<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Azure Storage Blog articles</title>
    <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/bg-p/AzureStorageBlog</link>
    <description>Azure Storage Blog articles</description>
    <pubDate>Wed, 29 Jul 2026 12:54:53 GMT</pubDate>
    <dc:creator>AzureStorageBlog</dc:creator>
    <dc:date>2026-07-29T12:54:53Z</dc:date>
    <item>
      <title>Optimize Oracle workloads on Azure with Azure NetApp Files</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/optimize-oracle-workloads-on-azure-with-azure-netapp-files/ba-p/4532644</link>
      <description>&lt;H1&gt;Table of Contents&lt;/H1&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc889217376" target="_self" rel="noopener"&gt;Introduction&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc1077756729" target="_self" rel="noopener"&gt;Azure NetApp Files Advancements Overview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc1040642234" target="_self" rel="noopener"&gt;Azure NetApp Files Advancements in Detail&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc109122866" target="_self" rel="noopener"&gt;Flexible service level capacity pools&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc312431028" target="_self" rel="noopener"&gt;Oracle Direct NFS&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc1009494549" target="_self" rel="noopener"&gt;Application volume group for Oracle&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;A href="#community--1-_Toc701886304" target="_self" rel="noopener"&gt;Availability zone volume placement&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;A href="#community--1-_Toc728735644" target="_self" rel="noopener"&gt;High availability&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;A href="#community--1-_Toc935810763" target="_self" rel="noopener"&gt;Standard network features&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;A href="#community--1-_Toc1406978524" target="_self" rel="noopener"&gt;Simplified deployment&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;A href="#community--1-_Toc486450575" target="_self" rel="noopener"&gt;Optimal volume placement&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;A href="#community--1-_Toc943352380" target="_self" rel="noopener"&gt;Scalability and flexibility&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;A href="#community--1-_Toc481088823" target="_self" rel="noopener"&gt;Integrated data protection&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;A href="#community--1-_Toc930772596" target="_self" rel="noopener"&gt;Using application volume group for Oracle&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="#community--1-_Toc534193383" target="_self" rel="noopener"&gt;VM IO throttling&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;&lt;A href="#community--1-_Toc1086250791" target="_self" rel="noopener"&gt;Automatic Storage Management (ASM)&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc1091691147" target="_self" rel="noopener"&gt;Migration assistant&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc1142143802" target="_self" rel="noopener"&gt;Short-term clones&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc529712874" target="_self" rel="noopener"&gt;Storage with cool access&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc2110269457" target="_self" rel="noopener"&gt;Sizing Your Volume Deployment for Oracle&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-internal-link" href="#community--1-_Toc256497963" target="_self" rel="noopener" data-lia-auto-title="Using Azure NetApp Files as backup target and test/dev for Oracle AI Database@Azure&amp;nbsp;" data-lia-auto-title-active="0"&gt;Using Azure NetApp Files as backup target and test/dev for Oracle AI Database@Azure&amp;nbsp;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc40213825" target="_self" rel="noopener"&gt;Summary&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc1385992621" target="_self" rel="noopener"&gt;Learn more&lt;/A&gt;&lt;/P&gt;
&lt;H1&gt;&lt;a id="community--1-_Toc889217376" class="lia-anchor"&gt;&lt;/a&gt;&lt;a id="community--1-_Toc233057490" class="lia-anchor"&gt;&lt;/a&gt;Introduction&lt;/H1&gt;
&lt;P&gt;Oracle workloads do not move to the cloud on storage promises alone. They only move when performance is predictable, operational needs are familiar, and the platform gives teams the flexibility they need to grow without disruption or the need to redesign or remigrate a database architecture as requirements evolve.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That was the foundation of the Azure Architecture Center &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/architecture/example-scenario/file-storage/oracle-azure-netapp-files" target="_blank" rel="noopener"&gt;Oracle Database with Azure NetApp Files&lt;/A&gt; reference architecture, which documents how Azure NetApp Files provides high-performance NFS storage for Oracle Database on Azure virtual machines. The article remains an important reference for customers who want low latency, high throughput, flexible scaling, data protection, and cloning for demanding Oracle environments.&lt;/P&gt;
&lt;P&gt;Since then, Azure NetApp Files has grown and evolved. New capabilities now make Oracle environments easier to size, deploy, protect, replicate, migrate, and clone on Azure. This article builds on the original Azure Architecture Center guidance and highlights what has changed: flexible service level capacity pools, application volume group for Oracle, availability-zone-aware volume placement, migration assistant, short-term clones, cool access, and expanded data protection options. &lt;BR /&gt;&lt;BR /&gt;This article explains how Oracle on Azure Virtual Machines can benefit from using Azure NetApp Files volumes for primary database storage and provides an additional look at how Azure NetApp Files can complement Oracle AI Database@Azure as a backup target and a source for rapid, space-efficient database clones.&lt;/P&gt;
&lt;P&gt;Co-authors:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/arntdegier/" target="_blank" rel="noopener"&gt;Arnt de Gier&lt;/A&gt;, Azure NetApp Files Product Manager&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/jeffrey-steiner-4465797/" target="_blank" rel="noopener"&gt;Jeffrey Steiner&lt;/A&gt;, Principal Architect, NetApp&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&lt;a id="community--1-_Toc1077756729" class="lia-anchor"&gt;&lt;/a&gt;&lt;a id="community--1-_Toc233057490" class="lia-anchor"&gt;&lt;/a&gt;Azure NetApp Files Advancements Overview&lt;/H1&gt;
&lt;P&gt;The most important advances are not just about faster storage. They are about making Oracle environments easier to size, deploy, protect, migrate, replicate, and reuse across the full database lifecycle.&lt;/P&gt;
&lt;P&gt;Key advancements include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Flexible service level capacity pools&lt;/STRONG&gt; &lt;BR /&gt;Capacity and throughput can now be tuned independently. Some databases are heavy on IOPS, while others are bandwidth-hungry. ANF capacity pools now help you avoid overprovisioning and align storage performance more closely with actual Oracle workload demand.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Application volume group for Oracle&lt;/STRONG&gt;&lt;BR /&gt;Deployment of Oracle data, redo, archive, and backup volumes can be automated through a workflow that applies Oracle-aware layout and placement guidance.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Availability-zone-aware volume placement&lt;/STRONG&gt;&lt;BR /&gt;Oracle VMs and Azure NetApp Files volumes can be aligned in the same availability zone to reduce avoidable latency and support more predictable performance.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Enhanced data protection and replication&lt;/STRONG&gt;&lt;BR /&gt;Snapshots, backup, cross-zone replication, and cross-region replication give customers more options to protect Oracle data and design for business continuity.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Migration assistant&lt;/STRONG&gt;&lt;BR /&gt;ONTAP-based volumes can be migrated to Azure NetApp Files using efficient block-level replication, preserving file structure, permissions, and existing snapshots while enabling incremental cutover planning.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Short-term clones&lt;/STRONG&gt;&lt;BR /&gt;Snapshots can be turned into writable, space-efficient clones for test, development, reporting, validation, or troubleshooting without creating full physical copies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Storage with cool access&lt;/STRONG&gt;&lt;BR /&gt;Inactive data can be tiered automatically to optimize storage cost while keeping data accessible through the same Azure NetApp Files namespace. This helps manage the cost of Azure NetApp Files volumes used as backup targets for Oracle databases.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Oracle Database@Azure backup and clone integration&lt;/STRONG&gt; - Azure NetApp Files can be used as a high-performance backup target and a source for rapid, space-efficient test and development refreshes using snapshots and short-term clones.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these advancements shift the conversation from simply “Can Oracle run well on Azure NetApp Files?” to “How can Oracle environments on Azure become easier to operate, easier to protect, and easier to scale?” For customers, that means more deployment confidence, better cost control, faster refresh cycles, and a more practical path to modernizing Oracle workloads on Azure.&lt;/P&gt;
&lt;H1&gt;Azure NetApp Files Advancements in Detail&lt;/H1&gt;
&lt;H2&gt;&lt;a id="community--1-_Toc109122866" class="lia-anchor"&gt;&lt;/a&gt;&lt;a id="community--1-_Toc233057491" class="lia-anchor"&gt;&lt;/a&gt;Flexible service level capacity pools&lt;/H2&gt;
&lt;P&gt;To match Azure NetApp Files storage to the real needs of each Oracle workload use &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/azure-netapp-files-service-levels#flexible-service-level-throughput-examples" target="_blank" rel="noopener"&gt;Flexible service level&lt;/A&gt; to enable sizing and scaling of capacity and throughput independently of each other instead of sizing capacity and performance together like you do with the traditional service levels (standard, premium and ultra). For an Oracle DBA, this means you can allocate the storage capacity your database requires and then tune throughput separately for the expected I/O profile. You start with a baseline throughput of 128 MiB/s and can increase performance in small increments, up to five times the Ultra service level per provisioned 1 TiB. This makes it easier to support demanding databases without over-provisioning storage, and it can reduce costs by 10–40% by paying only for the capacity and performance the workload actually needs. As database demand changes, you can adjust the balance between capacity and throughput to keep performance aligned with current requirements.&lt;/P&gt;
&lt;H2&gt;&lt;a id="community--1-_Toc233057493" class="lia-anchor"&gt;&lt;/a&gt;&lt;a id="community--1-_Toc312431028" class="lia-anchor"&gt;&lt;/a&gt;Oracle Direct NFS&lt;/H2&gt;
&lt;P&gt;Oracle Direct NFS (dNFS) with Azure NetApp Files gives Oracle workloads a faster, cleaner path to primary storage. Because dNFS is built into Oracle Database, it lets Oracle access Azure NetApp Files through a database-optimized NFS client rather than relying only on the host operating system. For customers, that means more predictable performance, simpler operations, and a practical way to modernize Oracle environments without changing proven NFS-based operating models.&lt;/P&gt;
&lt;P&gt;This pairing is especially useful for performance-sensitive Oracle databases, where low latency, scalable throughput, and operational consistency matter. Azure NetApp Files provides enterprise-grade shared storage with flexible capacity and throughput, while dNFS helps Oracle use that storage efficiently for production, reporting, migration, consolidation, and test/dev scenarios.&lt;/P&gt;
&lt;P&gt;The result is a storage architecture that is easy to understand, easy to scale, and easy to protect. Customers can keep familiar Oracle-on-NFS practices while gaining the elasticity, data protection, replication, backup, and cloning capabilities of Azure NetApp Files.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Predictable Oracle performance with a database-optimized NFS access path.&lt;/LI&gt;
&lt;LI&gt;Greater migration confidence for customers moving from on-premises NAS to Azure.&lt;/LI&gt;
&lt;LI&gt;Simpler storage operations with Azure NetApp Files snapshots, backup, replication, and cloning.&lt;/LI&gt;
&lt;LI&gt;Flexible scaling of capacity and throughput as Oracle workload demand changes.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P&gt;Oracle Direct NFS provides a database-optimized I/O path from Oracle Database on Azure VMs to Azure NetApp Files primary NFS storage, while Azure NetApp Files adds scalable throughput and enterprise data services such as snapshots, backup, replication, and cloning.&lt;/P&gt;
&lt;H2&gt;&lt;a id="community--1-_Toc233057494" class="lia-anchor"&gt;&lt;/a&gt;&lt;a id="community--1-_Toc1009494549" class="lia-anchor"&gt;&lt;/a&gt;Application volume group for Oracle&lt;/H2&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/application-volume-group-oracle-introduction" target="_blank" rel="noopener"&gt;Application volume group (AVG) for Oracle&lt;/A&gt; is a feature offered through Azure NetApp Files, designed to simplify the process of deploying all required volumes to install and run an Oracle database on Azure VMs (IaaS).&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;With just one workflow, you can provision volumes for data, redo, archive, and backup. This consolidation streamlines volume management, enforces best practices, and supports easy adjustments for size and throughput after deployment, all while keeping the flexibility of Azure NetApp Files volumes.&lt;/P&gt;
&lt;P&gt;Application volume group for Oracle was recently enhanced with new functionality:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Availability zone volume placement: volumes should be placed in the same availability zone as the Oracle virtual machines, minimizing network latency by shortening the data path.&lt;/LI&gt;
&lt;LI&gt;Data protection volume group creation: The same automated process allows you to create a data protection volume group with matching layout and naming for business continuity and disaster recovery in a secondary availability zone or region.&lt;/LI&gt;
&lt;LI&gt;Standard network features: always utilize standard network features for best performance.&lt;/LI&gt;
&lt;LI&gt;Enhanced performance: by deploying data and log volumes on separate storage endpoints, IOs are processed independently, preventing data read slowdowns during high-priority log writes. Application volume group will deploy multiple data volumes across different storage endpoints for large-scale workloads, using sizing inputs and affinity rules to optimize performance.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;a id="community--1-_Toc701886304" class="lia-anchor"&gt;&lt;/a&gt;Availability zone volume placement&lt;/H3&gt;
&lt;P&gt;The efficiency of application volume group for Oracle is enhanced by aligning Azure NetApp Files volumes with the application VMs in the same availability zone. This alignment is crucial for meeting strict latency requirements, ensuring your Oracle applications run smoothly and efficiently.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;Using compute in one zone and storage in another across a cross-zone data path (right side) introduces unnecessary latency and is easily avoided using availability zone aware volume placement and placing compute and storage in the same zone over a short data path (left side).&lt;/P&gt;
&lt;H3&gt;&lt;a id="community--1-_Toc728735644" class="lia-anchor"&gt;&lt;/a&gt;High availability&lt;/H3&gt;
&lt;P&gt;Azure availability zones are distinct locations within a region. By deploying Oracle volumes and application VMs in the same zone - and replicating data and redo logs to a secondary zone or region using &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/replication" target="_blank" rel="noopener"&gt;cross-zone replication or cross-region replication&lt;/A&gt;&amp;nbsp; you minimize the risk data loss during a disaster. Azure NetApp Files’ built-in &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/replication" target="_blank" rel="noopener"&gt;replication&lt;/A&gt; can offload the replication of data files and volumes freeing up compute resources for transaction processing and deliver an RPO as low as 10 minutes. The replica can also be activated for a near-zero RTO. If an RPO and RTO all the way down to zero are required, you can use Oracle Data Guard to create a fully operational hot standby copy of your database.&lt;/P&gt;
&lt;H3&gt;&lt;a id="community--1-_Toc935810763" class="lia-anchor"&gt;&lt;/a&gt;Standard network features&lt;/H3&gt;
&lt;P&gt;The use of standard network features is recommended for all new implementations of Azure NetApp Files volumes. Basic network features is no longer supported for new deployments and will be phased out completely. Volumes using basic network features can be migrated to standard network features without interruption.&lt;/P&gt;
&lt;H3&gt;&lt;a id="community--1-_Toc1406978524" class="lia-anchor"&gt;&lt;/a&gt;Simplified deployment&lt;/H3&gt;
&lt;P&gt;The automated application volume group deployment workflow accelerates and simplifies volume deployment, significantly reducing the risk of human error and resulting in a more reliable setup.&lt;/P&gt;
&lt;H3&gt;&lt;a id="community--1-_Toc486450575" class="lia-anchor"&gt;&lt;/a&gt;Optimal volume placement&lt;/H3&gt;
&lt;P&gt;Application volume group considers the underlying physical resources, applying affinity and anti-affinity rules to find the best locations for performance-critical volumes. This process ensures that your deployment achieves optimal performance; this is not possible with manual, one-by-one volume provisioning. Application volume group also splits data and log volumes across different storage endpoints to maximize performance and reduce contention.&lt;/P&gt;
&lt;H3&gt;&lt;a id="community--1-_Toc943352380" class="lia-anchor"&gt;&lt;/a&gt;Scalability and flexibility&lt;/H3&gt;
&lt;P&gt;Volume capacity and throughput can be easily resized before, during, or after deployment, allowing you to adapt your Oracle environment to changing needs without sacrificing availability or performance. Volume resizing and throughput adjustments can be done without interruption to the storage service and while the database is online.&lt;/P&gt;
&lt;H3&gt;&lt;a id="community--1-_Toc481088823" class="lia-anchor"&gt;&lt;/a&gt;Integrated data protection&lt;/H3&gt;
&lt;P&gt;Volumes deployed by application volume group are compatible with Azure NetApp Files data protection solutions, such as efficient, application-consistent &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/snapshots-introduction" target="_blank" rel="noopener"&gt;snapshots&lt;/A&gt; and &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/backup-introduction" target="_blank" rel="noopener"&gt;backup&lt;/A&gt; offloading.&amp;nbsp; Data management tools like &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/azacsnap-introduction" target="_blank" rel="noopener"&gt;AzAcSnap&lt;/A&gt;, NetApp &lt;A class="lia-external-url" href="https://docs.netapp.com/us-en/snapcenter/get-started/concept_snapcenter_overview.html" target="_blank" rel="noopener"&gt;SnapCenter®&lt;/A&gt; software or other 3&lt;SUP&gt;rd&lt;/SUP&gt;-party data protection tools compatible with Azure NetApp Files are required to further ensure the consistency and safety of your Oracle data.&lt;/P&gt;
&lt;H3&gt;&lt;a id="community--1-_Toc233057495" class="lia-anchor"&gt;&lt;/a&gt;&lt;a id="community--1-_Toc930772596" class="lia-anchor"&gt;&lt;/a&gt;Using application volume group for Oracle&lt;/H3&gt;
&lt;P&gt;To use application volume groups, you need an Azure NetApp Files &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/azure-netapp-files-understand-storage-hierarchy" target="_blank" rel="noopener"&gt;capacity pool&lt;/A&gt; that matches or exceeds the recommendations from the sizing exercise, and to be configured with &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/azure-netapp-files-understand-storage-hierarchy#qos_types" target="_blank" rel="noopener"&gt;Manual QoS&lt;/A&gt;. This setting allows application volume group to independently set volume throughput and capacity, making the most efficient use of the capacity pool since no overprovisioning will be required in this concept. The application volume group workflow calculates minimum required size and throughput based on your inputs and offers recommendations for optional backup volumes. After a successful pre-check it validates your inputs against the selected capacity pool, you simply click to deploy and after a few minutes your volumes are ready to mount onto your Oracle application VMs.&lt;/P&gt;
&lt;H4&gt;&lt;a id="community--1-_Toc534193383" class="lia-anchor"&gt;&lt;/a&gt;VM IO throttling&lt;/H4&gt;
&lt;P&gt;Not covered in this blog, but what may add to a more friendly TCO is the fact that network IO is not throttled by Azure VMs like managed disk is. This directly results in larger storage bandwidth when used with network connected storage like Azure NetApp Files. You may achieve the same or better performance with a smaller VM SKU, and this may have positive consequences for licensing as well.&lt;BR /&gt;Oracle on Azure specialists are available to help you with sizing Azure NetApp Files capacity pools, volumes and VM SKUs using your AWR reports.&lt;/P&gt;
&lt;H4&gt;&lt;a id="community--1-_Toc1086250791" class="lia-anchor"&gt;&lt;/a&gt;Automatic Storage Management (ASM)&lt;/H4&gt;
&lt;P&gt;Oracle’s Automatic Storage Management is primarily designed to stripe data across multiple devices. This helps improve performance, plus devices can be added and removed nondisruptively, which makes capacity management easier.&lt;/P&gt;
&lt;P&gt;Azure NetApp Files has the same capabilities, making ASM generally unnecessary. With Azure NetApp Files, IO is striped across multiple devices as the physical storage layer, and volumes can be resized on the fly and even throughput can be adjusted on the fly.&lt;/P&gt;
&lt;P&gt;If you require ASM, for example, if you have existing procedures and scripts that depend on ASM, it is still fully supported with Azure NetApp Files and features like dynamic performance management still apply. You also get additional benefits. For example, you can create instant, space-efficient snapshots of your ASM diskgroups, and those snapshots can be offloaded to Azure NetApp Files backup for long term retention and protection against unlikely complete volume loss or corruption.&lt;/P&gt;
&lt;H2&gt;&lt;a id="community--1-_Toc233057496" class="lia-anchor"&gt;&lt;/a&gt;&lt;a id="community--1-_Toc1091691147" class="lia-anchor"&gt;&lt;/a&gt;Migration assistant&lt;/H2&gt;
&lt;P&gt;Migration assistant allows for efficient migration of on-premises NetApp ONTAP® based storage volumes to Azure NetApp Files volumes.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;This enables optimized volume migration to Azure NetApp Files volumes using NetApp SnapMirror® technology, providing:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Optimized volume migration with encryption and compression in transit to save network bandwidth&lt;/LI&gt;
&lt;LI&gt;Complete database volumes are migrated, including the complete file structure with permissions and previously taken snapshots&lt;/LI&gt;
&lt;LI&gt;Dry-run options are offered to perform intermediate testing of the migrated data volumes&lt;/LI&gt;
&lt;LI&gt;Flexible cut-over planning with block-level incremental final transfer&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;&lt;a id="community--1-_Toc233057497" class="lia-anchor"&gt;&lt;/a&gt;&lt;a id="community--1-_Toc1142143802" class="lia-anchor"&gt;&lt;/a&gt;Short-term clones&lt;/H2&gt;
&lt;P&gt;Azure NetApp Files &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/create-short-term-clone" target="_blank" rel="noopener"&gt;short-term clones&lt;/A&gt; help reduce costs by allowing space-efficient provisioning of volume clones from snapshots for test/dev and other purposes.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;The space efficiency stems from smart block manipulation in Azure NetApp Files, where the short-term clone uses the same blocks as the originating volume except for any changes made. Changed and new data blocks are written to a separate space in the short-term clone volume. Short-term clones are available almost immediately after creation and only take space in the capacity pool for any anticipated changes to be written to the clones. This saves capacity pool allocation space and cost. After 32 days short-term clones need to be either removed or converted to full independent clones.&lt;BR /&gt;Use short-term clones to rapidly create copies of production databases for analysis and test and development at minimal cost impact.&lt;/P&gt;
&lt;H2&gt;&lt;a id="community--1-_Toc233057498" class="lia-anchor"&gt;&lt;/a&gt;&lt;a id="community--1-_Toc529712874" class="lia-anchor"&gt;&lt;/a&gt;Storage with cool access&lt;/H2&gt;
&lt;P&gt;Leveraging Azure NetApp Files&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/cool-access-introduction" target="_blank" rel="noopener"&gt;storage with cool access&lt;/A&gt; enables customers to optimize their storage strategies, reduce expenses, and efficiently manage their data lifecycle. Cool access automatically moves unused data to the Azure storage account without any changes required to user behavior or applications. This flexibility and efficiency make it a valuable option for a wide range of use cases, including backup and archival, data lakes, and compliance storage.&lt;/P&gt;
&lt;H1&gt;&lt;a id="community--1-_Toc233057499" class="lia-anchor"&gt;&lt;/a&gt;&lt;a id="community--1-_Toc2110269457" class="lia-anchor"&gt;&lt;/a&gt;Sizing Your Volume Deployment for Oracle&lt;/H1&gt;
&lt;P&gt;Sizing tools are available to help determine the required volume configuration for Oracle. When migrating databases to Azure, generate &lt;A class="lia-external-url" href="https://docs.oracle.com/en/database/oracle/oracle-database/26/tgdba/gathering-database-statistics.html" target="_blank" rel="noopener"&gt;Automatic Workload Repository (AWR)&lt;/A&gt; reports to analyze your current storage activity. AWR reports should be created at times when the database is at its highest load and run for a few hours. These reports allow the migration team to project suitable Azure NetApp Files volumes. &lt;BR /&gt;You can also upload multiple AWR reports to online sizing utilities such as the &lt;A class="lia-external-url" href="https://app.atroposs.com" target="_blank" rel="noopener"&gt;Atroposs&lt;/A&gt; and obtain recommendations for Azure NetApp Files capacity pool and volume layout using the &lt;A class="lia-external-url" href="https://app.atroposs.com/#/anf-module" target="_blank" rel="noopener"&gt;Atroposs Azure NetApp Files Oracle Volumes TCO Estimator module&lt;/A&gt; which uses the measurements from the AWR reports provided. Since the database size is not included in the AWR reports, you need to enter the database size(s) manually. You can collect database sizes using &lt;A class="lia-external-url" href="https://app.atroposs.com/awr-assets/sql/dbSize.sql" target="_blank" rel="noopener"&gt;this SQL script&lt;/A&gt;. Both volume capacity and throughput can be changed any time after deployment, providing flexibility and cost-efficiency. Please visit&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/anftools" target="_blank" rel="noopener"&gt;aka.ms/anftools&lt;/A&gt; for additional Azure NetApp Files estimator and sizing tools.&lt;/P&gt;
&lt;H1&gt;&lt;a id="community--1-_Toc233057500" class="lia-anchor"&gt;&lt;/a&gt;&lt;a id="community--1-_Toc256497963" class="lia-anchor"&gt;&lt;/a&gt;Using Azure NetApp Files as backup target and test/dev for Oracle AI Database@Azure&lt;/H1&gt;
