Azure file share on windows 10 no domain

%3CLINGO-SUB%20id%3D%22lingo-sub-1605760%22%20slang%3D%22en-US%22%3EAzure%20file%20share%20on%20windows%2010%20no%20domain%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1605760%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ei%20have%20an%20azure%20AD%20and%20Azure%20AD%20DS.%20i%20have%20host%20pool%20for%20wvd%20and%20Azure%20file%20for%20fileshare.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20Wvd%20users%20have%20access%20to%20fileshare.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUsers%20windows%20machine%20are%20not%20in%20domain%20because%20not%20have%20local%20server.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt's%20possible%20to%20mount%20azure%20file%20share%20on%20users%20computers%20with%20users%20Azure%20AD%20(or%20AD%20DS)%20credentials%20(I%20know%20it's%20possible%20with%20storage%20account%20and%20storage%20key%20but%20users%20should%20not%20have%20admin%20access%20to%20file%20share)%20%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1605778%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20file%20share%20on%20windows%2010%20no%20domain%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1605778%22%20slang%3D%22en-US%22%3E%3CP%3EIt%20is%20possible%20to%20mount%20an%20Azure%20Files%20SMB%20share%20with%20NTFS%20support%20in%20an%20Azure%20AD%20Domain%20Services%20or%20Windows%20AD%20environment.%26nbsp%3B%20However%2C%20the%20client%20computer%20has%20to%20be%20domain%20joined.%26nbsp%3B%20That%20is%20a%20requirement%20for%20the%20Kerberos%20authentication%20between%20Active%20Directory%20Domain%20Services%20and%20the%20storage%20account.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Ffiles%2Fstorage-files-identity-auth-active-directory-domain-service-enable%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Ffiles%2Fstorage-files-identity-auth-active-directory-domain-service-enable%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1605780%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20file%20share%20on%20windows%2010%20no%20domain%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1605780%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F78468%22%20target%3D%22_blank%22%3E%40Travis%20Roberts%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethank's%20for%20you%20reply.%20If%20I%20understand%2C%20I%20need%20local%20server%20with%20AD%20for%20mount%20azure%20file%20share%20with%20NTFS%20support%20on%20my%20local%20computer%20%3F%20It's%20possible%20to%20join%20Azure%20AD%20for%20this%20or%20local%20AD%20is%20necessary%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1605798%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20file%20share%20on%20windows%2010%20no%20domain%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1605798%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F767849%22%20target%3D%22_blank%22%3E%40jeep92%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20local%20computer%20would%20need%20to%20join%20the%20domain%20to%20get%20NTFS%20access.%26nbsp%3B%20Azure%20AD%20joined%20is%20not%20enough%20for%20SMB%20and%20NTFS%20support.%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%2C%20an%20Azure%20File%20Share%20can%20host%20a%20SMB%20share%20with%20NTFS%20for%20Azure%20AD%20DS%20or%20Windows%20AD%20(local)%2C%20but%20not%20both.%26nbsp%3B%20So%20even%20if%20you%20stood%20up%20a%20DC%20locally%2C%20that%20domain%20would%20not%20be%20able%20to%20participate%20in%20the%20same%20share%20that%20is%20attached%20to%20Azure%20AD%20DS.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hi,

 

i have an azure AD and Azure AD DS. i have host pool for wvd and Azure file for fileshare.

 

On Wvd users have access to fileshare.

 

Users windows machine are not in domain because not have local server. 

 

It's possible to mount azure file share on users computers with users Azure AD (or AD DS) credentials (I know it's possible with storage account and storage key but users should not have admin access to file share) ? 

3 Replies
Highlighted

It is possible to mount an Azure Files SMB share with NTFS support in an Azure AD Domain Services or Windows AD environment.  However, the client computer has to be domain joined.  That is a requirement for the Kerberos authentication between Active Directory Domain Services and the storage account.

https://docs.microsoft.com/en-us/azure/storage/files/storage-files-identity-auth-active-directory-do...

Highlighted

Hi @Travis Roberts ,

 

thank's for you reply. If I understand, I need local server with AD for mount azure file share with NTFS support on my local computer ? It's possible to join Azure AD for this or local AD is necessary ?

Highlighted

@jeep92 

The local computer would need to join the domain to get NTFS access.  Azure AD joined is not enough for SMB and NTFS support. 

Also, an Azure File Share can host a SMB share with NTFS for Azure AD DS or Windows AD (local), but not both.  So even if you stood up a DC locally, that domain would not be able to participate in the same share that is attached to Azure AD DS.