Map Azure Storage as Network Drive

%3CLINGO-SUB%20id%3D%22lingo-sub-1797771%22%20slang%3D%22en-US%22%3EMap%20Azure%20Storage%20as%20Network%20Drive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1797771%22%20slang%3D%22en-US%22%3E%3CP%3EHelping%20a%20client%20migrate%20completely%20off%20on-prem%20to%20Azure.%26nbsp%3B%20Need%20to%20map%20Azure%20storage%20directory%20as%20a%20network%20drive%20due%20to%20SQL%20and%20MS%20Access%20coding%20points%20to%20a%20mapped%20drive%20on-prem.%26nbsp%3B%20Few%20of%20the%20employees%20use%20Comcast%20at%20home%2C%20and%20port%20445%20is%20blocked%20so%20unable%20to%20map.%26nbsp%3B%20Setup%20Azure%20Point%20to%20Site%20VPN%2C%20installed%20on%20employee's%20home%20computer%2C%20no%20issue%20connecting%20on%20VPN%20client%2C%20but%20still%20getting%20%22network%20path%20not%20found%22%20when%20attempting%20to%20map%20the%20drive.%26nbsp%3B%20Anyone%20run%20into%20this%20type%20of%20issue%20and%20how%20did%20you%20fix%20%2F%20bypass%3F%3C%2FP%3E%3CP%3EAll%20end%20points%20are%20Windows%2010.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1797771%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ENetworking%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1797895%22%20slang%3D%22en-US%22%3ERe%3A%20Map%20Azure%20Storage%20as%20Network%20Drive%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1797895%22%20slang%3D%22en-US%22%3EEnsure%20port%20445%20is%20open%3A%20The%20SMB%20protocol%20requires%20TCP%20port%20445%20to%20be%20open%3B%20connections%20will%20fail%20if%20port%20445%20is%20blocked.%20You%20can%20check%20if%20your%20firewall%20is%20blocking%20port%20445%20with%20the%20Test-NetConnection%20cmdlet.%20To%20learn%20about%20ways%20to%20work%20around%20a%20blocked%20445%20port%2C%20see%20the%20Cause%201%3A%20Port%20445%20is%20blocked%20section%20of%20our%20Windows%20troubleshooting%20guide.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Ffiles%2Fstorage-troubleshoot-windows-file-connection-problems%23cause-1-port-445-is-blocked%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Ffiles%2Fstorage-troubleshoot-windows-file-connection-problems%23cause-1-port-445-is-blocked%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3ETo%20use%20an%20Azure%20file%20share%20with%20Windows%2C%20you%20must%20either%20mount%20it%2C%20which%20means%20assigning%20it%20a%20drive%20letter%20or%20mount%20point%20path%2C%20or%20access%20it%20via%20its%20UNC%20path.%3CBR%20%2F%3E%3CBR%20%2F%3EThis%20article%20uses%20the%20storage%20account%20key%20to%20access%20the%20file%20share.%20A%20storage%20account%20key%20is%20an%20administrator%20key%20for%20a%20storage%20account%2C%20including%20administrator%20permissions%20to%20all%20files%20and%20folders%20within%20the%20file%20share%20you're%20accessing%2C%20and%20for%20all%20file%20shares%20and%20other%20storage%20resources%20(blobs%2C%20queues%2C%20tables%2C%20etc.)%20contained%20within%20your%20storage%20account.%20If%20this%20is%20not%20sufficient%20for%20your%20workload%2C%20Azure%20File%20Sync%20may%20be%20used%2C%20or%20you%20may%20use%20identity-based%20authentication%20over%20SMB.%3CBR%20%2F%3E%3CBR%20%2F%3EA%20common%20pattern%20for%20lifting%20and%20shifting%20line-of-business%20(LOB)%20applications%20that%20expect%20an%20SMB%20file%20share%20to%20Azure%20is%20to%20use%20an%20Azure%20file%20share%20as%20an%20alternative%20for%20running%20a%20dedicated%20Windows%20file%20server%20in%20an%20Azure%20VM.%20One%20important%20consideration%20for%20successfully%20migrating%20a%20line-of-business%20application%20to%20use%20an%20Azure%20file%20share%20is%20that%20many%20line-of-business%20applications%20run%20under%20the%20context%20of%20a%20dedicated%20service%20account%20with%20limited%20system%20permissions%20rather%20than%20the%20VM's%20administrative%20account.%20Therefore%2C%20you%20must%20ensure%20that%20you%20mount%2Fsave%20the%20credentials%20for%20the%20Azure%20file%20share%20from%20the%20context%20of%20the%20service%20account%20rather%20than%20your%20administrative%20account.%3C%2FLINGO-BODY%3E
Occasional Visitor

Helping a client migrate completely off on-prem to Azure.  Need to map Azure storage directory as a network drive due to SQL and MS Access coding points to a mapped drive on-prem.  Few of the employees use Comcast at home, and port 445 is blocked so unable to map.  Setup Azure Point to Site VPN, installed on employee's home computer, no issue connecting on VPN client, but still getting "network path not found" when attempting to map the drive.  Anyone run into this type of issue and how did you fix / bypass?

All end points are Windows 10.  

Thanks in advance.

1 Reply
Ensure port 445 is open: The SMB protocol requires TCP port 445 to be open; connections will fail if port 445 is blocked. You can check if your firewall is blocking port 445 with the Test-NetConnection cmdlet. To learn about ways to work around a blocked 445 port, see the Cause 1: Port 445 is blocked section of our Windows troubleshooting guide.

https://docs.microsoft.com/en-us/azure/storage/files/storage-troubleshoot-windows-file-connection-pr...

To use an Azure file share with Windows, you must either mount it, which means assigning it a drive letter or mount point path, or access it via its UNC path.

This article uses the storage account key to access the file share. A storage account key is an administrator key for a storage account, including administrator permissions to all files and folders within the file share you're accessing, and for all file shares and other storage resources (blobs, queues, tables, etc.) contained within your storage account. If this is not sufficient for your workload, Azure File Sync may be used, or you may use identity-based authentication over SMB.

A common pattern for lifting and shifting line-of-business (LOB) applications that expect an SMB file share to Azure is to use an Azure file share as an alternative for running a dedicated Windows file server in an Azure VM. One important consideration for successfully migrating a line-of-business application to use an Azure file share is that many line-of-business applications run under the context of a dedicated service account with limited system permissions rather than the VM's administrative account. Therefore, you must ensure that you mount/save the credentials for the Azure file share from the context of the service account rather than your administrative account.