&lt;P&gt;For &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/oracle/oracle-db/database-overview" target="_blank" rel="noopener"&gt;Oracle AI Database@Azure&lt;/A&gt; deployments, Azure NetApp Files volumes can add value as high-performance backup targets that also become practical data sources for rapid test and development refreshes.&lt;/P&gt;
&lt;P&gt;If all you need is a simple, easy-to-manage high-throughput RMAN backup target, Azure NetApp Files can be used as a simple, yet high-performance shared filesystem. You can also take snapshots of your RMAN backups for additional protection and replicate those backups to other regions.&lt;/P&gt;
&lt;P&gt;If you really want to reduce your backup window and slash the capacity required for RMAN backups, you can combine RMAN image and incremental backups with Azure NetApp Files snapshots. The result is an incremental-forever backup strategy, but with a library of full-sized RMAN backups available within the snapshots. Backup windows shrink, and the only extra space required for each backup you retain is for the data that changed between backups.&lt;/P&gt;
&lt;P&gt;You can also treat backups as more than just a recovery asset. Backup volumes can be used to capture recent, application-consistent copies of production data and make those copies available for temporary downstream use.&lt;/P&gt;
&lt;P&gt;There are two options. First, you can set up a standby database (using Oracle Data Guard or as a traditional standby) to a right-sized VM and then create snapshot-based backups of that replica. That delivers backups as well as a low/zero RPO/RTO DR capability, but it can also be used for cloning. NetApp’s SnapCenter can automate the process from start-to-finish using those snapshots.&lt;/P&gt;
&lt;P&gt;That is done through short-term clones. When a backup lands on an Azure NetApp Files volume, a snapshot of that backup set can be used to create a short-term clone. The short-term clone is writable, available quickly, and space-efficient because it references the existing snapshot data and only consumes additional capacity for changed blocks. This makes it well suited for feeding fresh production-like data to test, development, reporting, validation, or troubleshooting environments without creating full physical copies of large Oracle data sets.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Accelerates refresh cycles by making recent backup data available to non-production environments in minutes rather than through lengthy copy or restore processes.&lt;/LI&gt;
&lt;LI&gt;Reduces storage consumption and cost by avoiding full-size duplicate database copies for short-lived test and development needs.&lt;/LI&gt;
&lt;LI&gt;Limits production impact because clone creation is based on backup or snapshot data rather than direct activity against the active production database volumes.&lt;/LI&gt;
&lt;LI&gt;Improves developer and QA productivity by providing realistic, current data sets for functional testing, upgrade validation, performance troubleshooting, and release rehearsal.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;After the test/dev activity is complete, the short-term clone can be deleted before it ages out or converted to a regular volume if it needs to be retained longer. This approach turns the &lt;SPAN style="color: rgb(30, 30, 30);"&gt;Oracle AI Database@Azure&lt;/SPAN&gt;&amp;nbsp;backup target into an active data lifecycle asset: protecting the database while also enabling faster, lower-cost access to fresh data for innovation and operational readiness.&lt;/P&gt;
&lt;P&gt;That’s not the only route to leveraging short-term clones. If you’re using Azure NetApp Files with the incremental-forever backup strategy, each of those snapshots contains a fully consistent set of datafiles. You can also clone them and bring them up as an operational database using your own automation tools.&lt;/P&gt;
&lt;H1&gt;&lt;a id="community--1-_Toc233057501" class="lia-anchor"&gt;&lt;/a&gt;&lt;a id="community--1-_Toc40213825" class="lia-anchor"&gt;&lt;/a&gt;Summary&lt;/H1&gt;
&lt;P&gt;Consider the use of Azure NetApp Files volumes for your Oracle databases for flexibility, cost-efficiency, data protection and high-availability. You may achieve the same or better database performance even when using smaller VM SKUs in Azure. Snapshots provide extremely fast and efficient primary data protection from which complete databases can be restored very quickly. Use RMAN or other integrated backup applications to orchestrate the creation of snapshots for application consistency and easy operation.&lt;/P&gt;
&lt;P&gt;Application volume group for Oracle provides a robust solution for deploying multiple Azure NetApp Files volumes for use with Oracle, optimizing performance, availability, and management of your Oracle databases. Leveraging availability zone placement ensures that your Oracle environment is resilient and ready for modern business challenges. Use application volume group for Oracle also for provisioning data protection volumes in an alternate zone or region and use cross-zone and cross-region replication to offload data and log volume replication from the application VMs for higher efficiency and better performance.&lt;/P&gt;
&lt;P&gt;For efficient migration of on-premises ONTAP-based volumes to Azure NetApp Files, use migration assistant.&lt;/P&gt;
&lt;P&gt;When using &lt;SPAN style="color: rgb(30, 30, 30);"&gt;Oracle AI Database@Azure&amp;nbsp;&lt;/SPAN&gt;consider sending backup data to Azure NetApp Files volumes to allow space-efficient volume cloning and feeding test/dev operations with fresh data from production.&lt;/P&gt;
&lt;P&gt;Consult Oracle on Azure specialists for sizing Azure NetApp Files volumes and VM SKUs for your Oracle deployment on IaaS in Azure.&lt;/P&gt;
&lt;H1&gt;&lt;a id="community--1-_Toc233057502" class="lia-anchor"&gt;&lt;/a&gt;&lt;a id="community--1-_Toc1385992621" class="lia-anchor"&gt;&lt;/a&gt;Learn more&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/azure-netapp-files-introduction" target="_blank" rel="noopener"&gt;What is Azure NetApp Files | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/azure-netapp-files-understand-storage-hierarchy" target="_blank" rel="noopener"&gt;Storage hierarchy of Azure NetApp Files | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://learn.microsoft.com/azure/architecture/example-scenario/file-storage/oracle-azure-netapp-files" target="_blank" rel="noopener"&gt;Oracle Database with Azure NetApp Files - Azure Architecture Center | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/application-volume-group-oracle-introduction" target="_blank" rel="noopener"&gt;Understand Azure NetApp Files application volume group for Oracle | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/application-volume-group-oracle-considerations" target="_blank" rel="noopener"&gt;Requirements and considerations for Azure NetApp Files application volume group for Oracle | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/application-volume-group-oracle-deploy-volumes" target="_blank" rel="noopener"&gt;Deploy application volume group for Oracle using Azure NetApp Files | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" style="background-color: rgb(255, 255, 255); font-style: normal; font-weight: 400;" href="https://learn.microsoft.com/azure/azure-netapp-files/azacsnap-introduction" target="_blank" rel="noopener"&gt;What is the Azure Application Consistent Snapshot tool for Azure NetApp Files | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://docs.netapp.com/us-en/snapcenter/protect-sco/concept_snapcenter_plug_in_for_oracle_database_features.html" target="_blank" rel="noopener"&gt;SnapCenter software - Features of Plug-in for Oracle Database | NetApp Product documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.youtube.com/watch?v=9i4Qgch6BIY" target="_blank" rel="noopener"&gt;Quick Bytes: Azure NetApp Files application volume group for Oracle&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.youtube.com/watch?v=1SvK-Ln-Rx8" target="_blank" rel="noopener"&gt;How-To: AVG for Oracle - Add data protection volumes&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.youtube.com/watch?v=Ua5i1LYPtpg" target="_blank" rel="noopener"&gt;How-to: Create Oracle database short-term clones in Azure NetApp Files with SnapCenter&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 09 Jul 2026 16:22:43 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/optimize-oracle-workloads-on-azure-with-azure-netapp-files/ba-p/4532644</guid>
      <dc:creator>GeertVanTeylingen</dc:creator>
      <dc:date>2026-07-09T16:22:43Z</dc:date>
    </item>
    <item>
      <title>Announcing General Availability of Client-Side Data Integrity Protections in Azure Blob Storage</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/announcing-general-availability-of-client-side-data-integrity/ba-p/4531364</link>
      <description>&lt;P&gt;We are excited to announce the General Availability of client-side data integrity in Azure Blob Storage. Blob Storage has long supported integrity validation, starting with MD5 as part of the original HTTP standards and adding CRC64-NVME support in 2019. Today, CRC64-NVME is now integrated into the latest Azure Blob SDKs for .NET, C++, and JavaScript, extending Azure’s data integrity protections all the way into client applications.&lt;/P&gt;
&lt;P&gt;Azure has had a longstanding commitment to provide the world’s most secure and reliable cloud storage platform. By extending data integrity protections into client applications, customers can end-to-end verify the data they read and write to Blob Storage is fully intact byte-for-byte from their application to Azure physical storage media using CRC64-NVME checksums – without the need to deploy and manage additional tools.&lt;/P&gt;
&lt;H2&gt;Azure’s Commitment to Data Integrity&lt;/H2&gt;
&lt;P&gt;Azure Blob Storage considers the durability and integrity of the data stored by customers as a fundamental promise of a cloud object storage provider. The Blob Storage platform was designed to prevent, detect, and repair any data integrity issues, along with making data durable and available at &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/storage/common/storage-redundancy" target="_blank" rel="noopener"&gt;up to sixteen 9s with GRS&lt;/A&gt;. From the beginning, Blob Storage has stored checksums alongside every data fragment and continuously verifies them with background jobs, ensuring the bytes we durably store remain exactly the bytes we received —for every data replica (LRS/ZRS/GRS/GZRS).&lt;/P&gt;
&lt;H2&gt;Extending integrity to your client applications&lt;/H2&gt;
&lt;P&gt;Today, Azure Blob Storage is extending that protection into your client applications for end-to-end integrity. When enabled by customers, with CRC64-NVME transactional verification built into the latest Blob SDKs, every byte uploaded or downloaded has a CRC64-NVME checksum generated and that checksum is validated end-to-end. This protects against silent corruption that can occur within client-side code, on faulty client hardware, or in proxies and other services that sit between your application and Blob Storage. With CRC64-NVME validation enabled, the SDK computes and sends a checksum over the data and the service independently verifies it before acknowledging the write; the same happens in reverse on read. For multi-part reads/writes, individual checksums are reconciled against a whole-object checksum to catch any corruption within the client library itself. Every byte is now integrity-checked from the moment it enters the SDK, through the Blob Storage service and your storage account, and back again.&lt;/P&gt;
&lt;H2&gt;Benefits of CRC64-NVME&lt;/H2&gt;
&lt;P&gt;Microsoft has always considered 64 bit-checksums a requirement at cloud scale, with the CRC64-NVME polynomial protecting exabytes of customer data in Blob Storage from accidental data corruption. Microsoft has invested and shared high-performance implementations of our CRC64-NVME implementation that other cloud providers and industry participants have adopted as the default for data integrity use cases.&lt;/P&gt;
&lt;P&gt;The Cyclic Redundancy Check (CRC) algorithm was originally designed for detecting bit corruption in data transit over network protocols like Ethernet, so it has relatively minimal CPU usage. The CRC64-NVME polynomial variant used for Blob Storage data integrity takes advantage of hardware acceleration present in modern x86 and ARM CPUs to further reduce CPU usage. Further performance gains are achieved by composing CRC checksums - meaning if you have the CRC of two chunks of data, you can combine them to get the CRC of the whole data, without needing to re-read the data. CRC64-NVME also provides strong reliability: a collision probability of a random bit error is 1 in 2^64, or 1 in 18 quintillion.&lt;/P&gt;
&lt;H2&gt;Performance&lt;/H2&gt;
&lt;P&gt;Performance is paramount in Azure Blob and great care was taken to implement the CRC64-NVME end to end integrity performantly. The &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/storage/common/storage-srp-overview" target="_blank" rel="noopener"&gt;latest version of the Blob SDK&lt;/A&gt; implements data integrity through the &lt;A class="lia-external-url" href="https://learn.microsoft.com/rest/api/storageservices/structured-body-format" target="_blank" rel="noopener"&gt;Structured Message Body&lt;/A&gt; REST API, which boosts our efficiency. Structured message bodies effectively allow the Blob client libraries to process the data, compute the CRC64-NVME checksum, and compose/unpack the HTTP request all in one flow, rather than processing the same data two or three times.&lt;/P&gt;
&lt;P&gt;There are no restrictions on the size of your data for end-to-end data integrity to work. The latest version of the Blob SDKs using the structured message body implementation can handle any size of data to perform the end-to-end Data Integrity, unlike our previous MD5 version.&lt;/P&gt;
&lt;P&gt;Throughput and CPU utilization can vary between using CRC64-NVME, MD5, and no validation. Customers can weigh the benefits of end-to-end integrity with the performance implications that might be right for their application.&lt;/P&gt;
&lt;H2&gt;Usage&lt;/H2&gt;
&lt;P&gt;Requires upgrading to the &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/storage/common/storage-srp-overview" target="_blank" rel="noopener"&gt;latest SDK versions&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Upload data to Blob with end-to-end data integrity (.NET):&lt;/P&gt;
&lt;LI-CODE lang="csharp"&gt;BlobUploadOptions options = new BlobUploadOptions
{
    TransferValidation = new UploadTransferValidationOptions
    {
        ChecksumAlgorithm = StorageChecksumAlgorithm.StorageCrc64
    }
};
Response&amp;lt;BlobContentInfo&amp;gt; response = blobClient.Upload(upStream, options);&lt;/LI-CODE&gt;
&lt;P&gt;Download data to Blob with end-to-end data integrity (.NET):&lt;/P&gt;
&lt;LI-CODE lang="csharp"&gt;BlobDownloadToOptions options = new BlobDownloadToOptions
{
    TransferValidation = new DownloadTransferValidationOptions
    {
        ChecksumAlgorithm = StorageChecksumAlgorithm.StorageCrc64
    }
};
Response response = blobClient.DownloadTo(downStream, options);&lt;/LI-CODE&gt;
&lt;P&gt;Upload and Download on all client operations to Blob with end-to-end data integrity (.NET):&lt;/P&gt;
&lt;LI-CODE lang="csharp"&gt;BlobClientOptions options = new BlobClientOptions
{
    TransferValidation =
    {
        Upload   = { ChecksumAlgorithm = StorageChecksumAlgorithm.StorageCrc64 },
        Download = { ChecksumAlgorithm = StorageChecksumAlgorithm.StorageCrc64 }
    },
};
BlobServiceClient blobServiceClient = new BlobServiceClient(serviceUri, new DefaultAzureCredential(), options);&lt;/LI-CODE&gt;
&lt;H2&gt;Availability&lt;/H2&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 30%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Compact" data-ccp-parastyle-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;eafb41c0-47a4-52dc-ac6b-3b5a7536b560|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[335559740,&amp;quot;240&amp;quot;,201341983,&amp;quot;0&amp;quot;,335559739,&amp;quot;36&amp;quot;,201342446,&amp;quot;1&amp;quot;,201342447,&amp;quot;5&amp;quot;,201342448,&amp;quot;1&amp;quot;,201342449,&amp;quot;1&amp;quot;,469777841,&amp;quot;Aptos&amp;quot;,469777842,&amp;quot;Arial&amp;quot;,469777843,&amp;quot;Aptos&amp;quot;,469777844,&amp;quot;Aptos&amp;quot;,201341986,&amp;quot;1&amp;quot;,469769226,&amp;quot;Aptos,Arial&amp;quot;,268442635,&amp;quot;24&amp;quot;,335559738,&amp;quot;36&amp;quot;,469775450,&amp;quot;Compact&amp;quot;,201340122,&amp;quot;2&amp;quot;,134234082,&amp;quot;true&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;Compact&amp;quot;,335572020,&amp;quot;1&amp;quot;,469778324,&amp;quot;Body Text&amp;quot;]}"&gt;SDK&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Compact"&gt;Minimum&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Compact"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Compact"&gt;V&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Compact"&gt;ersion&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/dotnet/api/overview/azure/storage" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;.NET&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Compact"&gt;12.28.0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/java/api/overview/azure/storage" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Java&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Compact"&gt;Coming soon&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/python/api/overview/azure/storage" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Python&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Compact"&gt;Coming soon&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/javascript/api/overview/azure/storage" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;JavaScript&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Compact"&gt;12.32.0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;A href="https://pkg.go.dev/github.com/Azure/azure-sdk-for-go/sdk/storage/azblob" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Go&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Compact"&gt;Coming soon&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/cpp/api/overview/azure/storage" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;C++&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Compact"&gt;12.17.0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:36,&amp;quot;335559739&amp;quot;:36,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;Comparison to MD5&lt;/H2&gt;
&lt;P&gt;MD5 is a cryptographic hashing algorithm that has historically been used for verifying integrity of data. Content-MD5 was one of the original HTTP headers for this purpose. While Blob Storage has supported HTTP headers for integrity including MD5, it’s less preferred than CRC64-NVME for data integrity due to its lower reliability in detection, high collision rate, inability for hardware acceleration, and higher computational cost. Recently, MD5 has even been disallowed by many security frameworks (e.g. FIPS) due to its lack of cryptographic security.&lt;/P&gt;
&lt;P&gt;With MD5, Blob Storage has only been able to verify the data integrity of each partitioned HTTP request/response with MD5, not the entire blob. Additionally, for reading blobs with MD5 validation there is a 4MiB size limit on the data in HTTP responses, which can significantly increase the number of HTTP requests required to read data. In both reading and writing blobs, the SDKs require buffering or re-reading the data to compute MD5 in addition to assembling the HTTP request and unpacking the HTTP response.&lt;/P&gt;
&lt;P&gt;With the latest implementation of CRC64-NVME, Azure Blob client libraries can verify data integrity on both the entire data and each HTTP request/response, can do so with any size of partitions on reading or writing data, and does so in only one pass over the data.&lt;/P&gt;
&lt;P&gt;To migrate from MD5 to CRC64-NVME, simply change your ChecksumAlgorithm:&lt;/P&gt;
&lt;LI-CODE lang="diff"&gt;-ChecksumAlgorithm = StorageChecksumAlgorithm.MD5
+ChecksumAlgorithm = StorageChecksumAlgorithm.StorageCrc64&lt;/LI-CODE&gt;
&lt;H2&gt;Next Steps&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To begin using end-to-end Data Integrity with CRC64-NVME, upgrade to the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/storage/common/storage-srp-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;latest &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;SDK version&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; of your preferred language and check out our developer guides and examples:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/azure/storage/blobs/storage-blob-upload" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;.NET&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://learn.microsoft.com/cpp/api/overview/azure/storage-blobs-readme" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;C++&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://learn.microsoft.com/azure/storage/blobs/storage-blob-upload-javascript" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;JavaScript&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://learn.microsoft.com/azure/storage/common/storage-srp-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Storage Client Libraries&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 29 Jun 2026 19:03:37 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/announcing-general-availability-of-client-side-data-integrity/ba-p/4531364</guid>
      <dc:creator>wmarkley</dc:creator>
      <dc:date>2026-06-29T19:03:37Z</dc:date>
    </item>
    <item>
      <title>Boost performance with NFS nconnect on Azure NetApp Files datastores for Azure VMware Solution</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/boost-performance-with-nfs-nconnect-on-azure-netapp-files/ba-p/4528858</link>
      <description>&lt;H1&gt;Table of contents&lt;/H1&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232606105" target="_self" rel="noopener"&gt;Introduction&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232606106" target="_self" rel="noopener"&gt;What is nconnect&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232606107" target="_self" rel="noopener"&gt;Why it matters&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232606108" target="_self" rel="noopener"&gt;How it works&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232606109" target="_self" rel="noopener"&gt;Reading the numbers: what the Azure VMware Solution datastore data shows&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232606110" target="_self" rel="noopener"&gt;What this unlocks for Azure VMware Solution with Azure NetApp Files&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232606111" target="_self" rel="noopener"&gt;Use cases&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232606112" target="_self" rel="noopener"&gt;Conclusion&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232606113" target="_self" rel="noopener"&gt;Next steps&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232606114" target="_self" rel="noopener"&gt;Learn more&lt;/A&gt;&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232606105"&gt;&lt;/A&gt;Introduction&lt;/H1&gt;
&lt;P&gt;For the most demanding workloads, storage is rarely the limiting factor on Azure NetApp Files. More often, it is the path to storage. NFS has long used a single TCP connection per datastore per host, and while that one stream is dependable, it quietly caps how much I/O a host can drive to a datastore. The usual workaround was to spread the workload across more datastores, or more hosts, so additional connections could share the load. It worked but it meant running and managing more datastores than the workload itself ever needed.&lt;/P&gt;
&lt;P&gt;The nconnect mount option removes that cap by letting a single NFS mount use multiple TCP connections. VMware introduced it in vSphere 8.0 Update 2, and on‑premises NetApp customers adopted it quickly to get more out of their high-speed networks and storage. Now that same option is supported on Azure VMware Solution with Azure NetApp Files. For details on the nconnect mount option, see the &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/performance-linux-mount-options" target="_blank" rel="noopener"&gt;Azure NetApp Files Linux NFS mount options documentation.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This matters because it changes what you can expect from a single datastore with higher throughput, lower latency under concurrency, and a simpler design all without leaving the managed Azure VMware Solution platform.&lt;/P&gt;
&lt;P&gt;Co-authors&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/richard-crofford-05135b8/" target="_blank" rel="noopener"&gt;Rich Crofford&lt;/A&gt;, Azure NetApp Files Product Manager&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/pravinkumarjeyakumar/" target="_blank" rel="noopener"&gt;Pravinkumar Jeya Kumar&lt;/A&gt;, Senior Program Manager Azure Dedicated&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232606106"&gt;&lt;/A&gt;What is nconnect&lt;/H1&gt;
&lt;P&gt;The &lt;A class="lia-external-url" href="https://www.man7.org/linux/man-pages/man5/nfs.5.html" target="_blank" rel="noopener"&gt;nconnect&lt;/A&gt; option is a client-side NFS capability that allows a single NFS mount to use multiple TCP connections. Instead of sending all Azure VMware Solution datastore traffic through one stream, the client distributes it across several parallel connections driving more traffic at a lower overall latency.&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 1. With nconnect=4, each ESXi host opens four parallel TCP connections to a single Azure NetApp Files datastore.&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;ESXi introduced multiple TCP connections for a single NFSv3 datastore in vSphere 8.0 Update 2, where the capability became generally available. The number of connections is configurable per datastore and adjustable at runtime, and the default stays at a single connection, so turning it on is a deliberate choice the administrator makes.&lt;/P&gt;
&lt;P&gt;On Azure VMware Solution, a setting of nconnect=4 is now supported with Azure NetApp Files. You can mount an Azure NetApp Files datastore with four parallel connections per host, bringing the same parallelism and performance that is proven on premises into the fully managed Azure VMware Solution. . The nconnect=4 capability is supported on both Azure VMware Solution Gen 1 and Gen 2 private clouds, so you get the same capability regardless of which generation you run.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232606107"&gt;&lt;/A&gt;Why it matters&lt;/H1&gt;
&lt;P&gt;The payoff shows up in the two dimensions workloads care about most.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Throughput. &lt;/STRONG&gt;Four connections carry more data in parallel than one. By spreading I/O across multiple TCP streams, a single datastore connection attains more bandwidth from the same host and makes fuller use of the available network, and thus storage throughput. On the Azure NetApp Files side, those connections are serviced in parallel by the storage service, so the extra client streams translate into real aggregate throughput instead of queuing a single connection.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Latency under concurrency. &lt;/STRONG&gt;This is the part that is easy to overlook. When an NFS mount is established, the storage service tracks a connection that supports a defined number of concurrent, in‑flight operations. When a busy workload exceeds that number on a single connection, the service applies flow control until operations complete and resources free up. Each pause is brief often only for microseconds but across millions of operations those pauses add up and surface as higher overall latency. Adding connections multiplies the number of operations that can be in flight at once, which reduces queuing and keeps response times consistent when the workload gets heavy. This is not just a theory. &lt;A href="https://learn.microsoft.com/azure/azure-netapp-files/performance-benchmarks-linux" target="_blank" rel="noopener"&gt;Azure NetApp Files testing with Linux NFS clients&lt;/A&gt; shows that adding parallel connections measurably lowers latency under concurrent load. The nconnect option brings that same mechanism to each Azure VMware Solution host.&lt;/P&gt;
