforced. For more details, please refer to our blog post:http://aka.ms/azure-file-aadds-authentication-ga-blog.

    A part of the GA announcement, we shared the upcoming plan to extend the authentication support to Active Directory (AD) either hosted on-premises or in cloud. If you need an Azure Files solution with AD authentication today, you can consider installing Azure File Sync (AFS) on your Windows File Servers where AD integration is fully supported.

    If you are interested to hear future updates on Azure Files Active Directory Authentication, please complete this sign-up survey:https://aka.ms/AzureFilesADAuthPreviewSurvey.

    Thanks,
    Azure Files Team

    Eric Irestone commented  · 

    Azure File Services provide a great opportunity to allow durability and de-duplication for multiple VMs when accessing common files, vs. copying them on each VHD for each VM.

    I would like to see that File Services allow for authentication against AD, hosted on a VM in Azure for example, so that my Window Services can access these common files via a UNC path.

    This would require the Window Service to run as a specified user in AD allowed to Run as a Service, and if the the Windows Service needed to access a UNC file resource it would not need to provide secondary credentials to access the file. This alleviates the issue of having to use "net use" which has a requirement of needing an Interactive Login for normal use in Windows, or needing to write a custom impersonation wrapper in your Windows Service.

    Eric Irestone supported this idea  · 

Feedback and Knowledge Base