&lt;P&gt;For applications that generate sustained I/O, more throughput with higher concurrency and lower latency is exactly what is needed to run predictably.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232606108"&gt;&lt;/A&gt;How it works&lt;/H1&gt;
&lt;P&gt;With nconnect=4, each Azure VMware Solution ESXi host mounts an Azure NetApp Files datastore over four parallel TCP connections. Storage traffic is processed concurrently across those connections, raising aggregate throughput and supporting a higher level of I/O concurrency than a single connection model ever could.&lt;/P&gt;
&lt;P&gt;Adoption is straightforward and non‑disruptive, for both new and existing datastores. New Azure NetApp Files datastores can be created with nconnect enabled from day one, and the option can also be applied to datastores you already run. Either way, no changes are required to your virtual machines or applications, they simply benefit from the added I/O parallelism. A single datastore can then support performance that previously took several, simplifying the environment while preserving the scalability demanding workloads rely on. Because nconnect is configured per datastore, each datastore’s connection count can be set independently to match its workload.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;⚠️&lt;STRONG&gt;&amp;nbsp;Important&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Four connections per datastore is a deliberate balance. It delivers a meaningful jump in parallelism while keeping the storage design clean and easy to operate. Azure VMware Solution supports up to 256 NFS connections per host, so with nconnect=4, each host can access up to 64 datastores per SDDC. Keep the connection count consistent across all hosts in a cluster so that performance and operations such as vMotion behave predictably.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232606109"&gt;&lt;/A&gt;Reading the numbers: what the Azure VMware Solution datastore data shows&lt;/H1&gt;
&lt;P&gt;Azure VMware Solution specific nconnect benchmarks are still being run, but we do not have to wait to understand the impact. The most useful context already exists in two places; the &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/performance-benchmarks-azure-vmware-solution" target="_blank" rel="noopener"&gt;published Azure NetApp Files datastore guidance for Azure VMware Solution&lt;/A&gt;, and years of Azure NetApp Files nconnect experience &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/performance-benchmarks-linux" target="_blank" rel="noopener"&gt;on Azure virtual machines&lt;/A&gt;. The single‑host scaling data comparing one datastore to multiple datastores is especially telling, because it shows exactly what happens when a host can spread load across more network flows.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What the published Azure VMware Solution data already tells us. &lt;/STRONG&gt;With a single datastore, each Azure VMware Solution host connects over a fixed number of network flows, which became a bottleneck for the most demanding workloads. Moving from one datastore to two, and then to four, scaled out performance by giving the host more parallel network flows, as the figure below shows. That gain came purely from adding datastore level connections not from any change inside the guest virtual machines.&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 2. Scaling from 1 to 16 datastores on a single host lifts 8K IOPS from roughly 156,000 to 389,000 driven entirely by more parallel datastore connections.&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;&lt;STRONG&gt;Why that matters for nconnect. &lt;/STRONG&gt;In those published single host results, moving from one datastore to four improved throughput because the host had more parallel datastore connections available. nconnect=4 changes the equation it lets a single datastore mount use four parallel TCP connections from each ESXi host. In other words, the same performance principle that previously favored multiple datastores can now be applied within a single datastore mount. That is why nconnect=4 is so significant for Azure VMware Solution with Azure NetApp Files as it helps one datastore deliver much more of the performance that used to require several.&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 3. Averaged across read/write mixes, scaling datastores delivers up to 397% (8KB random) and 279% (64KB sequential) relative to a single datastore the same scaling nconnect=4 brings within one datastore.&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;Read together, the data makes the point plainly more parallel datastore connections increase performance, and nconnect=4 brings that same scaling model to a single Azure NetApp Files datastore. These figures illustrate the scaling pattern your real‑world results will vary with the specific workload running against the datastore.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232606110"&gt;&lt;/A&gt;What this unlocks for Azure VMware Solution with Azure NetApp Files&lt;/H1&gt;
&lt;P&gt;Azure NetApp Files has always been the storage service of choice for the most demanding enterprise workloads databases, and high‑performance computing with no application changes required. For some of those workloads on Azure VMware Solution, the limiting factor was never the storage itself. It was the single‑connection ceiling between the host and the datastore, and nconnect=4 removes that ceiling.&lt;/P&gt;
&lt;P&gt;Customers already running Azure VMware Solution with Azure NetApp Files can easily make use of this new feature. Because nconnect is configured per datastore, you can apply it to the datastores that are already connected and see the benefit immediately with no migration and configuration changes to your virtual machines.&lt;/P&gt;
&lt;P&gt;Two common situations where I/O previously funneled through a single TCP flow will benefit right away: maximizing throughput for single VM with VMDKs maps to one datastore and increasing throughput for many VMs on a single datastore. In both cases, nconnect=4 relieves the bottleneck and lets the existing datastore absorb far more load which also spares you from spinning up extra datastores just to chase performance.&lt;/P&gt;
&lt;P&gt;That is what makes Azure VMware Solution and Azure NetApp Files so compelling together. You get the enterprise grade performance of Azure NetApp Files, the familiar VMware operating model of Azure VMware Solution, and now the parallel connection scaling that high-performance workloads depend on all on a managed cloud platform.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;It is worth saying plainly: with Azure VMware Solution and Azure NetApp Files, you do not need dedicated infrastructure to get bare‑metal performance. &lt;/STRONG&gt;That applies to virtualized Oracle and SQL Server, to large analytics estates, and to any storage heavy application that once justified a dedicated platform. The performance is right there in the Azure VMware Solution and Azure NetApp Files platform you already run.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232606111"&gt;&lt;/A&gt;Use cases&lt;/H1&gt;
&lt;P&gt;The nconnect=4 option is especially valuable for Azure VMware Solution workloads that need more throughput, steadier latency under concurrency, or a simpler storage design. These use cases show where parallel TCP connections to a single Azure NetApp Files datastore make the biggest difference.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Use case&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;How nconnect helps&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Databases on Azure VMware Solution plus Azure NetApp Files&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Databases live and die on throughput and latency, and they generate exactly the kind of sustained, concurrent I/O that benefits most from parallel connections. With nconnect=4, Oracle, SQL Server, and similar engines run consistently on a single high‑performing datastore without sharding data files across many datastores to chase performance.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Storage-heavy and high-performance workloads&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Analytics platforms, file‑intensive applications, and large virtual desktop estates all gain from higher aggregate IOPS and steadier latency per datastore. Backup and bulk‑data windows, where I/O spikes hard for a defined period, are a natural fit for the extra parallelism.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Datacenter exits and migrations&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Teams retiring physical datacenters want to move VMware estates to the cloud with minimal redesign. Azure VMware Solution lets you bring workloads over as they are, and Azure NetApp Files with nconnect=4 supplies the storage performance that once justified keeping high‑demand workloads on dedicated infrastructure. You retire the hardware and still clear the performance bar.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;Across all of these, Azure VMware Solution backed by Azure NetApp Files delivers the performance that once required specialized or dedicated platforms while keeping the storage design simpler.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232606112"&gt;&lt;/A&gt;Conclusion&lt;/H1&gt;
&lt;P&gt;The nconnect option lets each Azure VMware Solution ESXi host open four parallel TCP connections to each Azure NetApp Files datastore, increasing throughput and lowering effective latency under load without adding datastores or hosts. The capability has been proven in VMware for some time, and the performance case is already backed by existing benchmark data, including Azure NetApp Files nconnect scaling on Azure virtual machines and the published one datastore versus four datastore scaling results for Azure VMware Solution.&lt;/P&gt;
&lt;P&gt;For the workloads Azure NetApp Files is known to serve well; this was the missing piece. Databases, analytics, and other storage heavy applications now have the parallel connection scaling they need on a managed VMware platform. With Azure VMware Solution and Azure NetApp Files, you do not need specialized infrastructure to get bare‑metal performance; the performance is already there, and now it scales.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232606113"&gt;&lt;/A&gt;Next steps&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Review your datastore design. &lt;/STRONG&gt;Identify the workloads most likely to benefit from more parallelism, especially databases, analytics platforms, and other storage‑intensive applications that currently span multiple datastores mainly for performance.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Validate platform prerequisites. &lt;/STRONG&gt;Confirm that your Azure VMware Solution environment and Azure NetApp Files datastore deployment follows the documented connectivity and performance best practices for attached datastores, including the guidance for your generation of private cloud.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Test nconnect on the right datastores first. &lt;/STRONG&gt;Start with the datastores that show the clearest signs of throughput pressure or latency under concurrency, then compare performance and operational simplicity before expanding more broadly.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Standardize across the cluster. &lt;/STRONG&gt;Apply a consistent configuration across hosts for any datastore that uses nconnect, so performance characteristics and mobility operations stay predictable.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Use the published guidance to plan rollout. &lt;/STRONG&gt;Review the Azure VMware Solution attach guidance, performance considerations, and benchmark documentation to decide where nconnect can help you reduce datastore sprawl while preserving the performance your workloads require.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For Azure VMware Solution customers using Azure NetApp Files, nconnect is a practical way to simplify storage design while improving throughput and latency for demanding workloads. It helps you get more from the datastores you already use, with less need to spread workloads across additional datastores just to add parallelism.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232606114"&gt;&lt;/A&gt;Learn more&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/whats-new" target="_blank" rel="noopener"&gt;What’s new in Azure NetApp Files&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/performance-benchmarks-azure-vmware-solution" target="_blank" rel="noopener"&gt;Azure NetApp Files datastore performance benchmarks for Azure VMware Solution&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/performance-azure-vmware-solution-datastore" target="_blank" rel="noopener"&gt;Azure VMware Solution datastore performance considerations for Azure NetApp Files&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-vmware/attach-azure-netapp-files-to-azure-vmware-solution-hosts" target="_blank" rel="noopener"&gt;Attach Azure NetApp Files datastores to Azure VMware Solution hosts&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="http://learn.microsoft.com/azure/azure-netapp-files/performance-linux-mount-options#nconnect" target="_blank" rel="noopener"&gt;Azure NetApp Files Linux NFS mount options&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.man7.org/linux/man-pages/man5/nfs.5.html" target="_blank" rel="noopener"&gt;NFS mount Linux manual&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 24 Jun 2026 07:16:04 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/boost-performance-with-nfs-nconnect-on-azure-netapp-files/ba-p/4528858</guid>
      <dc:creator>GeertVanTeylingen</dc:creator>
      <dc:date>2026-06-24T07:16:04Z</dc:date>
    </item>
    <item>
      <title>Bringing Enterprise File Data to Users with Azure NetApp Files, Microsoft Foundry, and M365 Copilot</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/bringing-enterprise-file-data-to-users-with-azure-netapp-files/ba-p/4528002</link>
      <description>&lt;H1&gt;Table of Contents&lt;/H1&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232254867" target="_self" rel="noopener"&gt;Introduction&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232254868" target="_self" rel="noopener"&gt;Why the user experience layer matters in enterprise AI&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232254869" target="_self" rel="noopener"&gt;Microsoft Foundry: Orchestrating enterprise AI agents&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232254870" target="_self" rel="noopener"&gt;The Copilot agent as the enterprise user experience&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232254871" target="_self" rel="noopener"&gt;End‑to‑end user query flow&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232254872" target="_self" rel="noopener"&gt;Why this pattern works for regulated and complex environments&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232254873" target="_self" rel="noopener"&gt;Extending Copilot beyond SharePoint‑centric scenarios&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232254874" target="_self" rel="noopener"&gt;From storage to knowledge to action&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232254875" target="_self" rel="noopener"&gt;Key takeaway&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232254876" target="_self" rel="noopener"&gt;Put the architecture into practice&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232254877" target="_self" rel="noopener"&gt;Learn more&lt;/A&gt;&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232254867"&gt;&lt;/A&gt;Introduction&lt;/H1&gt;
&lt;P&gt;In &lt;STRONG&gt;Part 1, &lt;/STRONG&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurestorageblog/from-enterprise-file-storage-to-an-ai-ready-data-foundation-using-azure-netapp-f/4527999" target="_blank" rel="noopener" data-lia-auto-title="From Enterprise File Storage to an AI-Ready Data Foundation using Azure NetApp Files and OneLake" data-lia-auto-title-active="0"&gt;From Enterprise File Storage to an AI-Ready Data Foundation using Azure NetApp Files and OneLake&lt;/A&gt;, we established a zero‑copy data foundation that makes enterprise file data AI‑addressable using Azure NetApp Files and Microsoft OneLake, without migration, duplication, or workflow disruption.&lt;/P&gt;
&lt;P&gt;In &lt;STRONG&gt;Part 2, &lt;/STRONG&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurestorageblog/from-file-data-to-ai%E2%80%91powered-knowledge-pipelines-using-azure-netapp-files-object/4528001" target="_blank" rel="noopener" data-lia-auto-title="From File Data to AI‑Powered Knowledge Pipelines using Azure NetApp Files object REST API" data-lia-auto-title-active="0"&gt;From File Data to AI‑Powered Knowledge Pipelines using Azure NetApp Files object REST API&lt;/A&gt;, we showed how that foundation is activated through a knowledge pipeline using Azure AI Search and Azure OpenAI, transforming unstructured files into a living, queryable knowledge system grounded in Retrieval‑Augmented Generation (RAG).&lt;/P&gt;
&lt;P&gt;In this final part, &lt;STRONG&gt;we focus on the user experience&lt;/STRONG&gt;: how this architecture is safely and effectively surfaced to end users through enterprise AI agents, including Copilot, where employees already work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;Co-authors:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/gotthomas/" target="_blank" rel="noopener"&gt;Thomas Willingham&lt;/A&gt;, Azure NetApp Files Product Manager&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/seanluce/" target="_blank" rel="noopener"&gt;Sean Luce&lt;/A&gt;, Azure NetApp Files Product Manager&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232254868"&gt;&lt;/A&gt;Why the user experience layer matters in enterprise AI&lt;/H1&gt;
&lt;P&gt;Enterprise AI adoption rarely fails because models are insufficient. It fails when users are asked to change how they work, learn new tools, or trust opaque answers.&lt;/P&gt;
&lt;P&gt;For knowledge‑centric scenarios, success depends on three things:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Users interact with AI &lt;STRONG&gt;inside their existing workflows&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Answers are &lt;STRONG&gt;grounded in authorized enterprise data&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Responses are &lt;STRONG&gt;traceable, and auditable&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Microsoft 365 Copilot provides the ideal natural language experience for this layer. However, Copilot itself does not “understand files.” It relies on external knowledge sources and well‑defined grounding mechanisms to retrieve and synthesize information safely.&lt;/P&gt;
&lt;P&gt;This is where the Copilot Agent completes the architecture, &lt;EM&gt;with Microsoft Foundry providing the orchestration layer behind it.&lt;/EM&gt;&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232254869"&gt;&lt;/A&gt;Microsoft Foundry: Orchestrating enterprise AI agents&lt;/H1&gt;
&lt;P&gt;Before enterprise knowledge is exposed to end users through enterprise AI agents such as Copilot, it must first be assembled, grounded, and governed as an AI capability. This is the role of Microsoft Foundry.&lt;/P&gt;
&lt;P&gt;Microsoft Foundry is the control plane for building and governing enterprise AI agents. It provides the environment where enterprise AI agents are created and connected to authoritative knowledge sources. It orchestrates how Azure AI Search, Azure OpenAI models, and enterprise data sources, including Azure NetApp Files surfaced through OneLake, work together to deliver an accurate, grounded response.&lt;/P&gt;
&lt;P&gt;Rather than embedding intelligence directly inside Copilot, Foundry acts as the control plane for enterprise AI. It defines:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Which knowledge sources an agent can access,&lt;/LI&gt;
&lt;LI&gt;How retrieval and grounding are enforced,&lt;/LI&gt;
&lt;LI&gt;How models are constrained to retrieved enterprise content, ensuring responses remain grounded, explainable, and auditable.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This separation ensures that Copilot remains the user experience, while Foundry governs how enterprise AI agents reason over data, securely and predictably.&lt;/P&gt;
&lt;P&gt;Together, this user experience layer enables secure, seamless access to enterprise data for AI, unlocking real business value through governed, traceable Copilot experiences.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232254870"&gt;&lt;/A&gt;The Copilot agent as the enterprise user experience&lt;/H1&gt;
&lt;P&gt;The Copilot agent is built and governed within Microsoft Foundry, but users interact with it through Copilot.&lt;/P&gt;
&lt;P&gt;At a high level, the agent performs three critical functions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Receives natural language questions from users inside M365 experiences such as Teams or Copilot Chat,&lt;/LI&gt;
&lt;LI&gt;Queries the Azure AI Search index built over enterprise file data referenced through OneLake,&lt;/LI&gt;
&lt;LI&gt;Generates grounded responses using Azure OpenAI, restricted to retrieved content and enriched with source citations.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;This separation of responsibilities is deliberate. Copilot does not read file storage directly, nor does it reason over raw documents. Instead, it queries a curated, indexed knowledge source designed specifically for enterprise RAG scenarios.&lt;/P&gt;
&lt;P&gt;The result is a user experience that feels conversational but behaves predictably.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232254871"&gt;&lt;/A&gt;End‑to‑end user query flow&lt;/H1&gt;
&lt;P&gt;When a user asks a question in Copilot – such as:&lt;/P&gt;
&lt;P&gt;“What is our incident escalation procedure for data breaches?”&lt;/P&gt;
&lt;P&gt;The interaction follows a controlled, enterprise‑safe flow:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;User submits a question&lt;/STRONG&gt; in Copilot,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The Copilot Agent forwards the query&lt;/STRONG&gt; to Azure AI Search,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Relevant document chunks&lt;/STRONG&gt; are retrieved using semantic vector search,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure OpenAI synthesizes a response&lt;/STRONG&gt; using only the retrieved content,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Source filenames are included&lt;/STRONG&gt; in the response for transparency.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;At no point does the model infer information from outside the enterprise dataset or hallucinate answers based on its general training.&lt;/P&gt;
&lt;P&gt;This is not a chatbot layered on top of file storage. It is a governed retrieval and reasoning pipeline surfaced through a familiar, conversational experience.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232254872"&gt;&lt;/A&gt;Why this pattern works for regulated and complex environments&lt;/H1&gt;
&lt;P&gt;This user experience model is especially powerful for industries where trust, traceability, and compliance are non‑negotiable.&lt;/P&gt;
&lt;P&gt;Because answers are always grounded in specific source files:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Legal teams can verify interpretations against contract language,&lt;/LI&gt;
&lt;LI&gt;Security teams can audit responses back to official runbooks,&lt;/LI&gt;
&lt;LI&gt;Compliance teams can validate that policies, not assumptions, are being cited.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Just as importantly, data never leaves its system of record:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Files remain governed and secured in Azure NetApp Files,&lt;/LI&gt;
&lt;LI&gt;Access controls continue to be enforced at the storage layer,&lt;/LI&gt;
&lt;LI&gt;OneLake provides virtualization, not duplication,&lt;/LI&gt;
&lt;LI&gt;AI services operate on indexed representations, not copied datasets.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This preserves existing governance models while extending their reach into AI‑driven experiences.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232254873"&gt;&lt;/A&gt;Extending Copilot beyond SharePoint‑centric scenarios&lt;/H1&gt;
&lt;P&gt;Most Copilot examples focus on collaboration content stored in SharePoint or OneDrive. These are valid and important scenarios.&lt;/P&gt;
&lt;P&gt;However, enterprise knowledge does not live exclusively in collaborative repositories.&lt;/P&gt;
&lt;P&gt;Large organizations depend on:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Network file systems containing decades of operational knowledge,&lt;/LI&gt;
&lt;LI&gt;Hybrid environments where SMB and NFS are the primary interfaces,&lt;/LI&gt;
&lt;LI&gt;High‑performance storage platforms that cannot be re‑platformed.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;By combining Azure NetApp Files, OneLake, a RAG‑based knowledge pipeline, and Copilot, this architecture extends Copilot’s reach to the realities of the enterprise data estate, without forcing that estate to change.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232254874"&gt;&lt;/A&gt;From storage to knowledge to action&lt;/H1&gt;
&lt;P&gt;Taken together, the three layers form a cohesive architecture:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Part 1: Data Foundation&lt;/STRONG&gt;&lt;BR /&gt;Azure NetApp Files + OneLake make enterprise file data AI‑addressable without migration or duplication.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Part 2: Knowledge Pipeline&lt;/STRONG&gt;&lt;BR /&gt;Azure AI Search + Azure OpenAI transform files into a living knowledge system using RAG.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Part 3: AI Orchestration &amp;amp; User Experience&lt;/STRONG&gt;&lt;BR /&gt;Microsoft Foundry orchestrates enterprise AI agents, and Copilot provides a natural, trusted way for users to ask questions and receive grounded answers.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is not a single-use solution. It is a repeatable architecture pattern for enabling secure, seamless access to enterprise data for AI, unlocking real business value safely, predictably, and at scale.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232254875"&gt;&lt;/A&gt;Key takeaway&lt;/H1&gt;
&lt;P&gt;The real promise of enterprise AI is not replacing systems of record but making them intelligible.&lt;/P&gt;
&lt;P&gt;With this architecture, Azure NetApp Files becomes more than high performance storage.&lt;/P&gt;
&lt;P&gt;It becomes the foundation of an AI‑ready data estate, delivering grounded insights inside Copilot, without compromising performance, security, or trust.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Together, these three parts form a complete architecture for extending AI to enterprise file data – bridging the gap between systems of record and AI-powered user experiences.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232254876"&gt;&lt;/A&gt;Put the architecture into practice&lt;/H1&gt;
&lt;P&gt;This three‑part series outlines a repeatable pattern for bringing AI to enterprise file data; without migration, duplication, workflow disruption, or governance compromise.&lt;/P&gt;
&lt;P&gt;To go deeper:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Review the reference architecture described in this series and map it to your environment,&lt;/LI&gt;
&lt;LI&gt;Identify candidate file‑based knowledge scenarios (security, compliance, operations),&lt;/LI&gt;
&lt;LI&gt;Engage your data, storage, and AI teams, with us at &lt;A class="lia-external-url" href="mailto:askANF@microsoft.com" target="_blank" rel="noopener"&gt;askANF@microsoft.com&lt;/A&gt; to apply this pattern using Azure NetApp Files, Microsoft OneLake, and Copilot.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Enterprise AI succeeds when systems of record become systems of intelligence.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232254877"&gt;&lt;/A&gt;Learn more&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurestorageblog/from-enterprise-file-storage-to-an-ai-ready-data-foundation-using-azure-netapp-f/4527999" target="_blank" rel="noopener" data-lia-auto-title="From Enterprise File Storage to an AI-Ready Data Foundation using Azure NetApp Files and OneLake" data-lia-auto-title-active="0"&gt;From Enterprise File Storage to an AI-Ready Data Foundation using Azure NetApp Files and OneLake&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurestorageblog/from-file-data-to-ai%E2%80%91powered-knowledge-pipelines-using-azure-netapp-files-object/4528001" target="_blank" rel="noopener" data-lia-auto-title="From File Data to AI‑Powered Knowledge Pipelines using Azure NetApp Files object REST API" data-lia-auto-title-active="0"&gt;From File Data to AI‑Powered Knowledge Pipelines using Azure NetApp Files object REST API&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/object-rest-api-access-configure" target="_blank" rel="noopener"&gt;Configure object REST API in Azure NetApp Files | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/fabric/onelake/onelake-overview" target="_blank" rel="noopener"&gt;OneLake, the OneDrive for data - Microsoft Fabric | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/foundry/" target="_blank" rel="noopener"&gt;Microsoft Foundry | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/microsoft-365/copilot/extensibility/" target="_blank" rel="noopener"&gt;Build a Copilot agent for Microsoft 365 | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 15 Jun 2026 07:37:24 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/bringing-enterprise-file-data-to-users-with-azure-netapp-files/ba-p/4528002</guid>
      <dc:creator>GeertVanTeylingen</dc:creator>
      <dc:date>2026-06-15T07:37:24Z</dc:date>
    </item>
    <item>
      <title>From Enterprise File Storage to an AI-Ready Data Foundation using Azure NetApp Files and OneLake</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/from-enterprise-file-storage-to-an-ai-ready-data-foundation/ba-p/4527999</link>
      <description>&lt;H1&gt;Table of Contents&lt;/H1&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232253433" target="_self" rel="noopener"&gt;Introduction&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232253434" target="_self" rel="noopener"&gt;Why the data foundation matters&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232253435" target="_self" rel="noopener"&gt;Expanding beyond collaboration-centric data&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232253436" target="_self" rel="noopener"&gt;The zero‑copy data foundation pattern&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232253437" target="_self" rel="noopener"&gt;Why OneLake changes the model&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232253438" target="_self" rel="noopener"&gt;What this enables&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232253439" target="_self" rel="noopener"&gt;Key takeaway&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc232253440" target="_self" rel="noopener"&gt;Learn more&lt;/A&gt;&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232253433"&gt;&lt;/A&gt;Introduction&lt;/H1&gt;
&lt;P&gt;Enterprise AI is advancing rapidly, but many organizations are discovering a common challenge: their most valuable data is not accessible to the systems they want to use.&lt;/P&gt;
&lt;P&gt;While collaboration platforms and modern data services are designed for AI integration, the majority of enterprise knowledge still resides in file systems, powering critical applications, operational workflows, and long-standing systems of record. These environments were built for performance, reliability, and scale, not for AI-driven discovery or reasoning.&lt;/P&gt;
&lt;P&gt;This creates a fundamental gap. Organizations have the data they need to power AI, but that data often remains outside the reach of modern AI platforms.&lt;/P&gt;
&lt;P&gt;In this blog series, we explore how to close that gap without rewriting workflows, migrating data, or disrupting existing systems.&lt;/P&gt;
&lt;P&gt;Co-authors:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/gotthomas/" target="_blank" rel="noopener"&gt;Thomas Willingham&lt;/A&gt;, Azure NetApp Files Product Manager&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/seanluce/" target="_blank" rel="noopener"&gt;Sean Luce&lt;/A&gt;, Azure NetApp Files Product Manager&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232253434"&gt;&lt;/A&gt;Why the data foundation matters&lt;/H1&gt;
&lt;P&gt;As organizations accelerate their adoption of AI, a familiar challenge keeps emerging: AI is only as effective as the data it can access. While models and tools continue to advance rapidly, many enterprises are constrained by data foundations that were never designed for AI workloads.&lt;/P&gt;
&lt;P&gt;The issue is not a lack of data. In fact, most organizations already store their most valuable institutional knowledge on enterprise file systems:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Engineering specifications and design documents&lt;/LI&gt;
&lt;LI&gt;Legal contracts and compliance records&lt;/LI&gt;
&lt;LI&gt;Policies and procedures&lt;/LI&gt;
&lt;LI&gt;Technical runbooks&lt;/LI&gt;
&lt;LI&gt;Historical reports and archives&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For many enterprises, this content lives on high‑performance file storage such as Azure NetApp Files, accessed through long‑standing SMB and NFS workflows. The data is fast, reliable, and trusted, yet largely invisible to AI.&lt;/P&gt;
&lt;P&gt;Files are rich in information, but they are fundamentally passive. Users must already know where to look, and AI systems cannot reason over data they cannot access. This disconnect between where enterprise content lives and where AI knowledge can operate is now one of the biggest blockers to scalable AI adoption.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232253435"&gt;&lt;/A&gt;Expanding beyond collaboration-centric data&lt;/H1&gt;
&lt;P&gt;Many AI scenarios today focus on collaboration-centric data that is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Cloud‑native&lt;/LI&gt;
&lt;LI&gt;Stored in SharePoint or OneDrive&lt;/LI&gt;
&lt;LI&gt;Well suited for small to medium‑sized repositories&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is an important and valuable class of data. But it represents only part of the enterprise reality. Enterprise AI requires extending beyond collaboration data to include systems of record, where the majority of institutional knowledge resides.&lt;/P&gt;
&lt;P&gt;Most large organizations also rely on:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Large NAS estates&lt;/STRONG&gt; measured in tens or hundreds of terabytes, and often millions of files&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Hybrid and on‑premises &lt;/STRONG&gt;environments&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Long‑standing SMB/NFS workflows&lt;/STRONG&gt; that cannot be easily re‑platformed or migrated&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These environments are not failures of SharePoint, they serve different needs. File systems remain the system of record for many regulated, performance‑sensitive, and document‑heavy workloads.&lt;/P&gt;
&lt;P&gt;The challenge has been extending AI, and data platforms, to this class of enterprise file data without forcing migration, duplication, or workflow change.&lt;/P&gt;
&lt;P&gt;This is the gap that Azure NetApp Files and Microsoft OneLake fill together.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232253436"&gt;&lt;/A&gt;The zero‑copy data foundation pattern&lt;/H1&gt;
&lt;P&gt;To unlock AI across enterprise file data, we need a different foundation, one that respects existing systems of record while making data accessible to modern AI services.&lt;/P&gt;
&lt;P&gt;This solution introduces a zero‑copy, zero‑migration data foundation built on three key components:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Component&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Role&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Azure NetApp Files&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;System of record for unstructured enterprise files (SMB/NFS)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Object REST API&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Provides object access (S3‑compatible) to file data&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft OneLake&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Unified data layer that exposes data without duplicating it&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;Files continue to be created, updated, and managed on Azure NetApp Files exactly as they are today.&lt;/P&gt;
&lt;P&gt;The Azure NetApp Files object REST API provides object‑based access to that data, enabling modern analytics and AI platforms to work directly with existing file datasets without copying, moving, or restructuring them.&lt;/P&gt;
&lt;P&gt;This same zero-copy pattern is already used to unlock advanced analytics and AI scenarios with services such as Azure Databricks and Microsoft Fabric, validating its suitability for large‑scale enterprise AI workloads.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232253437"&gt;&lt;/A&gt;Why OneLake changes the model&lt;/H1&gt;
&lt;P&gt;Microsoft OneLake is often described as a “single data lake for the entire organization,” but its most important capability in this architecture is what it does not do.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;OneLake does not &lt;EM&gt;ingest&lt;/EM&gt; Azure NetApp Files data.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Instead, it:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;creates &lt;STRONG&gt;shortcuts&lt;/STRONG&gt; as virtual pointers to external data,&lt;/LI&gt;
&lt;LI&gt;preserves &lt;STRONG&gt;ownership, permissions&lt;/STRONG&gt;, and &lt;STRONG&gt;access patterns&lt;/STRONG&gt;,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;avoids&lt;/STRONG&gt; storage duplication and ETL pipelines,&lt;/LI&gt;
&lt;LI&gt;keeps Azure NetApp Files as the &lt;STRONG&gt;authoritative system of record&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This shortcut‑based model allows OneLake to unify data across clouds, platforms, and on‑premises environments while maintaining a single logical namespace.&lt;/P&gt;
&lt;P&gt;From an AI perspective, this is critical. It means enterprise file data can be discovered, indexed, and reasoned over by downstream AI services without breaking compliance boundaries, duplicating storage, or introducing synchronization risk.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232253438"&gt;&lt;/A&gt;What this enables&lt;/H1&gt;
&lt;P&gt;With Azure NetApp Files connected to OneLake through the object REST API:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;enterprise file data becomes AI‑addressable,&lt;/LI&gt;
&lt;LI&gt;existing SMB/NFS workflows remain unchanged,&lt;/LI&gt;
&lt;LI&gt;data stays governed, secured, and owned by the original platform,&lt;/LI&gt;
&lt;LI&gt;AI systems gain visibility into previously inaccessible knowledge.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This architecture does not replace SharePoint‑based scenarios. Instead, it expands AI and data analytics scenarios across a broader, more representative enterprise data estate.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232253439"&gt;&lt;/A&gt;Key takeaway&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;Azure NetApp Files is the high-performance, intelligent, and cyber-resilient foundation for enterprise file data, powering AI with enterprise application file data wherever it lives.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;By combining Azure NetApp Files, the object REST API, and Microsoft OneLake, organizations establish a unified, zero‑copy foundation that brings enterprise file data into scope for modern AI systems.&lt;/P&gt;
&lt;P&gt;With the data foundation in place, the next step is turning that data into usable knowledge.&lt;/P&gt;
&lt;P&gt;This AI‑ready data foundation enables higher‑level AI capabilities and agents that are governed and surfaced to users in later layers of the architecture.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;In Part 2,&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" style="background-color: rgb(255, 255, 255); font-style: normal; font-weight: 400;" href="https://techcommunity.microsoft.com/blog/azurestorageblog/from-file-data-to-ai%E2%80%91powered-knowledge-pipelines-using-azure-netapp-files-object/4528001" target="_blank" rel="noopener" data-lia-auto-title="From File Data to AI‑Powered Knowledge Pipelines using Azure NetApp Files object REST API " data-lia-auto-title-active="0"&gt;From File Data to AI‑Powered Knowledge Pipelines using Azure NetApp Files object REST API &lt;/A&gt;we’ll explore how this foundation enables a knowledge pipeline using Azure AI Search and Azure OpenAI to support Retrieval-Augmented Generation (RAG).&lt;/STRONG&gt;&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc232253440"&gt;&lt;/A&gt;Learn more&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurestorageblog/from-file-data-to-ai%E2%80%91powered-knowledge-pipelines-using-azure-netapp-files-object/4528001" target="_blank" rel="noopener" data-lia-auto-title="From File Data to AI‑Powered Knowledge Pipelines using Azure NetApp Files object REST API | Microsoft Community Hub" data-lia-auto-title-active="0"&gt;From File Data to AI‑Powered Knowledge Pipelines using Azure NetApp Files object REST API | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurestorageblog/bringing-enterprise-file-data-to-users-with-azure-netapp-files-microsoft-foundry/4528002" target="_blank" rel="noopener" data-lia-auto-title="Bringing Enterprise File Data to Users with Azure NetApp Files, Microsoft Foundry, and M365 Copilot | Microsoft Community Hub" data-lia-auto-title-active="0"&gt;Bringing Enterprise File Data to Users with Azure NetApp Files, Microsoft Foundry, and M365 Copilot | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/object-rest-api-introduction" target="_blank" rel="noopener"&gt;Understand Azure NetApp Files object REST API | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/object-rest-api-access-configure" target="_blank" rel="noopener"&gt;Configure object REST API in Azure NetApp Files | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/object-rest-api-onelake" target="_blank" rel="noopener"&gt;Connect OneLake to an Azure NetApp Files volume using object REST API | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurearchitectureblog/how-azure-netapp-files-object-rest-api-powers-azure-and-isv-data-and-ai-services/4459545" target="_blank" rel="noopener" data-lia-auto-title="How Azure NetApp Files Object REST API powers Azure and ISV Data &amp;amp; AI services – on YOUR data | Microsoft Community Hub" data-lia-auto-title-active="0"&gt;How Azure NetApp Files Object REST API powers Azure and ISV Data &amp;amp; AI services – on YOUR data | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurearchitectureblog/unlocking-advanced-data-analytics--ai-with-azure-netapp-files-object-rest-api/4486098" target="_blank" rel="noopener" data-lia-auto-title="Unlocking Advanced Data Analytics &amp;amp; AI with Azure NetApp Files object REST API | Microsoft Community Hub" data-lia-auto-title-active="0"&gt;Unlocking Advanced Data Analytics &amp;amp; AI with Azure NetApp Files object REST API | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 15 Jun 2026 07:37:21 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/from-enterprise-file-storage-to-an-ai-ready-data-foundation/ba-p/4527999</guid>
      <dc:creator>GeertVanTeylingen</dc:creator>
      <dc:date>2026-06-15T07:37:21Z</dc:date>
    </item>
    <item>
      <title>From File Data to AI‑Powered Knowledge Pipelines using Azure NetApp Files object REST API</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/from-file-data-to-ai-powered-knowledge-pipelines-using-azure/ba-p/4528001</link>
      <description>&lt;H1&gt;Table of Contents&lt;/H1&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc231223799" target="_self" rel="noopener"&gt;Introduction&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc231223800" target="_self" rel="noopener"&gt;Why a knowledge pipeline is required&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc231223801" target="_self" rel="noopener"&gt;Retrieval‑augmented generation (RAG) at enterprise scale&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc231223802" target="_self" rel="noopener"&gt;Knowledge pipeline architecture overview&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc231223803" target="_self" rel="noopener"&gt;Step 1: Indexing enterprise file content without moving it&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc231223804" target="_self" rel="noopener"&gt;Step 2: Creating semantic meaning with embeddings&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc231223805" target="_self" rel="noopener"&gt;Step 3: Retrieval at query time&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc231223806" target="_self" rel="noopener"&gt;Step 4: Grounded answer generation&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc231223807" target="_self" rel="noopener"&gt;Why this architecture matters&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc231223808" target="_self" rel="noopener"&gt;Preparing for the Copilot experience&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc231223809" target="_self" rel="noopener"&gt;Key takeaway&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc231223810" target="_self" rel="noopener"&gt;Learn more&lt;/A&gt;&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc231223799"&gt;&lt;/A&gt;Introduction&lt;/H1&gt;
&lt;P&gt;In &lt;STRONG&gt;Part 1&lt;/STRONG&gt;, &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurestorageblog/from-enterprise-file-storage-to-an-ai-ready-data-foundation-using-azure-netapp-f/4527999" target="_blank" rel="noopener" data-lia-auto-title="From Enterprise File Storage to an AI-Ready Data Foundation using Azure NetApp Files and OneLake" data-lia-auto-title-active="0"&gt;From Enterprise File Storage to an AI-Ready Data Foundation using Azure NetApp Files and OneLake&lt;/A&gt;, we established the foundation: how Azure NetApp Files and Microsoft OneLake together transform enterprise file storage into an AI‑addressable data layer, without data migration, duplication, or workflow disruption.&lt;/P&gt;
&lt;P&gt;But an AI‑ready foundation alone does not make data usable by AI.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-8"&gt;&lt;STRONG&gt;⚠️Important&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Industry research shows that many AI initiatives fail &lt;EM&gt;before&lt;/EM&gt; they ever reach production. According to IDC, fewer than half (44%) of AI pilot projects advance out of experimentation, with the primary limiting factors not being model capability but the quality of business data and the timeliness of access to it.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;IDC, *AI-Ready Data Storage Infrastructure: Definition, Taxonomy, Ontology, and Future Outlook*, IDC #US53709325, August 2025&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;To turn enterprise file data into something large language models can reason over, search, and cite, we need a knowledge pipeline, one that can understand unstructured content at scale, retrieve the right information at the right time, and ground AI responses in authoritative source data.&lt;/P&gt;
&lt;P&gt;This is where Retrieval‑Augmented Generation (RAG) enters the architecture.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;Co-authors:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/gotthomas/" target="_blank" rel="noopener"&gt;Thomas Willingham&lt;/A&gt;, Azure NetApp Files Product Manager&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/seanluce/" target="_blank" rel="noopener"&gt;Sean Luce&lt;/A&gt;, Azure NetApp Files Product Manager&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc231223800"&gt;&lt;/A&gt;Why a knowledge pipeline is required&lt;/H1&gt;
&lt;P&gt;Large language models are powerful, but they have a fundamental limitation in enterprise settings: they do &lt;STRONG&gt;not&lt;/STRONG&gt; have inherent access to your organization’s internal data.&lt;/P&gt;
&lt;P&gt;Even when data is accessible through a unified foundation like OneLake, these models cannot simply “read” files on demand. Enterprise AI systems require a mechanism to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Discover&lt;/STRONG&gt; relevant content across large document sets,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Understand&lt;/STRONG&gt; the semantic meaning of unstructured files,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Retrieve&lt;/STRONG&gt; only the most relevant excerpts for a given question,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Generate&lt;/STRONG&gt; responses grounded in real documents, with traceability.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is exactly what a knowledge pipeline provides.&lt;/P&gt;
&lt;P&gt;Rather than pushing all enterprise data into a model, the pipeline keeps data in place, builds a continuously updated semantic index, and retrieves relevant information at query time. The AI model then generates answers &lt;EM&gt;based only on retrieved content&lt;/EM&gt;, not on guesswork or generalized training data.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc231223801"&gt;&lt;/A&gt;Retrieval‑augmented generation (RAG) at enterprise scale&lt;/H1&gt;
&lt;P&gt;At a high level, Retrieval‑Augmented Generation combines two functions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Retrieval&lt;/STRONG&gt; – finding the most relevant pieces of enterprise content&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Generation&lt;/STRONG&gt; – using a language model to synthesize an answer from those retrieved sources&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;For enterprise file data, this pattern is especially important:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;File repositories are large, dynamic, and constantly changing&lt;/LI&gt;
&lt;LI&gt;Content is unstructured and varies widely in format and quality&lt;/LI&gt;
&lt;LI&gt;Accuracy, traceability, and compliance are mandatory, not optional&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;RAG ensures that AI responses are grounded in current, authorized enterprise content, not inferred, outdated, or hallucinated knowledge.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc231223802"&gt;&lt;/A&gt;Knowledge pipeline architecture overview&lt;/H1&gt;
&lt;P&gt;In this solution, the knowledge pipeline sits on top of the OneLake data foundation and connects enterprise file data to downstream AI experiences through three core services:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Component&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Role in the Knowledge Pipeline&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft OneLake&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Provides unified, zero‑copy access to enterprise file data&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Azure AI Search&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Indexes, chunks, and retrieves relevant content using keyword + vector search&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Azure OpenAI&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Generates semantic embeddings and synthesizes grounded responses&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;Together, these services transform passive file data into an actively queryable enterprise knowledge system.&lt;/P&gt;
&lt;H2&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc231223803"&gt;&lt;/A&gt;Step 1: Indexing enterprise file content without moving it&lt;/H2&gt;
&lt;P&gt;The pipeline begins with Azure AI Search indexing content exposed through OneLake.&lt;/P&gt;
&lt;P&gt;Because OneLake references Azure NetApp Files volumes via shortcuts, Azure AI Search can read files directly, without copying them into another storage system. Files remain:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Stored&lt;/STRONG&gt; on Azure NetApp Files,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;In-place available&lt;/STRONG&gt; via existing SMB / NFS workflows,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Governed&lt;/STRONG&gt; by their original security and ownership model.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Azure AI Search performs three key functions during indexing:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Content extraction&lt;/STRONG&gt; – reading text from supported document formats,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Chunking&lt;/STRONG&gt; – splitting large documents into semantically meaningful segments,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Metadata capture&lt;/STRONG&gt; – preserving filenames and contextual information.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;This process creates a searchable representation of enterprise file content while leaving the original data untouched. As files change, this index is refreshed through re-indexing processes that regenerate embeddings for updated content.&lt;/P&gt;
&lt;H2&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc231223804"&gt;&lt;/A&gt;Step 2: Creating semantic meaning with embeddings&lt;/H2&gt;
&lt;P&gt;Keyword search alone is insufficient for natural language queries.&lt;/P&gt;
&lt;P&gt;To understand &lt;EM&gt;meaning&lt;/EM&gt;, not just matching words, the pipeline uses vector embeddings generated by Azure OpenAI.&lt;/P&gt;
&lt;P&gt;During indexing:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Each document chunk is converted into a high‑dimensional vector that represents its semantic meaning,&lt;/LI&gt;
&lt;LI&gt;These embeddings are stored in Azure AI Search alongside the textual index.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This enables semantic similarity search, allowing the system to retrieve relevant content even when a user’s question does not match document wording exactly.&lt;/P&gt;
&lt;P&gt;For example:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A query about “incident response procedures” can retrieve documents titled “Security Escalation Playbook.”&lt;/LI&gt;
&lt;LI&gt;Policy intent matters more than literal phrasing.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is critical for natural language AI scenarios, where users ask questions conversationally rather than searching by filename or keyword.&lt;/P&gt;
&lt;H2&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc231223805"&gt;&lt;/A&gt;Step 3: Retrieval at query time&lt;/H2&gt;
&lt;P&gt;When a user submits a question, for example through an AI agent, the knowledge pipeline activates in real time.&lt;/P&gt;
&lt;P&gt;At query time:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The question is converted into an embedding,&lt;/LI&gt;
&lt;LI&gt;Azure AI Search performs vector similarity search against the indexed content,&lt;/LI&gt;
&lt;LI&gt;The most relevant document chunks are retrieved,&lt;/LI&gt;
&lt;LI&gt;Source metadata (including filenames) is preserved.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Only the retrieved content is passed to the language model for response generation.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example: How retrieval works in practice&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A user asks: “What is our incident escalation procedure for data breaches?”&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The system retrieves relevant sections from documents such as a “Security Escalation Playbook” stored on Azure NetApp Files, and passes only those excerpts to the language model to generate a grounded response with source citations included.&lt;/P&gt;
&lt;P&gt;This design ensures:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;AI responses are based on actual enterprise documents,&lt;/LI&gt;
&lt;LI&gt;The scope of information is tightly controlled,&lt;/LI&gt;
&lt;LI&gt;Results remain explainable and auditable.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc231223806"&gt;&lt;/A&gt;Step 4: Grounded answer generation&lt;/H2&gt;
&lt;P&gt;Finally, Azure OpenAI synthesizes a natural language response using only the retrieved content.&lt;/P&gt;
&lt;P&gt;The model does not infer beyond the supplied sources. Instead, it:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Summarizes relevant information,&lt;/LI&gt;
&lt;LI&gt;Resolves ambiguities across multiple documents,&lt;/LI&gt;
&lt;LI&gt;Produces an answer grounded in enterprise data.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Because filenames are preserved throughout the pipeline, downstream interfaces, such as an AI agent, require responses to include explicit source citations.&lt;/P&gt;
&lt;P&gt;This is especially important in regulated and compliance‑driven environments, where users must be able to verify where an answer came from.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc231223807"&gt;&lt;/A&gt;Why this architecture matters&lt;/H1&gt;
&lt;P&gt;The knowledge pipeline solves a problem that generic AI integrations cannot:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;No data movement&lt;/STRONG&gt; – files remain on Azure NetApp Files,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;No re‑platforming&lt;/STRONG&gt; – existing workflows continue unchanged,&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;No trust gap&lt;/STRONG&gt; – every answer can be traced back to a real document.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Instead of forcing enterprises to restructure their data to fit AI tools, this architecture adapts AI to how enterprises store and manage knowledge.&lt;/P&gt;
&lt;P&gt;The result is a &lt;STRONG&gt;living knowledge system&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Updated as content changes through re-indexing processes that refresh the semantic index,&lt;/LI&gt;
&lt;LI&gt;Scalable across millions of documents,&lt;/LI&gt;
&lt;LI&gt;Ready to support multiple AI experiences, not just a single user-facing scenario.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc231223808"&gt;&lt;/A&gt;Preparing for the Copilot experience&lt;/H1&gt;
&lt;P&gt;At this point, the pipeline has done the hard work:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Enterprise file data is accessible through OneLake,&lt;/LI&gt;
&lt;LI&gt;Semantically indexed and searchable,&lt;/LI&gt;
&lt;LI&gt;Ready for controlled, grounded AI access.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;What remains is exposing this capability to end users; safely, consistently, and within the tools they already use.&lt;/P&gt;
&lt;P&gt;This knowledge pipeline provides the governed, retrieval‑ready foundation that enterprise AI agents can consume and orchestrate, before being surfaced to end users through downstream user experiences.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc231223809"&gt;&lt;/A&gt;Key takeaway&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;Enterprise file data becomes a living, queryable knowledge system, without moving, copying, or restructuring a single file, eliminating the operational “copy-tax” associated with data duplication.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;By combining Microsoft OneLake, Azure AI Search, and Azure OpenAI, the knowledge pipeline transforms the zero‑copy data foundation into an actively searchable enterprise resource. Every AI response is grounded in real documents, traceable to its source, and scoped to authorized content.&lt;/P&gt;
&lt;P&gt;With the knowledge pipeline in place, the next step is surfacing this capability to end users in a secure and intuitive way.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;In Part 3, &lt;/STRONG&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurestorageblog/bringing-enterprise-file-data-to-users-with-azure-netapp-files-microsoft-foundry/4528002" target="_blank" rel="noopener" data-lia-auto-title="Bringing Enterprise File Data to Users with Microsoft Foundry, M365 Copilot and Azure NetApp Files" data-lia-auto-title-active="0"&gt;Bringing Enterprise File Data to Users with Microsoft Foundry, M365 Copilot and Azure NetApp Files&lt;/A&gt;&lt;STRONG&gt;,&lt;/STRONG&gt;&lt;STRONG&gt; we’ll explore how this pipeline is exposed through enterprise AI agents and user experiences, and governed by Microsoft Foundry, enabling natural language interaction with enterprise file data, complete with citations, governance, and enterprise controls.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc231223810"&gt;&lt;/A&gt;Learn more&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurestorageblog/from-enterprise-file-storage-to-an-ai-ready-data-foundation-using-azure-netapp-f/4527999" target="_blank" rel="noopener" data-lia-auto-title="From Enterprise File Storage to an AI-Ready Data Foundation using Azure NetApp Files and OneLake" data-lia-auto-title-active="0"&gt;From Enterprise File Storage to an AI-Ready Data Foundation using Azure NetApp Files and OneLake&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurestorageblog/bringing-enterprise-file-data-to-users-with-azure-netapp-files-microsoft-foundry/4528002" target="_blank" rel="noopener" data-lia-auto-title="Bringing Enterprise File Data to Users with Azure NetApp Files, Microsoft Foundry, and M365 Copilot" data-lia-auto-title-active="0"&gt;Bringing Enterprise File Data to Users with Azure NetApp Files, Microsoft Foundry, and M365 Copilot&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/search/retrieval-augmented-generation-overview" target="_blank" rel="noopener"&gt;Retrieval‑Augmented Generation (RAG) with Azure AI Search | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/search/vector-search-integrated-vectorization-ai-studio" target="_blank" rel="noopener"&gt;Integrated vectorization with Azure OpenAI embeddings | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/object-rest-api-onelake" target="_blank" rel="noopener"&gt;Connect OneLake to an Azure NetApp Files volume using object REST API | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 15 Jun 2026 07:37:13 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/from-file-data-to-ai-powered-knowledge-pipelines-using-azure/ba-p/4528001</guid>
      <dc:creator>GeertVanTeylingen</dc:creator>
      <dc:date>2026-06-15T07:37:13Z</dc:date>
    </item>
    <item>
      <title>File share migrations simplified with Azure Copilot Migration Agent</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/file-share-migrations-simplified-with-azure-copilot-migration/ba-p/4524563</link>
      <description>&lt;P&gt;Building on our&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/azuremigrationblog/discover-and-assess-file-shares-for-migration-to-azure-files-with-azure-migrate/4509034" target="_blank" rel="noopener"&gt;earlier announcement of discovery and assessment support for SMB and NFS file shares in Azure Migrate&lt;/A&gt;, we are extending the experience to support end-to-end file share migrations within the same workflow. With &lt;A href="https://techcommunity.microsoft.com/blog/azuremigrationblog/azure-copilot-migration-agent/4501292" target="_blank" rel="noopener"&gt;Azure Copilot Migration Agent&lt;/A&gt;, customers can move from discovery and assessment to migration through a single guided experience in Azure Migrate. By bringing planning and execution together, the &lt;A href="https://aka.ms/MigrationAgentDocs" target="_blank" rel="noopener"&gt;agent&lt;/A&gt; helps organizations streamline migration activity, reduce handoffs, and maintain continuity across stages.&lt;/P&gt;
&lt;H2 data-line="6"&gt;Overview&lt;/H2&gt;
&lt;P&gt;Since the release of file share discovery and assessment in Azure Migrate earlier this year, customers have indicated that while visibility into their file share estate improved, the transition to execution remained fragmented. In many cases, teams still had to work across separate workflows for inventory, readiness planning, and migration, increasing operational friction and the risk of losing context between stages.&lt;/P&gt;
&lt;P&gt;Azure Copilot Migration Agent helps address this gap by bringing discovery, assessment, planning, and execution into a single guided journey. Azure Migrate provides visibility and recommendations, while Azure Storage Mover supports execution in a connected, agentic experience. The result is a more consistent migration path that reduces complexity, preserves context, and helps teams move file shares to Azure with greater operational confidence.&lt;/P&gt;
&lt;img&gt;Invoking the Azure Migration Copilot Agent for on-premises data migration&lt;/img&gt;
&lt;P class="lia-clear-both"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 data-line="18"&gt;Customer Value&lt;/H2&gt;
&lt;P&gt;This update streamlines the migration journey by connecting each stage of the process and reducing operational overhead. Natural language guidance helps teams start and manage migration activities much faster, often in hours or days instead of weeks.&lt;/P&gt;
&lt;P&gt;The experience supports the following scenarios:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;End-to-end discovery, assessment, and migration for on-premises Windows and Linux file shares (SMB) to Azure Files.&lt;/LI&gt;
&lt;LI&gt;Discovery and assessment for on-premises Windows and Linux file shares (NFS).&lt;/LI&gt;
&lt;LI&gt;Data transfers from one Azure Blob container to another container.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 data-line="39"&gt;Design principles&lt;/H2&gt;
&lt;P&gt;The experience preserves continuity across inventory, readiness insights, and execution planning, enables direct movement of validated shares when heavyweight orchestration is unnecessary, maintains approval and sequencing controls, and supports the file and object movement patterns commonly required in production environments.&lt;/P&gt;
&lt;H2&gt;Getting Started with Storage Migration in Azure Copilot Migration Agent (ACMA)&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;Launch Azure Migrate: Sign-in to the Azure portal, open Azure Migrate.&lt;/LI&gt;
&lt;LI&gt;From the Getting Started page, open Azure Copilot Migration Agent, then select or create an Azure Migrate project.&lt;/LI&gt;
&lt;LI&gt;Describe the migration in natural language. The agent detects storage migration intent and assists with storage migration planning and routes execution requests seamlessly.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H4&gt;Examples scenarios and prompts&lt;/H4&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;Migration of on-premises Windows Server data over SMB to Azure Files &lt;/SPAN&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;setting up key vault after source is confirmed&lt;/img&gt;
&lt;P class="lia-clear-both"&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;create target if not already present&lt;/img&gt;
&lt;P class="lia-clear-both"&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;review configuration before creation of migration job&lt;/img&gt;&lt;img&gt;run migration job and check status&lt;/img&gt;
&lt;P class="lia-clear-both"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Prompt: Help me transfer data from one Azure blob container to another blob container&lt;/P&gt;
&lt;H2&gt;Call to action&lt;/H2&gt;
&lt;P&gt;Storage integrated capability is launching in Limited Preview at Microsoft Build. Sign up for the Preview&amp;nbsp;&lt;A href="https://forms.cloud.microsoft/r/nJzS9MXnWk" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;For questions, contact &lt;A href="mailto:storagemigrationcopilotagent@microsoft.com" target="_blank" rel="noopener"&gt;storagemigrationcopilotagent@microsoft.com&lt;/A&gt;.&lt;/P&gt;
&lt;H3 data-line="55"&gt;Learn More&lt;/H3&gt;
&lt;OL data-line="56"&gt;
&lt;LI data-line="56"&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/migrate/create-file-share-assessment?view=migrate" target="_blank" rel="noopener" data-href="https://learn.microsoft.com/en-us/azure/migrate/create-file-share-assessment?view=migrate"&gt;File share discovery and assessment in Azure Migrate&lt;/A&gt;&lt;/LI&gt;
&lt;LI data-line="57"&gt;&lt;A href="https://aka.ms/MigrationAgentDocs" target="_blank" rel="noopener" data-href="https://aka.ms/MigrationAgentDocs"&gt;Azure Copilot Migration Agent&lt;/A&gt;&lt;/LI&gt;
&lt;LI data-line="58"&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/storage-mover/" target="_blank" rel="noopener" data-href="https://learn.microsoft.com/en-us/azure/storage-mover/"&gt;Azure Storage Mover&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 03 Jun 2026 12:28:05 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/file-share-migrations-simplified-with-azure-copilot-migration/ba-p/4524563</guid>
      <dc:creator>madhurinrao</dc:creator>
      <dc:date>2026-06-03T12:28:05Z</dc:date>
    </item>
    <item>
      <title>Simpler, scalable file share management in Azure - now generally available</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/simpler-scalable-file-share-management-in-azure-now-generally/ba-p/4523035</link>
      <description>&lt;P&gt;Linux workloads in Azure are scaling faster than ever, powering everything from container platforms, analytics pipelines, SAP environments to line-of-business applications. As these workloads grow, infrastructure teams commonly run into challenges with scale, cost management, complexity and compliance. IT organizations need more granular control over management and isolation boundaries for file shares independent of storage accounts, to prevent multiple application teams sharing the same capacity pools, limits, and configuration surface across different storage services. Infrastructure administrators seek operational simplicity with managing access control, policy and networking isolation for file shares, so application teams can focus on business logic and development agility.&lt;/P&gt;
&lt;P&gt;We are announcing the general availability of a &lt;A href="https://learn.microsoft.com/en-us/azure/storage/files/create-file-share?tabs=azure-portal" target="_blank" rel="noopener"&gt;new service&lt;/A&gt; management experience for premium SSD file shares (NFS) which allows each file share to be created, secured, scaled, and billed independently, without being tied to a storage account.&lt;/P&gt;
&lt;P&gt;Key benefits include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Familiar and intuitive file share management&lt;/STRONG&gt;: Aligns user experience with on-premises NAS and file server paradigms, improving usability compared to the classic model.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Infrastructure-as-Code&lt;/STRONG&gt;: Define naming, capacity, IOPS, networking, tags, and security in Bicep or ARM templates for simplified automation with your favorite DevOps tools.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Scale to match the workload&lt;/STRONG&gt;: Support for up to 10,000 file shares per subscription per region, with 2.5x faster file share provisioning experience.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Share-level security and networking&lt;/STRONG&gt;: Network restrictions, snapshots, and encryption scoped to the individual share, making isolation boundaries match workload boundaries.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Per-share cost visibility&lt;/STRONG&gt;: Billing meters emit under the file share resource, teams can crossbill accurately, track per-workload costs, and improve chargeback without workarounds.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;H2&gt;Independent performance, security, and billing per share&lt;/H2&gt;
&lt;P&gt;Combined with the provisioned v2 model, each file share is independently provisioned with its own storage, IOPS, and throughput. This allows organizations to align file shares directly to application or tenant boundaries, rather than grouping them under shared infrastructure constructs.&lt;/P&gt;
&lt;P&gt;For multi-tenant SaaS platforms, this enables a natural one-to-one mapping between tenants and file shares. Each tenant operates within its own performance envelope, allowing steady workloads and bursty workloads to scale independently without contention. This reduces the need for capacity planning tradeoffs or overprovisioning to accommodate peak usage across tenants.&lt;/P&gt;
&lt;P&gt;This isolation extends beyond performance; each file share carries its own encryption in transit settings, RBAC, policy, and network boundaries. For example, production tenants can be isolated with dedicated private endpoints, while development environments can operate under more flexible configurations. These boundaries align directly with application design, making systems easier to reason about and manage at scale.&lt;/P&gt;
&lt;P&gt;Finally, treating each file share as its own resource simplifies cost management. Teams can tag and track usage at the workload or tenant level, enabling more accurate chargeback and better visibility into resource consumption. This makes it easier to understand how individual workloads contribute to overall spending without introducing additional tracking mechanisms.&lt;/P&gt;
&lt;H2&gt;Start easy, scale big&lt;/H2&gt;
&lt;P&gt;Cloud-native Linux applications often scale dynamically, so the underlying storage platform must provide resources quickly and support higher scale limits to keep pace with workload demand and enable teams to quickly provision infrastructure and keep pace of development. The new file share experience supports up to 10,000 file shares per subscription per region, making it practical to use a dedicated share for each application, environment, or tenant without running into platform limits. It also provides faster provisioning, with time to first share 2.5x times faster than classic file shares, so teams can spend less time waiting on infrastructure and more time building, testing, and shipping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;“Provisioning is fast and integrates seamlessly with Linux environments through NFS.”&lt;EM&gt; - &lt;/EM&gt;Siam Commercial Bank&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;Data protection with snapshots&lt;/H2&gt;
&lt;P&gt;Linux workloads using shared file storage require robust data protection. With the new service management experience, customers can continue to leverage point-in-time incremental snapshots with up to 200 snapshots per share. You can also now edit metadata on individual snapshots, making it easier to organize and identify recovery points. Whether you need short term restore points or need to retain data for compliance requirements, snapshots provide an easy and cost-effective recovery mechanism.&lt;/P&gt;
&lt;H2&gt;Get started today&lt;/H2&gt;
&lt;P&gt;The new file share experience is available for NFS 4.1 file shares on SSD storage, using the provisioned v2 billing model with LRS and ZRS options. Whether the deployment model is ARM templates, Bicep, MCP server, or custom CI/CD pipelines, file shares are scriptable, repeatable, and automatable through the same tooling used for the rest of Azure infrastructure. Explore our &lt;A href="https://go.microsoft.com/fwlink/?LinkId=2365254" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt; for step-by-step guidance.&lt;/P&gt;
&lt;P&gt;We're continuously enhancing the new file share experience with the goal of achieving full feature parity while delivering improved scale and performance limits. We would love to hear your feedback, please fill out the &lt;A href="https://forms.cloud.microsoft/r/vQ9kesXuzY" target="_blank" rel="noopener"&gt;survey&lt;/A&gt; to share your thoughts.&lt;/P&gt;
&lt;H3&gt;Learn more&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://go.microsoft.com/fwlink/?LinkId=2334847" target="_blank" rel="noopener"&gt;Planning for an Azure Files deployment&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://go.microsoft.com/fwlink/?LinkId=2365254" target="_blank" rel="noopener"&gt;How to create a file share&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://go.microsoft.com/fwlink/?LinkId=2343819" target="_blank" rel="noopener"&gt;Scalability &amp;amp; performance targets&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For questions or feedback, contact us at azurefiles@microsoft.com.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 19:07:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/simpler-scalable-file-share-management-in-azure-now-generally/ba-p/4523035</guid>
      <dc:creator>VincentLiu</dc:creator>
      <dc:date>2026-06-02T19:07:28Z</dc:date>
    </item>
    <item>
      <title>Secure, Modern Access to Azure Files on macOS with MS Entra ID</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/secure-modern-access-to-azure-files-on-macos-with-ms-entra-id/ba-p/4524077</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Enterprises,&amp;nbsp;large&amp;nbsp;and small,&amp;nbsp;rely on Azure Files for secure, scalable, and cost-efficient&amp;nbsp;file&amp;nbsp;storage.&amp;nbsp;Modern&amp;nbsp;workflows&amp;nbsp;today span devices, platforms, and geographies;&amp;nbsp;seamless,&amp;nbsp;and&amp;nbsp;secure access to shared data across every endpoint is critical to keeping teams productive and collaborative.&amp;nbsp;With&amp;nbsp;the&amp;nbsp;growing demand for access across every device, Azure Files now extends&amp;nbsp;secure access&amp;nbsp;to macOS with Entra ID authentication,&amp;nbsp;supporting design, creative, and AI teams where they work.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Today, we are announcing&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Public&amp;nbsp;Preview&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;of&amp;nbsp;MS&amp;nbsp;Entra&amp;nbsp;ID&amp;nbsp;based authentication for Azure Files on macOS.&amp;nbsp;Whether you are running creative production pipelines, design workflows, or AI workloads, macOS users can now access Azure file shares securely, meeting Microsoft Entra ID enterprise governance standards automatically and seamlessly, with no credential prompts, no storage account keys, and no complexity.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Key benefits&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Enhanced&amp;nbsp;Security&amp;nbsp;posture:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;MacOS&amp;nbsp;users can now sign in to their device and open shared files in Finder with no credential prompts and no storage account keys.&amp;nbsp;Microsoft Entra ID governs access, conditional access policies, MFA requirements, and&amp;nbsp;MS Entra ID&amp;nbsp;governance applies&amp;nbsp;automatically&amp;nbsp;with&amp;nbsp;AES-256&amp;nbsp;encryption.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Reduced operational overhead&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;: IT&amp;nbsp;admins&amp;nbsp;no longer need to manage storage account key distribution/rotation. Provisioning and deprovisioning access is handled through standard Entra ID group membership.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;No dependency on Active Directory&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt; Organizations moving away from on-premises&amp;nbsp;infrastructure,&amp;nbsp;including&amp;nbsp;Active Directory,&amp;nbsp;can now give MacOS users full access to Azure file shares using cloud-based identities in MS Entra ID, with no domain controller&amp;nbsp;required. MacOS users get full parity with the traditional Windows SMB share experience.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Identity Based Access model&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&amp;nbsp;User authentication is&amp;nbsp;enforced with&amp;nbsp;Kerberos&amp;nbsp;and&amp;nbsp;share-level access is enforced through Azure RBAC.&amp;nbsp;File and folder permissions are controlled through NTFS ACLs, giving organizations precise, layered control.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Enabling AI-Driven Workloads&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;:&amp;nbsp;SMB&amp;nbsp;shares&amp;nbsp;on macOS enables AI teams to seamlessly access and share large datasets, fueling faster experimentation and&amp;nbsp;streamlining&amp;nbsp;developer&amp;nbsp;and AI-generated&amp;nbsp;workflows.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Partnership with Apple&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Azure Files support for macOS is built in close collaboration with Apple macOS SMB engineering team. The integration works with&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://support.apple.com/guide/deployment/platform-sso-for-macos-dep7bbb05313/web" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Apple’s Platform SSO&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity-platform/apple-sso-plugin" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Enterprise SSO plug-in&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;via MDM platforms such as Microsoft Intune.&amp;nbsp;This allows macOS devices to authenticate through Microsoft Entra ID with single sign-in. We are committed to continuing this partnership to ensure Mac users in enterprise environments have a first-class experience accessing cloud services.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Powering Diverse Workloads&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;across&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Des&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;ign&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Developer&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Education&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Ent&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;er&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;prises&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Secure SMB access for creative workloads&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Creative workflows on macOS have historically required workarounds to reach centralized cloud storage, often meaning local copies, consumer file sharing tools, or storage account keys distributed to individuals. Azure Files gives creative teams direct access to shared project libraries and production files from Finder, with no syncing or local copies needed. For IT, setup is simple: assign the right RBAC role on the share, add users to an Entra group, and access is ready. No keys to distribute and no deep storage&amp;nbsp;expertise&amp;nbsp;required.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;"&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Secure access for our macOS users is a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;gamechanger&lt;/STRONG&gt; for our creative teams&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. The ability to mount directly and access shared files securely — without keys, without workarounds — changes how we work. It’s&amp;nbsp;how&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;modern enterprise file access&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;should feel&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;"&lt;/EM&gt; -Peter Day, Senior Engineer,&amp;nbsp;The Marketing Store&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;SMB shares streamline developer and AI-generated build workflows&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;MacOS developers rely on local tools like Visual Studio Code, GitHub copilot, or fast iteration, but build artifacts, logs, and AI-generated outputs often end up fragmented across machines and pipelines.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With Azure Files, teams can use SMB shares as a centralized workspace for&amp;nbsp;build&amp;nbsp;outputs and shared assets. Mac build systems can write directly to a mounted share, making artifacts&amp;nbsp;immediately&amp;nbsp;accessible across developers, pipelines, and AI agents. DevOps teams gain a secure, identity-based storage layer using RBAC and Microsoft Entra, without managing keys or custom storage solutions.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Enabl&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;e&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;co&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ll&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;boration&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;across mixed&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;plat&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;form&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;environments&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Mac users should not be a special case. Azure Files gives MacOS users the same governed, identity-based access to shared storage that Windows users have always had. Access is provisioned through Entra ID, enforced through RBAC, and managed without a separate workflow, separate keys, or separate infrastructure. For large organizations running mixed-OS environments, this means a single, consistent access model&amp;nbsp;tied to&amp;nbsp;the&amp;nbsp;user and&amp;nbsp;not&amp;nbsp;a&amp;nbsp;device&amp;nbsp;–&amp;nbsp;the&amp;nbsp;user&amp;nbsp;can&amp;nbsp;seamlessly&amp;nbsp;access the&amp;nbsp;SMB share&amp;nbsp;across&amp;nbsp;their&amp;nbsp;Windows&amp;nbsp;and&amp;nbsp;Mac&amp;nbsp;devices.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;“&lt;SPAN data-olk-copy-source="MessageBody"&gt;By supporting Kerberos authentication for Azure Files on Mac devices, Microsoft delivers &lt;STRONG&gt;secure, consistent access&lt;/STRONG&gt; for organizations operating &lt;STRONG&gt;mixed-OS environments.&lt;/STRONG&gt; It addresses a long-standing enterprise gap by extending&lt;STRONG&gt; centrally governed identity controls&lt;/STRONG&gt; to all users, regardless of device—helping organizations simplify access management and &lt;STRONG&gt;maintain trust at scale&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;”&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;-Preetham G.K., CDL, Accenture&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335557856&amp;quot;:16777215,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Mo&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;dernize&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;In&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;frast&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ruct&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ure&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;se&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;cure a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ccess&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Education&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;al&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Institutions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Institutions standardizing on macOS have faced a hard tradeoff:&amp;nbsp;maintain&amp;nbsp;costly on-premises infrastructure at every&amp;nbsp;site or&amp;nbsp;accept that MacOS&amp;nbsp;users fall back on personal drives and consumer file sharing. Neither is acceptable&amp;nbsp;at&amp;nbsp;scale. Azure Files removes the tradeoff. Students, faculty, and staff access shared repositories and course materials directly from&amp;nbsp;an&amp;nbsp;SMB share&amp;nbsp;over&amp;nbsp;Finder using their Entra ID credentials.&amp;nbsp;Access management can&amp;nbsp;be controlled&amp;nbsp;through group membership, with no per-site infrastructure and no manual credential management.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Get started with Azure Files Entra Kerberos authentication for macOS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Start&amp;nbsp;leveraging&amp;nbsp;secure, identity-based file access on macOS today at no added cost. Explore&amp;nbsp;our&amp;nbsp;&lt;/SPAN&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/storage/files/identity-kerberos-authentication-macos?source=docs" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;for step-by-step guidance. Whether you are onboarding new Mac users or modernizing an existing deployment, this feature gives your organization a simple path to identity management for Azure Files on macOS. Make your Mac workloads ready for the future!&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For any questions, please reach out to the team at&amp;nbsp;&lt;/SPAN&gt;&lt;A href="mailto:azurefiles@microsoft.com" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;azurefiles@microsoft.com&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 18:55:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/secure-modern-access-to-azure-files-on-macos-with-ms-entra-id/ba-p/4524077</guid>
      <dc:creator>grace_kim</dc:creator>
      <dc:date>2026-06-02T18:55:03Z</dc:date>
    </item>
    <item>
      <title>From Scale to Breakthrough: Azure NetApp Files Sets a New Cloud Benchmark for EDA Performance</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/from-scale-to-breakthrough-azure-netapp-files-sets-a-new-cloud/ba-p/4520890</link>
      <description>&lt;H1&gt;Table of Contents&lt;/H1&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc230032971" target="_self" rel="noopener"&gt;Introduction&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc230032972" target="_self" rel="noopener"&gt;New benchmark proof with large volume breakthrough mode&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc230032973" target="_self" rel="noopener"&gt;What is Azure NetApp Files large volume breakthrough mode?&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc230032974" target="_self" rel="noopener"&gt;Explore the latest Azure NetApp Files SPECstorage® 2020 publications&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc230032975" target="_self" rel="noopener"&gt;Results that Speak for Themselves&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc230032976" target="_self" rel="noopener"&gt;Single large volume breakthrough mode&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="#community--1-_Toc230032977" target="_self" rel="noopener"&gt;Large volume breakthrough mode at scale&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc230032978" target="_self" rel="noopener"&gt;Performance that Scales with Your Design Cycles&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc230032979" target="_self" rel="noopener"&gt;From large volume scale… to breakthrough mode scale&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc230032980" target="_self" rel="noopener"&gt;What Storage Performance Means For EDA Velocity&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_Toc230032981" target="_self" rel="noopener"&gt;Learn more&lt;/A&gt;&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc230032971"&gt;&lt;/A&gt;Introduction&lt;/H1&gt;
&lt;P&gt;In his latest &lt;SPAN style="color: rgb(30, 30, 30);"&gt;&lt;A class="lia-external-url" href="https://azure.microsoft.com/en-us/blog/azure-netapp-files-for-eda-workloads-from-revolution-to-breakthrough-at-scale/" target="_blank" rel="noopener"&gt;Azure NetApp Files for EDA workloads: From revolution to breakthrough at scale&lt;/A&gt; post &lt;/SPAN&gt;&lt;A class="lia-external-url" href="https://azure.microsoft.com/en-us/blog/author/aung-oo/" target="_blank"&gt;Aung Oo&lt;/A&gt; – Vice President, Azure Storage – explored a fundamental shift in Electronic Design Automation (EDA) infrastructure: cloud storage no longer needs to tradeoff between scale and predictable performance. It unpacked the historical compromises EDA teams made to balance amongst extreme concurrently, shared datasets and the strict latency requirements and how&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/azure-netapp-files-introduction" target="_blank" rel="noopener"&gt;Azure NetApp Files&lt;/A&gt; was architected to solve these challenges with consistent, linear scaling behavior.&lt;/P&gt;
&lt;P&gt;Just as importantly, that post presented independently validated &lt;A class="lia-external-url" href="https://www.spec.org/storage2020/" target="_blank" rel="noopener"&gt;SPECstorage® Solution 2020&lt;/A&gt; benchmarks showing that Azure NetApp Files can support real-world EDA workloads at scale while sustaining sub-millisecond latency – shifting cloud storage from a bottleneck in modern chip design pipelines to an enabler.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;This blog builds on that foundation.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;With the introduction of &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/whats-new#november-2025" target="_blank" rel="noopener"&gt;Azure NetApp Files large volume breakthrough mode&lt;/A&gt;, the conversation shifts from proving scalable performance to redefining its upper limits. Where earlier results established predictable scaling, breakthrough mode pushes the concurrency envelope further – allowing thousands of parallel jobs to share storage while maintaining consistent latency under sustained load.&lt;/P&gt;
&lt;P&gt;The result is a new level of cloud performance for EDA: not just solving scale challenges, but delivering a true performance breakthrough, now validated by the latest SPECstorage® Solution 2020 benchmark publications.&lt;/P&gt;
&lt;P&gt;In this blog, we take a closer look at two new &lt;A class="lia-external-url" href="https://www.spec.org/storage2020/results/eda_blended/" target="_blank" rel="noopener"&gt;SPECstorage® Solution 2020 EDA_BLENDED benchmark submissions&lt;/A&gt; that validate the impact of large volume breakthrough mode, both for a single volume configuration and at scale, and place those results in real-world context.&lt;/P&gt;
&lt;P&gt;Co-authors:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/ron-hogue-8656a94/" target="_blank" rel="noopener"&gt;Ron Hogue&lt;/A&gt;, Sr. Program Manager&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/ranga-sankar-2594401/" target="_blank" rel="noopener"&gt;Ranga Sankar&lt;/A&gt;, Azure NetApp Files Product Manager&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/andy-chan-3720418/" target="_blank" rel="noopener"&gt;Andy Chan&lt;/A&gt;, Azure NetApp Files HPC/EDA Principal Product Manager&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/gstrother/" target="_blank" rel="noopener"&gt;George Strother&lt;/A&gt;, Senior Cloud Solutions Architect, NetApp&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/in/cassmorgenstern/" target="_blank" rel="noopener"&gt;Cass Morgenstern&lt;/A&gt;, Director of Engineering - Office the CTO, NetApp&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc230032972"&gt;&lt;/A&gt;New benchmark proof with large volume breakthrough mode&lt;/H1&gt;
&lt;P&gt;Following the same industry‑standard SPECstorage® Solution 2020 EDA_BLENDED workload methodology used in our prior large volume submissions, the newly published results evaluate:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure NetApp Files large volume breakthrough mode&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure NetApp Files large volume breakthrough mode scale&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these independently audited benchmark publications validate how breakthrough mode enable Azure NetApp Files large volumes to sustain higher concurrency levels while maintaining the consistent, sub‑millisecond response times that modern chip design pipelines depend on.&lt;/P&gt;
&lt;H2&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc230032973"&gt;&lt;/A&gt;What is Azure NetApp Files large volume breakthrough mode?&lt;/H2&gt;
&lt;P&gt;Azure NetApp Files large volume breakthrough mode unlocks a new level of scale and performance for the most demanding EDA workloads. By combining massive concurrency with consistent sub-millisecond latency, it helps modern chip design pipelines move faster, scale further, and operate without compromise.&lt;/P&gt;
&lt;P&gt;For a quick overview, check out the Quick Byte video:&lt;/P&gt;
&lt;div data-video-id="https://www.youtube.com/watch?v=6ISCwDirLs0/1779133900680" data-video-remote-vid="https://www.youtube.com/watch?v=6ISCwDirLs0/1779133900680" class="lia-video-container lia-media-is-center lia-media-size-large"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F6ISCwDirLs0%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D6ISCwDirLs0&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F6ISCwDirLs0%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;H2&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc230032974"&gt;&lt;/A&gt;Explore the latest Azure NetApp Files SPECstorage® 2020 publications&lt;/H2&gt;
&lt;P&gt;These two newly released benchmark publications showcase the exceptional performance and scalability of Azure NetApp Files’ large volume breakthrough mode for EDA workloads.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Azure NetApp Files large volume breakthrough mode:&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;A class="lia-external-url" href="https://www.spec.org/storage2020/results/res2026q2/storage2020-20260227-00147.html" target="_blank" rel="noopener"&gt;https://www.spec.org/storage2020/results/res2026q2/storage2020-20260227-00147.html&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Azure NetApp Files large volume breakthrough mode scale: &lt;BR /&gt;&lt;/STRONG&gt;&lt;A class="lia-external-url" href="https://www.spec.org/storage2020/results/res2026q2/storage2020-20260227-00148.html" target="_blank" rel="noopener"&gt;https://www.spec.org/storage2020/results/res2026q2/storage2020-20260227-00148.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc230032975"&gt;&lt;/A&gt;Results that Speak for Themselves&lt;/H1&gt;
&lt;P&gt;This chapter presents the latest benchmark results for Azure NetApp Files in full detail, highlighting the significant performance advantages enabled by large volume breakthrough mode. Through both single and scaled large volume configurations, these results demonstrate the ability to support demanding EDA workloads with exceptional throughput and consistent low latency. The findings underscore Azure NetApp Files’ capability to meet the rigorous requirements of modern chip design pipelines, ensuring reliability and efficiency at every scale.&lt;/P&gt;
&lt;H2&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc230032976"&gt;&lt;/A&gt;Single large volume breakthrough mode&lt;/H2&gt;
&lt;P&gt;The architecture shown in the diagram was specifically designed to generate the load necessary for producing the benchmark results discussed in this section.&lt;/P&gt;
&lt;img /&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;The result:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The Azure NetApp Files large volume breakthrough mode configuration reached&amp;nbsp;&lt;STRONG&gt;2,880&lt;/STRONG&gt; SPECstorage® Solution 2020 EDA_BLENDED JOBS with an overall response time of &lt;STRONG&gt;0.51 ms&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;A single Azure NetApp Files large volume breakthrough mode delivered&amp;nbsp;&lt;STRONG&gt;20,910 MB/s&lt;/STRONG&gt;&amp;nbsp;(19,941 MiB/s) of throughput and&amp;nbsp;&lt;STRONG&gt;1,296,040 operations per second&lt;/STRONG&gt;&amp;nbsp;at peak.&lt;/P&gt;
&lt;P&gt;Throughout the iterations, sub-millisecond latency was observed with latency only breaching 1 ms at the very peak.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;BR /&gt;This level of performance demonstrates how a single large volume deployment can sustain thousands of concurrent EDA workloads – while preserving the latency profile required for simulation, synthesis, and verification tasks.&lt;/P&gt;
&lt;H2&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc230032977"&gt;&lt;/A&gt;Large volume breakthrough mode at scale&lt;/H2&gt;
&lt;P&gt;The architecture shown in the diagram was specifically designed to generate the load necessary for producing the benchmark results discussed in this section. For resource availability reasons, six volumes were distributed across multiple Azure regions and availability zones, though this is not a requirement. Deployments can use any number of volumes, and regional / zonal distribution is optional – only necessary when targeting specific availability or resilience goals.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;The result:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The Azure NetApp Files large volume breakthrough mode scale configuration reached&amp;nbsp;&lt;STRONG&gt;17,280&lt;/STRONG&gt; SPECstorage® Solution 2020 EDA_BLENDED JOBS with an overall response time of &lt;STRONG&gt;0.60 ms&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;At this scale, the aggregate throughput was&amp;nbsp;&lt;STRONG&gt;125,474 MB/s&lt;/STRONG&gt;&amp;nbsp;(119,661&amp;nbsp;MiB/s), with&amp;nbsp;&lt;STRONG&gt;7,776,147 operations per second&lt;/STRONG&gt; on the benchmark.&lt;/P&gt;
&lt;P&gt;Again, throughout the iterations, sub-millisecond latency was observed with latency only breaching 1 ms at the peak.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;Even at six times the workload scale, latency remains consistently sub‑millisecond – enabling highly parallel EDA workflows to scale without introducing storage‑induced bottlenecks.&lt;/P&gt;
&lt;P&gt;The multi-region/zone configuration was selected for resource availability reasons. This configuration is not a requirement, and deployments can use any number of volumes – by no means limited to six. A configuration can scale to any number of volumes, provided sufficient large volume capacity is available.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc230032978"&gt;&lt;/A&gt;Performance that Scales with Your Design Cycles&lt;/H1&gt;
&lt;P&gt;Across breakthrough mode and breakthrough mode scale configurations, latency remains tightly bounded as workload concurrency increases — indicating that Azure NetApp Files large volume breakthrough mode enables linear scalability characteristics without introducing latency instability under load.&lt;/P&gt;
&lt;img /&gt;&lt;img /&gt;&lt;img /&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;EDA_BLENDED Metric&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Large volume&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;breakthrough mode&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Large volume&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;breakthrough mode scale&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Factor&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Job Sets&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;2,880&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;17,280&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;6.00x&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Throughput (MB/s)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;20,910&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;125,474&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;6.00x&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Operations/second&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;1,296,040&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;7,776,147&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;6.00x&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;ORT (ms)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;0.51&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;0.60&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;1.18x&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;This predictable performance and scale behavior is critical for distributed EDA environments, where design teams increasingly rely on massively parallel simulation and verification jobs to accelerate time‑to‑tape‑out.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc230032979"&gt;&lt;/A&gt;From large volume scale… to breakthrough mode scale&lt;/H1&gt;
&lt;P&gt;Compared to &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/azurearchitectureblog/validating-scalable-eda-storage-performance-azure-netapp-files-and-specstorage-s/4459517" target="_blank" rel="noopener" data-lia-auto-title="previously published (non‑breakthrough mode) large volume results" data-lia-auto-title-active="0"&gt;previously published (non‑breakthrough mode) large volume results&lt;/A&gt; from October 2025,, large volume breakthrough mode expands the achievable throughput envelope while even lowering observed overall response times as workload levels increase.&lt;/P&gt;
&lt;img /&gt;&lt;img /&gt;
&lt;P&gt;This allows Azure NetApp Files to deliver:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Higher aggregate throughput ceilings&lt;/LI&gt;
&lt;LI&gt;Greater concurrency tolerance&lt;/LI&gt;
&lt;LI&gt;Consistent latency behavior under scaled-out EDA job submission&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;– all without architectural changes to application workflows.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-1" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;More Throughput + Consistent Low Latency = More Jobs!&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc230032980"&gt;&lt;/A&gt;What Storage Performance Means For EDA Velocity&lt;/H1&gt;
&lt;P&gt;Modern EDA workflows are built around rapid, iterative design loops, where architects and physical designers continuously refine Register-Transfer Level (RTL), run regressions, analyze timing, fix violations, and repeat often thousands of times before tape‑out. At scale, these workflows depend on large compute grids with hundreds or thousands of cores accessing shared storage simultaneously. In this environment, storage latency is not just a performance metric; it directly determines engineering velocity and business outcomes. Azure NetApp Files large volume breakthrough mode delivers cloud‑native storage performance that keeps every core productive, enabling higher simulation throughput, faster iteration cycles, and predictable performance even under extreme parallel load. The benchmark results independently validate how Azure NetApp Files large volume breakthrough mode empowers the most demanding modern EDA workflows.&lt;/P&gt;
&lt;P&gt;Ultimately, this improves engineering velocity. Shorter regression cycles enable more iterations per day, higher compute utilization eliminates idle cores, and predictable performance allows teams to confidently push scale without risk. More iterations before tape‑out translate directly into better Power, Performance, and Area (PPA) outcomes and faster time‑to‑market. For semiconductor design organizations, Azure NetApp Files large volume breakthrough mode elevates storage from supporting infrastructure to a strategic enabler – delivering independently validated, cloud‑scale performance purpose‑built for the most demanding EDA workloads.&lt;/P&gt;
&lt;P&gt;Storage Performance Impact on Engineering Velocity:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Shorter regression cycles → more design iterations per day&lt;/LI&gt;
&lt;LI&gt;Higher compute utilization → no idle cores or wasted licenses&lt;/LI&gt;
&lt;LI&gt;Fewer job failures → engineers focus on design, not infrastructure&lt;/LI&gt;
&lt;LI&gt;Faster data movement → smoother transitions across design stages&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is why companies investing in cloud‑scale EDA infrastructure such as&amp;nbsp;&lt;A class="lia-external-url" href="https://www.netapp.com/media/140770-na-1201-azure-eda-solution-brief.pdf" target="_blank" rel="noopener"&gt;AMD&lt;/A&gt;, &lt;A class="lia-external-url" href="https://azure.microsoft.com/en-us/blog/azure-netapp-files-revolutionizing-silicon-design-for-high-performance-computing/" target="_blank" rel="noopener"&gt;Microsoft&lt;/A&gt;, and &lt;A class="lia-external-url" href="https://www.netapp.com/customers/asml-holding/" target="_blank" rel="noopener"&gt;ASML&lt;/A&gt;, consistently report faster time‑to‑market and stronger design outcomes.&lt;/P&gt;
&lt;H1&gt;&lt;A class="lia-anchor" target="_blank" name="_Toc230032981"&gt;&lt;/A&gt;Learn more&lt;/H1&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/azure-netapp-files/azure-netapp-files-introduction" target="_blank" rel="noopener"&gt;What is Azure NetApp Files&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.spec.org/storage2020/" target="_blank" rel="noopener"&gt;SPECstorage® Solution 2020&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.spec.org/storage2020/results/eda_blended/" target="_blank" rel="noopener"&gt;All Published SPECstorage® Solution 2020_eda_blended Results&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://azure.microsoft.com/en-us/blog/azure-netapp-files-for-eda-workloads-from-revolution-to-breakthrough-at-scale/" target="_blank" rel="noopener"&gt;Azure NetApp Files for EDA workloads: From revolution to breakthrough at scale&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://techcommunity.microsoft.com/blog/azurearchitectureblog/validating-scalable-eda-storage-performance-azure-netapp-files-and-specstorage-s/4459517" target="_blank" rel="noopener" data-lia-auto-title="Validating Scalable EDA Storage Performance: Azure NetApp Files and SPECstorage® Solution 2020" data-lia-auto-title-active="0"&gt;Validating Scalable EDA Storage Performance: Azure NetApp Files and SPECstorage® Solution 2020&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://learn.microsoft.com/azure/azure-netapp-files/solutions-benefits-azure-netapp-files-electronic-design-automation" target="_blank" rel="noopener"&gt;Benefits of using Azure NetApp Files for Electronic Design Automation (EDA)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://azure.microsoft.com/blog/azure-netapp-files-revolutionizing-silicon-design-for-high-performance-computing/" target="_blank" rel="noopener"&gt;Azure NetApp Files: Revolutionizing silicon design for high-performance computing&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://learn.microsoft.com/azure/azure-netapp-files/azure-netapp-files-solution-architectures#electronic-design-automation-eda" target="_blank" rel="noopener"&gt;Solution architectures using Azure NetApp Files | Electronic design automation (EDA)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 22 May 2026 15:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/from-scale-to-breakthrough-azure-netapp-files-sets-a-new-cloud/ba-p/4520890</guid>
      <dc:creator>GeertVanTeylingen</dc:creator>
      <dc:date>2026-05-22T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Action required: Kerberos RC4 hardening may affect Azure Files 
Active Directory Domain Services</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/action-required-kerberos-rc4-hardening-may-affect-azure-files/ba-p/4518577</link>
      <description>&lt;P&gt;A Windows security hardening change beginning in April 2026 updates default Kerberos encryption behavior and may impact customers using Azure Files with Active Directory Domain Services (AD DS) authentication over SMB. If you created Azure Files shares prior to 2023, or chose RC4 encryption for your file shares, you will need to reconfigure to use AES-256 to avoid disruption to file share access. This is in accordance with the updated security posture and recommendation from Windows &lt;A href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20833" target="_blank" rel="noopener"&gt;CVE-2026-20833.&lt;/A&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;H2&gt;Background&lt;/H2&gt;
&lt;P&gt;Azure Files uses Kerberos authentication for identity-based access when integrated with on-premises Active Directory Domain Services (AD DS). AES-256 Kerberos encryption has been supported since AzFilesHybrid module v0.2.2, and it has been the default since v0.2.5. Historically, RC4 was the only supported option until AES-256 support was added. This is a Windows platform security hardening change; Azure Files service behavior is not being modified.&lt;/P&gt;
&lt;H2&gt;You may be impacted if:&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;You use Kerberos-based SMB access to Azure Files with AD DS authentication, and&lt;/LI&gt;
&lt;LI&gt;Kerberos encryption settings are RC4-only or unset (null) for relevant AD objects, service accounts, or computer accounts associated with Azure Files authentication.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;When will this happen:&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;April 2026 – July 2026&lt;/STRONG&gt;: Install the Windows security update and validate access. Domain controllers will default to issuing AES-256 tickets when msDS-SupportedEncryptionTypes is not explicitly set.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;After July 2026: &lt;/STRONG&gt;Manual rollback is removed. If you have not migrated to AES-256 by then, Kerberos-based SMB access to your Azure Files shares may fail.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;What you should do now:&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;Find out if you are impacted, run the following PowerShell command on a domain-joined machine, with read access to AD. This identifies storage accounts that use Azure Files with AD DS authentication but have not been upgraded to AES-256 or follow the detection steps in &lt;A class="lia-external-url" href="https://aka.ms/rc4azurefiles" target="_blank" rel="noopener"&gt;aka.ms/rc4azurefiles&lt;/A&gt;:&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI-CODE lang="powershell"&gt;Get-ADObject `
    -LDAPFilter "(&amp;amp;(servicePrincipalName=*.file.core.windows.net)(!(msDS-SupportedEncryptionTypes=*)))" -Properties servicePrincipalName, msDS-SupportedEncryptionTypes |
    Select-Object Name, ObjectClass, servicePrincipalName, msDS-SupportedEncryptionTypes&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/troubleshoot/azure/azure-storage/files/security/files-troubleshoot-encryption#step-2-ensure-aes-256-is-allowed-by-clients-and-by-the-storage-account" target="_blank" rel="noopener"&gt;Update configurations&lt;/A&gt; to support and prefer AES256-based Kerberos ticket encryption.&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/troubleshoot/azure/azure-storage/files/security/files-troubleshoot-encryption#option-1-use-the-azfileshybrid-cmdlet-recommended" target="_blank" rel="noopener"&gt;Validate&lt;/A&gt; end-to-end SMB authentication and application access to Azure Files shares.&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/troubleshoot/azure/azure-storage/files/security/files-troubleshoot-encryption#step-4-confirm-the-aes-256-upgrade" target="_blank" rel="noopener"&gt;Run klist purge&lt;/A&gt; from an elevated command prompt to clear any cached Kerberos tickets that still use RC4.&lt;/LI&gt;
&lt;LI&gt;Remount the Azure file share.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;For any questions, please reach out to the team at&lt;STRONG&gt;&lt;EM&gt; azurefiles@microsoft.com&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2&gt;Resources:&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Azure Files &lt;A class="lia-external-url" href="https://aka.ms/rc4azurefiles" target="_blank"&gt;documentation&lt;/A&gt; on this change&lt;/LI&gt;
&lt;LI&gt;Read the full Windows hardening guidance:&amp;nbsp;&lt;A href="https://support.microsoft.com/topic/1ebcda33-720a-4da8-93c1-b0496e1910dc" target="_blank" rel="noopener"&gt;How to manage Kerberos KDC usage of RC4 for service account ticket issuance changes related to CVE-2026-20833&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Learn about RC4 usage in Windows and its risks:&amp;nbsp;&lt;A href="https://learn.microsoft.com/windows-server/security/kerberos/detect-remediate-rc4-kerberos" target="_blank" rel="noopener"&gt;Detect and remediate RC4 usage in Kerberos&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Learn more about the related vulnerability:&amp;nbsp;&lt;A href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20833" target="_blank" rel="noopener"&gt;CVE-2026-20833&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Windows Server Blog:&amp;nbsp;&lt;A href="https://www.microsoft.com/windows-server/blog/2025/12/03/beyond-rc4-for-windows-authentication/" target="_blank" rel="noopener"&gt;Beyond RC4 for Windows authentication&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 05 Jun 2026 21:50:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/action-required-kerberos-rc4-hardening-may-affect-azure-files/ba-p/4518577</guid>
      <dc:creator>grace_kim</dc:creator>
      <dc:date>2026-06-05T21:50:11Z</dc:date>
    </item>
    <item>
      <title>Modernizing Azure Virtual Desktop with Nerdio and Azure Files</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/modernizing-azure-virtual-desktop-with-nerdio-and-azure-files/ba-p/4516542</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Coauthored with&amp;nbsp;Nerdio&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations adopting Azure Virtual Desktop (AVD) typically begin with small pilot deployments that perform well under limited load. As these environments scale to hundreds or thousands of users, a consistent set of challenges emerges.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;At the center of that shift is the user profile layer. FSLogix profile containers—stored on file shares—sit directly on the critical path of the user experience. During peak periods such as login storms, profile attach latency becomes a primary determinant of sign-in performance.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;At the same time, identity dependencies, storage configuration complexity, and cost management introduce variability across environments. What worked in a pilot often becomes more difficult to manage consistently at scale.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Common challenges&amp;nbsp;include:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Performance variability during peak concurrency&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Complex identity configurations for SMB access&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Configuration drift across environments&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Cost inefficiencies from peak-based provisioning&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;At enterprise scale, these issues converge at the storage and identity layers—making them central to both user experience and operational efficiency.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H1&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 10" data-ccp-parastyle-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;81d40c56-e640-5cda-82bb-83448542e906|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[469775450,&amp;quot;heading 10&amp;quot;,201340122,&amp;quot;2&amp;quot;,134234082,&amp;quot;true&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;heading10&amp;quot;,335572020,&amp;quot;1&amp;quot;,134224900,&amp;quot;true&amp;quot;,268442635,&amp;quot;32&amp;quot;,335559739,&amp;quot;200&amp;quot;,335559738,&amp;quot;360&amp;quot;,335560102,&amp;quot;0&amp;quot;,469777841,&amp;quot;Arial&amp;quot;,469777842,&amp;quot;Arial&amp;quot;,469777843,&amp;quot;Arial&amp;quot;,469777844,&amp;quot;Arial&amp;quot;,469769226,&amp;quot;Arial&amp;quot;]}"&gt;Nerdio&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 10"&gt;: simplifying how AVD is deployed and operated&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:360,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:360,&amp;quot;335559739&amp;quot;:200}"&gt;&lt;A href="https://nmehelp.getnerdio.com/hc/en-us/articles/25499406288653-Create-and-manage-configured-Azure-Files-shares" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Nerdio Manager&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(available as&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Nerdio&amp;nbsp;Manager for Enterprise&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Nerdio&amp;nbsp;Manager for MSP&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;)&amp;nbsp;is a deployment, management, and auto-scaling platform for Azure Virtual Desktop (AVD)&amp;nbsp;with capabilities such as desktop image management, performance monitoring, and user session control&amp;nbsp;to eliminate the need for complex scripting and speed up responses to end-users. Nerdio Manager helps organizations deploy and operate AVD environments in a more consistent, repeatable way. Rather than treating compute, storage, and identity as separate workflows, Nerdio integrates these components into a single operational model. Storage provisioning, permissions, and FSLogix configuration are handled as part of host pool deployment and scaling. This reduces coordination overhead, minimizes configuration drift, and keeps storage aligned with how environments grow.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This view shows how&amp;nbsp;Nerdio&amp;nbsp;brings users, host pools, and storage into a single control plane—ensuring storage is configured&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;as part of deployment&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, not after.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:200}"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 20" data-ccp-parastyle-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;741782aa-652f-563c-bdc7-8d2b1b3f555d|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[469775450,&amp;quot;heading 20&amp;quot;,201340122,&amp;quot;2&amp;quot;,134234082,&amp;quot;true&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;heading20&amp;quot;,335572020,&amp;quot;1&amp;quot;,134224900,&amp;quot;true&amp;quot;,268442635,&amp;quot;28&amp;quot;,335559739,&amp;quot;160&amp;quot;,335559738,&amp;quot;280&amp;quot;,335560102,&amp;quot;1&amp;quot;,469777841,&amp;quot;Arial&amp;quot;,469777842,&amp;quot;Arial&amp;quot;,469777843,&amp;quot;Arial&amp;quot;,469777844,&amp;quot;Arial&amp;quot;,469769226,&amp;quot;Arial&amp;quot;]}"&gt;Azure Files: enabling performance and identity at scale&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:280,&amp;quot;335559739&amp;quot;:160}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/storage/files/storage-files-introduction" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Files&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;provides the foundational storage layer for&amp;nbsp;FSLogix&amp;nbsp;profile containers in many AVD environments. Because profiles attach at sign-in, storage performance directly&amp;nbsp;impacts&amp;nbsp;user experience.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN data-contrast="auto"&gt;Provisioned v2: performance without over-provisioning&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Azure Files Provisioned v2 decouples performance (IOPS and throughput) from capacity.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Previously, higher performance required over-provisioning storage. With Provisioned v2, organizations can align performance directly to workload needs.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;This is especially important for&amp;nbsp;FSLogix, where login storms create short bursts of high IOPS demand even when data volumes are modest.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;The result:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;better cost efficiency and more predictable performance&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;“We’ve&amp;nbsp;been early adopters of&amp;nbsp;Nerdio&amp;nbsp;and consistently see meaningful Azure cost optimization… With Azure Files Provisioned v2, the decoupling of quota and IOPS… gives us precise control over performance and cost.”&lt;/SPAN&gt; &lt;/EM&gt;&lt;SPAN data-contrast="auto"&gt;— David Wasserman, Chief Value Officer, FlexibleIT.com&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN data-contrast="auto"&gt;Entra ID authentication: simplifying identity architecture&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Azure Files supports&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/azurestorageblog/cloud-native-identity-with-azure-files-entra-only-secure-access-for-the-modern-e/4469778" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Entra ID authentication&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;for SMB, enabling a cloud-native identity model.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This&amp;nbsp;eliminates&amp;nbsp;the need for domain infrastructure used only for storage access, resulting in:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Reduced infrastructure overhead&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Simpler networking&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Lower operational burden&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Alignment with Zero Trust&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These capabilities are already in use in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Nerdio&amp;nbsp;Manager for MSP&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;environments managing multi-tenant&amp;nbsp;deployments, and&amp;nbsp;are being extended to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Nerdio&amp;nbsp;Manager for Enterprise&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;in Q3&amp;nbsp;CY26 to&amp;nbsp;enable the same cloud-native model within enterprise environments&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This highlights how provisioning, monitoring, scaling, and identity are handled as part of a unified system instead of fragmented tasks.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 20" data-ccp-parastyle-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;741782aa-652f-563c-bdc7-8d2b1b3f555d|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[469775450,&amp;quot;heading 20&amp;quot;,201340122,&amp;quot;2&amp;quot;,134234082,&amp;quot;true&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;heading20&amp;quot;,335572020,&amp;quot;1&amp;quot;,134224900,&amp;quot;true&amp;quot;,268442635,&amp;quot;28&amp;quot;,335559739,&amp;quot;160&amp;quot;,335559738,&amp;quot;280&amp;quot;,335560102,&amp;quot;1&amp;quot;,469777841,&amp;quot;Arial&amp;quot;,469777842,&amp;quot;Arial&amp;quot;,469777843,&amp;quot;Arial&amp;quot;,469777844,&amp;quot;Arial&amp;quot;,469769226,&amp;quot;Arial&amp;quot;]}"&gt;Operationalizing storage at scale, w&lt;/SPAN&gt;&lt;/SPAN&gt;hy this matters for enterprises&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Enterprise AVD environments operate under fundamentally different constraints. User populations are larger and more concentrated, compliance requirements are stricter, and tolerance for performance variability is significantly lower.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In practice, these pressures converge at the storage layer.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For enterprise customers, the goal is not automation itself—it is better user experience, lower cost, and predictable operations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Faster, more consistent deployments. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Storage is configured alongside compute, reducing dependency on separate teams and minimizing drift.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Lower cost without sacrificing peak performance. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Capacity and performance align with actual demand instead of peak assumptions. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;More predictable sign-ins during login storms. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Standardized configuration reduces bottlenecks during high concurrency.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Audit-ready governance by default. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;RBAC, snapshots, backup, and data protection policies are applied consistently across environments.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;Get started&lt;/H1&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;At scale, Azure Virtual Desktop is as much about storage and identity as it is about compute.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Azure Files plays a central role in determining sign-in performance, user experience, and cost efficiency. With Provisioned v2 and Entra ID authentication, organizations can move toward a more predictable and cloud-native model. Nerdio builds on this foundation by integrating storage and identity into a unified AVD deployment and operations workflow.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://marketplace.microsoft.com/en-us/product/saas/nerdio.nerdioforazure?tab=Overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Get started&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;with Nerdio today.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2026 16:05:17 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/modernizing-azure-virtual-desktop-with-nerdio-and-azure-files/ba-p/4516542</guid>
      <dc:creator>Vybava_Ramadoss</dc:creator>
      <dc:date>2026-05-04T16:05:17Z</dc:date>
    </item>
    <item>
      <title>AHEAD helps us launch the Strategic Azure Storage Services Partner Program</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/ahead-helps-us-launch-the-strategic-azure-storage-services/ba-p/4516355</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Authors:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Aung Oo, Vice President Azure Storage Product Management&lt;/P&gt;
&lt;P&gt;Parker Leavitt, Partner Account Manager, AHEAD&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Special thanks to: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Michael Johnson, Vice President, Cloud, AHEAD&lt;/P&gt;
&lt;img /&gt;
&lt;H1&gt;AHEAD background&lt;/H1&gt;
&lt;P&gt;&lt;A href="https://www.ahead.com/partner/microsoft/" target="_blank" rel="noopener"&gt;AHEAD&lt;/A&gt; was formed in 2007 and possesses deep expertise in Infrastructure, Cloud Platforms, AI, Analytics, Networking, Storage, Security and many more technical disciplines. 80% of AHEAD’s employees are engineers who help customers with the assessment of their needs to design optimal solutions and through implementation of complex application and infrastructure deployments. Headquartered in Chicago, IL, AHEAD has locations worldwide and is ready to assist with your most complex Azure projects. They hold over 1,000 Microsoft certifications and 4 Advanced Specializations.&lt;/P&gt;
&lt;H1&gt;Valued collaboration&lt;/H1&gt;
&lt;P&gt;AHEAD has been a key advisor to Azure Storage throughout the design and build of our Channel strategy. As a premier Microsoft Cloud and AI Partner, and with decades of Storage expertise, AHEAD helped us to create the Learning Path channel partners will need to complete to qualify as a &lt;STRONG&gt;Strategic Azure Storage Services Partner&lt;/STRONG&gt; (SASS). SASS Partners have been validated by us to possess the skills to offer consulting, design, implementation, and migration services to Azure and ISV Storage services.&lt;/P&gt;
&lt;H1&gt;What can you expect?&lt;/H1&gt;
&lt;P&gt;AHEAD brings their history of infrastructure expertise to Azure Storage customers through a catalog of services that make it possible to select the optimal solution to ensure the ideal blend of price, performance, and resiliency.&lt;/P&gt;
&lt;H2&gt;Assessment&lt;/H2&gt;
&lt;P&gt;What are you doing to prepare for the industry wide memory shortage? How well do you understand your datasets? What are your performance requirements? Are there features you are paying for and not using? When was the last time that directory hosting the “Super Important Project” files was accessed? Is there mission critical data hiding that you should be leveraging to fuel Enterprise AI Agents? Is an Azure Storage Service the best fit for your data, or is it better to migrate it to one of our Storage ISV services?&lt;/P&gt;
&lt;P&gt;AHEAD provides Microsoft-funded assessments that deliver data-driven guidance to help you align your application and data set needs with the ideal storage service(s) on Azure. We have long advocated that the best solution is the one that meets your requirements both today and in the future. AHEAD can help you get there.&lt;/P&gt;
&lt;H2&gt;Migration&lt;/H2&gt;
&lt;P&gt;After gaining insight into your data estate, AHEAD has the experience to help you migrate safely with best-of-breed solutions. Whether offline migration with Data Box or online over the network with Storage Mover or one of our validated ISVs like Komprise, Cirrus Data, or Cirata, AHEAD can help you move your data to an Azure Storage service like Blob Storage, Files, Elastic SAN, or NetApp Files – or one of our ISV Partners like Nasuni and Pure Storage. You can find our full list of validated partners on &lt;A href="https://aka.ms/azurestoragepartners" target="_blank" rel="noopener"&gt;Microsoft Learn&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Azure Storage ISV Strength&lt;/H2&gt;
&lt;P&gt;An important reason we chose to onboard AHEAD as our first Strategic Channel Partner was the large crossover in mutual ISV relationships they possess, and their proven skills with each. You can view AHEAD’s full list of partners, including Nasuni, NetApp, Everpure, Commvault, Veeam, Rubrik, and Dell on&amp;nbsp;&lt;A href="https://www.ahead.com/partners/" target="_blank" rel="noopener"&gt;their website&lt;/A&gt;. Our recent engagements with AHEAD and Nasuni are a great example of AHEAD’s depth. They were able to quickly determine Nasuni as the best fit for a customer who required a single centralized Azure-based repository for their data that could then be accessed within Azure and multiple remote locations simultaneously.&lt;/P&gt;
&lt;P&gt;AHEAD has shown us that across their portfolio of ISVs, they can help you implement best-of-breed ISV services that include solutions in:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Air Gap Business Continuity&lt;/LI&gt;
&lt;LI&gt;VMware Modernization&lt;/LI&gt;
&lt;LI&gt;Storage Modernization&lt;/LI&gt;
&lt;LI&gt;Cloud Scale Analytics&lt;/LI&gt;
&lt;LI&gt;AI Dataset Curation&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;How can you move forward?&lt;/H1&gt;
&lt;P&gt;Do you need help understanding your data estate? Could you use expertise selecting the ideal service in Azure to host your data? Reach out to the AHEAD Azure team at &lt;A href="mailto:info@ahead.com" target="_blank" rel="noopener"&gt;info@ahead.com&lt;/A&gt; or via their &lt;A href="https://marketplace.microsoft.com/en-us/marketplace/consulting-services/aheadllc1585153938726.rapid_assess?tab=Overview" target="_blank" rel="noopener"&gt;Rapid Assess&lt;/A&gt; offer on Microsoft Marketplace and get started today!&lt;/P&gt;
&lt;H1&gt;Strategic Azure Storage Services Partner&lt;/H1&gt;
&lt;P&gt;In coming months, you will see our list of SASS Channel Partners expand, but we could not be more grateful to AHEAD for being a not only a pioneer, but a trusted advisor. Their commitment to Azure and Azure customers has made an impact that will benefit our customers worldwide.&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2026 00:49:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/ahead-helps-us-launch-the-strategic-azure-storage-services/ba-p/4516355</guid>
      <dc:creator>karautenMSFT</dc:creator>
      <dc:date>2026-05-01T00:49:28Z</dc:date>
    </item>
    <item>
      <title>Prefix-scoped access for User Delegation SAS is now generally available for Azure Blob Storage</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/prefix-scoped-access-for-user-delegation-sas-is-now-generally/ba-p/4516010</link>
      <description>&lt;P&gt;We would like to share that &lt;STRONG&gt;prefix-scoped access for User Delegation SAS for Azure Blob Storage is generally available in all Azure regions&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;SAS tokens for Blob Storage have historically supported two levels of scope: container and individual blob. With this release, you can now scope access to a &lt;STRONG&gt;prefix or virtual directory&lt;/STRONG&gt; within a container, granting access to all blobs beneath the path.&lt;/P&gt;
&lt;P&gt;This is especially valuable for applications that organize data by tenant, workspace, project, or department within a shared container. Instead of granting access to an entire container or generating many blob-level tokens, you can now issue a single SAS token scoped to a set of blobs through a prefix.&lt;/P&gt;
&lt;P&gt;For example, if a container has these blobs:&lt;/P&gt;
&lt;P&gt;contoso/sales/Q1-report.csv&lt;/P&gt;
&lt;P&gt;contoso/sales/Q2-report.csv&lt;/P&gt;
&lt;P&gt;contoso/invoice.pdf&lt;/P&gt;
&lt;P&gt;A SAS token scoped to the prefix contoso/sales would grant access only to the two sales reports. This simplifies manageability by not having to generate multiple blob scoped tokens which significantly reduces overhead to manage permissions for large scale data storage estates. In addition, it helps customers provide more scoped permissions to a certain set of blobs rather than broader permissions at a container level.&lt;/P&gt;
&lt;P&gt;Prefix-scoped access is supported for both Blob and Data Lake storage accounts.&lt;/P&gt;
&lt;P&gt;As a best practice, we recommend using Entra ID with RBAC or ABAC for least privilege access. If you need to use SAS for your use cases, we recommend using user delegation SAS and prefix-based scoping is a good option to consider for more scoped permissions for a certain set of blobs.&lt;/P&gt;
&lt;H5&gt;Pricing and Availability&lt;/H5&gt;
&lt;P&gt;There is no additional cost for prefix-scoped access for user delegation SAS. Pricing is based on standard transaction costs for your storage account type. To learn more, see&lt;A class="lia-external-url" href="https://azure.microsoft.com/pricing/details/storage/blobs/" target="_blank" rel="noopener"&gt; Azure Storage Pricing&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;Prefix-scoped access for user delegation SAS is available in all Azure regions.&lt;/P&gt;
&lt;H5&gt;How to generate a prefix-scoped SAS&lt;/H5&gt;
&lt;P&gt;To generate and use a prefix-scoped SAS:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Identify the prefix (or virtual directory) you want to authorize.&lt;/LI&gt;
&lt;LI&gt;Follow the steps in the documentation to create a prefix-scoped SAS for &lt;A class="lia-external-url" href="https://learn.microsoft.com/rest/api/storageservices/create-user-delegation-sas" target="_blank" rel="noopener"&gt;user delegation SAS&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Use the SAS token with your application.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Notes&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Support for prefix-scoped access parameters is available with authorization version 2020-02-10 or later via REST API and .NET Blob SDKs starting with version 12.29.0-beta.1 and newer.&lt;/LI&gt;
&lt;LI&gt;The semantics for prefix scope (sr=d) are similar to container scope (sr=c), except that access is restricted to a prefix. When creating a prefix-scoped SAS, you must specify the signedDirectoryDepth (sdd) to indicate how many directory levels from the container root to the specified directory. For example, to grant access to dir2 on path container1/dir1/dir2, set the directory depth (sdd) = 2 to indicate the SAS is scoped to dir2 and everything beneath it.&lt;/LI&gt;
&lt;LI&gt;Below are .NET SDK and REST API examples for reference.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H6&gt;&lt;U&gt;.NET SDK Sample Definition&lt;/U&gt;&lt;/H6&gt;
&lt;LI-CODE lang=""&gt;            BlobSasBuilder blobSasBuilder = new BlobSasBuilder(
                permissions: BlobContainerSasPermissions.All,
                expiresOn: Recording.UtcNow.AddDays(1))
            {
                BlobContainerName = test.Container.Name,
                BlobName = blobName,
                IsDirectory = true,
            };

            // Test using same name as SAS
            BlobUriBuilder blobUriBuilder1 = new BlobUriBuilder(test.Container.Uri)
            {
                BlobName = blobName,
                Sas = blobSasBuilder.ToSasQueryParameters(Tenants.GetNewSharedKeyCredentials())
            };
            AppendBlobClient appendBlobClient1 = new AppendBlobClient(blobUriBuilder1.ToUri(), GetOptions());
            await appendBlobClient1.CreateAsync();

            // Test using SAS name + suffix
            BlobUriBuilder blobUriBuilder2 = new BlobUriBuilder(test.Container.Uri)
            {
                BlobName = blobName + "/test",
                Sas = blobSasBuilder.ToSasQueryParameters(Tenants.GetNewSharedKeyCredentials())
            };
            AppendBlobClient appendBlobClient2 = new AppendBlobClient(blobUriBuilder2.ToUri(), GetOptions());
            await appendBlobClient2.CreateAsync();&lt;/LI-CODE&gt;
&lt;H6&gt;&lt;U&gt;REST API Sample Request&lt;/U&gt;&lt;/H6&gt;
&lt;P&gt;GET https://myaccount.blob.core.windows.net/mycontainer&lt;/P&gt;
&lt;P&gt;?restype=container&lt;/P&gt;
&lt;P&gt;&amp;amp;comp=list&lt;/P&gt;
&lt;P&gt;&amp;amp;prefix=dir1/dir2/&lt;/P&gt;
&lt;P&gt;&amp;amp;sr=d&lt;/P&gt;
&lt;P&gt;&amp;amp;sdd=2&lt;/P&gt;
&lt;P&gt;&amp;amp;sp=rl&lt;/P&gt;
&lt;P&gt;&amp;amp;sv=2024-11-04&lt;/P&gt;
&lt;P&gt;&amp;amp;se=2026-04-22T06:00:00Z&lt;/P&gt;
&lt;P&gt;&amp;amp;skoid=&amp;lt;signed-oid&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;amp;sktid=&amp;lt;signed-tid&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;amp;skt=2026-04-22T00:00:00Z&lt;/P&gt;
&lt;P&gt;&amp;amp;ske=2026-04-22T08:00:00Z&lt;/P&gt;
&lt;P&gt;&amp;amp;sks=b&lt;/P&gt;
&lt;P&gt;&amp;amp;skv=2024-11-04&lt;/P&gt;
&lt;P&gt;&amp;amp;sig=&amp;lt;signature&amp;gt;&lt;/P&gt;
&lt;H5&gt;Next Steps&lt;/H5&gt;
&lt;P&gt;For a deeper dive, explore these resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/storage/common/storage-sas-overview" target="_blank" rel="noopener"&gt;Grant limited access to data with shared access signatures (SAS)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/rest/api/storageservices/create-user-delegation-sas" target="_blank" rel="noopener"&gt;Create a user delegation SAS&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/rest/api/storageservices/create-service-sas" target="_blank" rel="noopener"&gt;Create a service SAS&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/storage/blobs/monitor-blob-storage?tabs=azure-portal" target="_blank" rel="noopener"&gt;Monitor Azure Blob Storage&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;Help and Support&lt;/H5&gt;
&lt;P&gt;If you have questions, get answers from community experts in &lt;A class="lia-external-url" href="https://learn.microsoft.com/answers/tags/125/azure-blob-storage" target="_blank" rel="noopener"&gt;Microsoft Q&amp;amp;A&lt;/A&gt;. If you have a support plan and you need technical help, create a &lt;A class="lia-external-url" href="https://portal.azure.com/#blade/Microsoft_Azure_Support/HelpAndSupportBlade/newsupportrequest" target="_blank" rel="noopener"&gt;support request&lt;/A&gt;:  &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;For Issue type, select&amp;nbsp;&lt;STRONG&gt;Technical&lt;/STRONG&gt;.  &lt;/LI&gt;
&lt;LI&gt;For Subscription, select your subscription.  &lt;/LI&gt;
&lt;LI&gt;For Service, select &lt;STRONG&gt;My services&lt;/STRONG&gt;.  &lt;/LI&gt;
&lt;LI&gt;For Service type, select &lt;STRONG&gt;Blob Storage&lt;/STRONG&gt;.  &lt;/LI&gt;
&lt;LI&gt;For Resource, select the Azure resource you are creating a support request for.  &lt;/LI&gt;
&lt;LI&gt;For Summary, type a description of your issue.  &lt;/LI&gt;
&lt;LI&gt;For Problem type, select &lt;STRONG&gt;Authentication and Authorization&lt;/STRONG&gt; .&lt;/LI&gt;
&lt;LI&gt;For Problem subtype, select Issues using &lt;STRONG&gt;Shared Access Signature (SAS Token)&lt;/STRONG&gt;. &lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 06 May 2026 20:01:06 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/prefix-scoped-access-for-user-delegation-sas-is-now-generally/ba-p/4516010</guid>
      <dc:creator>despindola</dc:creator>
      <dc:date>2026-05-06T20:01:06Z</dc:date>
    </item>
    <item>
      <title>Secure, Keyless Application Access with Managed Identities - Now GA in Azure Files SMB</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/secure-keyless-application-access-with-managed-identities-now-ga/ba-p/4513053</link>
      <description>&lt;P&gt;As enterprises modernize applications and strengthen their security posture, identity is central to how applications access shared storage. Traditional identity models relying on account keys, stored credentials, or domain‑joined infrastructure add operational overhead and introduce security risks such as credential leakage, lack of identity attribution, and excessive privilege if shared keys are compromised. Today, we are excited to announce the &lt;STRONG&gt;General Availability (GA) of Managed Identity support for Azure Files over SMB&lt;/STRONG&gt;, enabling applications and virtual machines to securely access Azure Files without secrets, passwords, or key distribution.&lt;/P&gt;
&lt;P&gt;Managed Identity support enables customers to &lt;STRONG&gt;meet modern enterprise security standards&lt;/STRONG&gt; without reliance on storage account keys, streamlining how organizations &lt;STRONG&gt;securely enable file&lt;/STRONG&gt;‑&lt;STRONG&gt;based application access&lt;/STRONG&gt; and reducing the operational overhead of filing internal exceptions. New storage accounts can support secure, identity‑based SMB access out of the box, while existing deployments can get secure by enabling Managed Identity authentication.&lt;/P&gt;
&lt;P&gt;From web application workloads such as WordPress, to databases on Azure Kubernetes Service (AKS), to CI/CD pipelines, applications require secure access. In a world where security is foundational, continued reliance on key-based access conflicts with Zero Trust principles and least privilege access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H2&gt;What’s New In GA&lt;/H2&gt;
&lt;H3&gt;AKS Workload Identity Support&lt;/H3&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://github.com/kubernetes-sigs/azurefile-csi-driver/blob/master/docs/workload-identity-static-pv-mount.md" target="_blank"&gt;AKS Workload Identity&lt;/A&gt; (preview) extends the traditional managed identity model for Kubernetes by shifting the identity from the node to pods. Instead of inheriting the identity of the underlying cluster, each Kubernetes pod can use its own federated identity, mapped directly to a Microsoft Entra ID principal.&lt;/P&gt;
&lt;P&gt;This feature enables:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Pod-level identity isolation&lt;/STRONG&gt;, rather than cluster-level&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Least-privilege access&lt;/STRONG&gt; with secure RBAC&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Seamless scaling and redeployment&lt;/STRONG&gt;, without identity reconfiguration&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;No secrets, no key rotation, no credential injection&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When combined with Azure Files over SMB, Workload Identity allows AKS workloads to access shared file storage &lt;STRONG&gt;securely and natively per pod&lt;/STRONG&gt;, using the same identity-driven model as cluster level managed identities. Now available with AKS 1.35, for customers specifically in the financial services industries, AKS Workload Identity enables per‑application, least‑privilege access to Azure Files without credentials, improving isolation and auditability. This allows regulated, stateful workloads to run securely on AKS while meeting strict compliance and regulatory requirements.&lt;/P&gt;
&lt;H3&gt;Co-existence of Application Identities and end-user identity access&lt;/H3&gt;
&lt;P&gt;Azure Files now enables both Managed Identity and end‑user access on the same storage account, with users and applications independently authenticated via Entra ID and authorized through a shared permissions model.&lt;BR /&gt;This unified access model eliminates the need for duplicate storage or credentials, enabling secure collaboration, troubleshooting, and automation on shared data without compromising governance or compliance.&lt;/P&gt;
&lt;P&gt;This supports scenarios such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Developers accessing the same file share as an application for debugging&lt;/LI&gt;
&lt;LI&gt;Admins managing content used by automated workflows&lt;/LI&gt;
&lt;LI&gt;Hybrid environments with user-driven and app-driven access&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Simplified Storage Account enablement via the Azure portal&lt;/H3&gt;
&lt;P&gt;We have now added a dedicated Managed Identity property that makes enabling identity‑based SMB access simple and transparent via the Azure portal for new as well as existing storage accounts. With a single configuration at the storage account level, customers can allow applications to authenticate to Azure Files using Managed Identities. This portal experience supports incremental adoption, making it easy to modernize authentication while maintaining compatibility with existing user access and governance models.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-clear-both"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Get Started with Managed Identities with SMB Azure Files&lt;/H2&gt;
&lt;P&gt;Start using Managed Identities with Azure Files today at no additional cost. This feature is supported on HDD and SSD SMB shares across all billing models. Refer to our&amp;nbsp;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2338790" target="_blank"&gt;documentation&lt;/A&gt; for complete set-up guidance.&lt;/P&gt;
&lt;P&gt;Whether provisioning new storage or enhancing existing deployments, this capability provides secure, enterprise‑grade access with a streamlined configuration experience.&lt;/P&gt;
&lt;P&gt;For any questions, reach out to the team at&amp;nbsp; &lt;A href="mailto:azurefiles@microsoft.com" target="_blank"&gt;azurefiles@microsoft.com.&amp;nbsp;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 17:57:56 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/secure-keyless-application-access-with-managed-identities-now-ga/ba-p/4513053</guid>
      <dc:creator>Priyanka-Gangal</dc:creator>
      <dc:date>2026-04-20T17:57:56Z</dc:date>
    </item>
    <item>
      <title>Simplify On-prem File share Migration to Azure: Discover &amp; assess suitability using Azure Migrate</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/simplify-on-prem-file-share-migration-to-azure-discover-assess/ba-p/4509195</link>
      <description>&lt;H6&gt;&lt;SPAN class="lia-text-color-10"&gt;&lt;STRONG&gt;UPDATE as of 20th May 2026: &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-text-color-10"&gt;&lt;SPAN class="lia-text-color-21"&gt;We are happy to announce that t&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-text-color-21"&gt;his capability is now GA worldwide.&lt;/SPAN&gt;&lt;/H6&gt;
&lt;P&gt;Migrating on‑premises file servers to the cloud is a complex infrastructure transformation—not just a data move. Many organizations lack the visibility needed to decide whether to rehost or modernize file shares spread across Windows and Linux servers. Azure Migrate now extends its &lt;A href="https://learn.microsoft.com/azure/migrate/create-file-share-assessment?view=migrate" target="_blank" rel="noopener"&gt;discovery and assessment capabilities&lt;/A&gt;&amp;nbsp; to SMB and NFS file shares, enabling a data‑driven approach to modernizing on‑premises file workloads with Azure Files, or alternatively rehosting to deployment within an Azure VM.&lt;/P&gt;
&lt;P&gt;We are pleased to introduce the public preview of Azure Migrate’s new &lt;STRONG&gt;comprehensive discovery and assessment of on-premises SMB and NFS file shares for migration to Azure Files&lt;/STRONG&gt;. This enhancement simplifies the migration process by integrating discovery and evaluation tools for SMB and NFS shares across both Windows and Linux platforms. Users can efficiently identify file shares, analyze their compatibility, and compare cost benefits for transitioning to Azure Files, all within an intuitive and streamlined interface.&lt;/P&gt;
&lt;H1&gt;Why does this matter&lt;/H1&gt;
&lt;P&gt;File shares remain a foundational service for most workloads - supporting applications, analytics, user home directories, and shared content. Planning such a vast amount of data for migration can be slow, manual, and fragmented. This new Azure Migrate capability is designed to help with:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Reduce migration planning from months to weeks&lt;/STRONG&gt; through automated discovery and assessment of SMB and NFS file shares.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Perform holistic migration planning &lt;/STRONG&gt;of your data and storage alongside servers, applications and data bases from within Azure Migrate experience.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Modernize confidently to Azure Files&lt;/STRONG&gt; with tailored SKU recommendations, readiness assessments, and comprehensive cost insights, enabling you to build a clear business case by comparing ongoing on-premises and Azure Files costs.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;What’s available in public preview&lt;/H1&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Discover &lt;/STRONG&gt;and view details of all &lt;STRONG&gt;on-premises SMB, NFS shares&lt;/STRONG&gt; hosted on Windows and Linux servers&lt;/LI&gt;
&lt;LI&gt;Group, tag, filter shares by Production, non-production, project, business group for &lt;STRONG&gt;better planning&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Create and review assessment for each share, its &lt;STRONG&gt;target Azure Files SKU&lt;/STRONG&gt; based on region, redundancy, pricing options and media type.&lt;/LI&gt;
&lt;LI&gt;Generate a &lt;STRONG&gt;business case&lt;/STRONG&gt; for selected group of shares running on Azure Files against on-premises cost.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;How do you get this feature? &lt;/STRONG&gt;Install the&lt;STRONG&gt; &lt;/STRONG&gt;latest&lt;STRONG&gt; &lt;/STRONG&gt;Azure Migrate appliance, or enable the &lt;A href="https://learn.microsoft.com/en-us/azure/migrate/migrate-appliance?view=migrate#appliance-upgrades" target="_blank" rel="noopener"&gt;auto update feature&lt;/A&gt; for the appliance will receive this new capability. All existing SMB, NFS file shares will be reported in the Azure Migrate portal along with their Windows and Linux hosts. You do not need to perform any additional steps to discover the shares.&lt;/P&gt;
&lt;H1&gt;End-to-end experience&lt;/H1&gt;
&lt;P&gt;The experience is fully integrated into Azure Migrate and follows a familiar, guided workflow as below.&lt;/P&gt;
&lt;H2&gt;1.&amp;nbsp;&amp;nbsp; Discover on‑premises file servers and file shares&lt;/H2&gt;
&lt;P&gt;You can start by creating an Azure Migrate project in the Azure portal and enabling discovery using the Azure Migrate appliance. The appliance can be deployed in connected or disconnected mode and runs on VMware, Hyper‑V, or physical servers. Once deployed, the appliance automatically discovers file servers and the file shares they host, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Operating system (Windows or Linux)&lt;/LI&gt;
&lt;LI&gt;File share protocol (SMB or NFS)&lt;/LI&gt;
&lt;LI&gt;Associated volumes&lt;/LI&gt;
&lt;LI&gt;Estimated capacity&lt;/LI&gt;
&lt;LI&gt;Basic performance metrics such as IOPS and throughput (when performance collection is enabled)&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Discovered file shares appear directly in Azure Migrate inventory views, where they are surfaced as inventory items under respective Windows or Linux systems. This makes it easy to filter, tag, and review all shares at scale.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H2&gt;2.&amp;nbsp;&amp;nbsp; Build a business case&lt;/H2&gt;
&lt;P&gt;The next step is to create&amp;nbsp;&lt;STRONG&gt;a&lt;/STRONG&gt; &lt;STRONG&gt;business case. &lt;/STRONG&gt;This&lt;STRONG&gt; &lt;/STRONG&gt;offers a clear comparison of on-premises costs versus Azure, highlights long-term savings and operational benefits, and justifies modernizing to Azure Files rather than rehosting file servers on virtual machines. This allows IT leaders to make data-driven decisions confidently.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H2&gt;3.&amp;nbsp;&amp;nbsp; Create and review an Azure Files assessment&lt;/H2&gt;
&lt;P&gt;Once you have finalised your business case and decided to move to Azure Files, you can initiate an &lt;STRONG&gt;Azure Files assessment&lt;/STRONG&gt; right from the Azure Migrate platform. The assessments are adaptable, allowing you to focus solely on file shares, include their parent servers, or even expand to scenarios that cover VMs, databases, and file shares—reflecting real-world planning needs. Each assessment reviews readiness and provides recommendations based on inventory and performance metrics gathered. Furthermore, you can tailor assessment settings, including selecting a target Azure region, pricing and savings preferences, media type, redundancy options, and choosing either performance-based or as-is sizing. The assessment offers a detailed overview of migration readiness and economic factors, supporting well-informed decisions for subsequent actions.&lt;/P&gt;
&lt;P&gt;Key insights include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Readiness states&lt;/STRONG&gt; for each file share (Ready, Ready with conditions, or Not ready)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Recommended Azure Files SKU&lt;/STRONG&gt; based on performance and suitability. For example, Azure Files provisioned v2 premium SSD for a NFS 4.1 share as target.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Monthly cost estimates&lt;/STRONG&gt; for the recommended SKU.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;On‑premises vs Azure TCO comparison&lt;/STRONG&gt;, helping customers understand long‑term cost implications&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Azure Migrate also identifies potential warnings and provides necessary remediation guidance. For example, when a redundancy type is not available in an Azure region, it is flagged as ready with conditions and recommend choosing an alternative redundancy type and fallback to next available option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Prepare for migration with appropriate tools&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Once you are ready to migrate, Azure Migrate also highlights &lt;STRONG&gt;recommended migration tools&lt;/STRONG&gt; as part of the assessment. &lt;STRONG&gt;Azure Storage Mover&lt;/STRONG&gt; is the default recommended path for file share migrations—providing a first party, managed service to move data efficiently to Azure Files. To learn more about Microsoft’s recommendations to unstructured data migration using other tools, please visit: &lt;A href="https://aka.ms/migratemydata" target="_blank" rel="noopener"&gt;https://aka.ms/migratemydata&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Learn more about &lt;A href="https://learn.microsoft.com/en-us/azure/migrate/create-file-share-assessment?view=migrate" target="_blank" rel="noopener"&gt;creation of assessment&lt;/A&gt; and &lt;A href="https://learn.microsoft.com/en-us/azure/migrate/review-file-share-assessment?view=migrate" target="_blank" rel="noopener"&gt;review assessment&lt;/A&gt; to get started with understanding your on-premises file shares estate today. Write to us at &lt;U&gt;migratemydata@microsoft.com&lt;/U&gt; for any questions or feedback - we look forward to hearing from you!&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2026 10:24:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/simplify-on-prem-file-share-migration-to-azure-discover-assess/ba-p/4509195</guid>
      <dc:creator>bapic</dc:creator>
      <dc:date>2026-05-22T10:24:28Z</dc:date>
    </item>
    <item>
      <title>Unlocking AI-Ready Unstructured Data at Scale with Komprise and Azure</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/unlocking-ai-ready-unstructured-data-at-scale-with-komprise-and/ba-p/4507422</link>
      <description>&lt;H1 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Why &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;M&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;ove&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Unstructured Data&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;to Azure&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-21"&gt;On-premises storage environments are often over-provisioned to accommodate future growth, driving&amp;nbsp;costs&amp;nbsp;and operational complexity. Azure’s cloud-based storage platform enables organizations to right-size their environments through elastic scaling and Microsoft’s global economies of scale. This flexibility is especially critical for regulated industries managing sensitive data at&amp;nbsp;massive&amp;nbsp;scale.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-21"&gt;Azure also delivers enterprise-grade security capabilities, including immutability and object locking, which protect data against ransomware and malicious deletion. By moving unstructured data to Azure, organizations gain not only cost efficiency, but also a more resilient and secure data foundation.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-21"&gt;A strong example of this approach is the Florida Department of Environmental Protection. With support from&amp;nbsp;&lt;A class="lia-external-url" href="https://www.komprise.com/partners/microsoft-azure/" target="_blank" rel="noopener"&gt;Komprise&lt;/A&gt;&amp;nbsp;and funding through Microsoft’s&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/migrate/migrate-services-overview?view=migrate-classic" target="_blank" rel="noopener"&gt;Azure Migrate&lt;/A&gt;&amp;nbsp;program, the department successfully migrated large volumes of data to Azure, enabling the phase-out of on-premises data centers while&amp;nbsp;maintaining&amp;nbsp;access to data for analysis across regions. This&amp;nbsp;demonstrates&amp;nbsp;how organizations can modernize data infrastructure without disrupting business operations.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H1 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Hybrid Cloud and Intelligent Tiering&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Most enterprises&amp;nbsp;operate&amp;nbsp;in hybrid environments, balancing on-premises systems with cloud storage.&amp;nbsp;Komprise&amp;nbsp;and Microsoft address this reality by enabling&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/storage/solution-integration/validated-partners/data-management/komprise-tiering-guide" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;intelligent tiering&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;of unstructured data across environments.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Using Azure Blob Storage, organizations can transparently move cold and infrequently&amp;nbsp;accessed&amp;nbsp;data to lower-cost cloud tiers while keeping&amp;nbsp;frequently&amp;nbsp;accessed data close to applications and users. This approach reduces pressure on expensive on-premises storage infrastructure without sacrificing accessibility.&amp;nbsp;For example, a major healthcare organization achieved approximately $2.5&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;million in storage cost savings by tiering cold data to Azure while&amp;nbsp;maintaining&amp;nbsp;seamless access for clinicians and applications.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H1 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;AI&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Depends on&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;D&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;ata&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;C&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;uration&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;AI's efficacy is reliant on data quality.&amp;nbsp;The need for&amp;nbsp;high-quality&amp;nbsp;and&amp;nbsp;curated data&amp;nbsp;cannot be&amp;nbsp;enough emphasized&amp;nbsp;so AI can generate meaningful and&amp;nbsp;accurate&amp;nbsp;results. In partnership with&amp;nbsp;Komprise, organizations can efficiently cleanse and enhance their data by&amp;nbsp;identifying&amp;nbsp;and&amp;nbsp;eliminating&amp;nbsp;redundancies. By curating data before AI processes, organizations have achieved impressive accuracy improvements—as&amp;nbsp;demonstrated&amp;nbsp;by a financial services firm that increased their AI output accuracy by 135%.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H1 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Making Data&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;AI&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;-Ready&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;on Azur&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;e&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Azure provides a powerful execution platform for AI and&amp;nbsp;Komprise&amp;nbsp;enhances this by bringing structure to unstructured data through its data classification, metadata extraction capabilities and with search, curation and intelligent ingestion via its data workflow and governance capabilities. These ensure only high-quality,&amp;nbsp;relevant&amp;nbsp;and compliant data&amp;nbsp;feeds&amp;nbsp;AI workflows.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This approach enables smoother integration with AI services and applications such as Microsoft Foundry and Copilot, while preserving flexibility. By treating data readiness as a foundational step, organizations can accelerate time to value from AI while reducing risk.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H1 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Security&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;,&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;Governance&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;, and Responsible AI&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As cyber threats and regulatory requirements continue to intensify, security and governance are no longer optional. Organizations must manage data flows carefully,&amp;nbsp;maintain&amp;nbsp;auditability, and protect sensitive information—especially when using data for AI.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Azure’s built-in security capabilities, including immutability, versioning, and backup, provide&amp;nbsp;a strong foundation&amp;nbsp;for protecting unstructured data.&amp;nbsp;Komprise&amp;nbsp;complements these capabilities by automating data governance policies, enforcing compliance, and helping organizations&amp;nbsp;maintain&amp;nbsp;visibility and control across hybrid environments. Together, they enable organizations to use data safely and responsibly, supporting both regulatory compliance and responsible AI practices.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H1&gt;&lt;SPAN data-contrast="none"&gt;Conclusion&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As AI adoption accelerates, success increasingly depends on data readiness rather than algorithms alone. Clean, well-governed, and properly placed data is the foundation for meaningful AI outcomes.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;By combining Azure’s scalable and secure cloud platform with&amp;nbsp;Komprise’s&amp;nbsp;intelligent data management, organizations can reduce costs, strengthen security, and unlock real value from unstructured data at scale.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To learn more, watch the Microsoft–Komprise&amp;nbsp;fireside chat, where we discuss customer examples, architectural best practices, and proven approaches for managing unstructured data across hybrid environments. We also invite you to explore our joint Azure and&amp;nbsp;Komprise&amp;nbsp;solutions to see how you can move from data sprawl to AI value while&amp;nbsp;maintaining&amp;nbsp;control, security, and flexibility.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In a recent fireside chat now available on &lt;A class="lia-external-url" href="https://youtu.be/JgQIPJ6jmjA" target="_blank" rel="noopener"&gt;YouTube&lt;/A&gt;, Azure Storage VP Aung Oo joined Komprise COO Krishna Subramanian to explore how Azure and Komprise are empowering customers to mobilize, curate, and optimize unstructured data to make it AI-ready.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To&amp;nbsp;leverage&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/storage/solution-integration/validated-partners/data-management/azure-file-migration-program-solutions" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Storage Migration Program&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;with&amp;nbsp;Komprise&amp;nbsp;to migrate your data to&amp;nbsp;Azure&amp;nbsp;find more information at&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://marketplace.microsoft.com/en-us/product/komprise_inc.intelligent_data_management?tab=Overview%E2%80%8B" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Marketplace&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;To take advantage of&amp;nbsp;the&amp;nbsp;full&amp;nbsp;Komprise&amp;nbsp;suite including automated tiering&amp;nbsp;and&amp;nbsp;smart&amp;nbsp;workflows&amp;nbsp;–&amp;nbsp;additional&amp;nbsp;details&amp;nbsp;are available&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://marketplace.microsoft.com/en-us/product/komprise_inc.intelligent_data_management?tab=Overview%E2%80%8B" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2026 09:53:30 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/unlocking-ai-ready-unstructured-data-at-scale-with-komprise-and/ba-p/4507422</guid>
      <dc:creator>dmalbrough</dc:creator>
      <dc:date>2026-04-02T09:53:30Z</dc:date>
    </item>
    <item>
      <title>Enterprise Identity Meets Secure File Transfer: Entra ID Public Preview on Azure Blob Storage SFTP</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/enterprise-identity-meets-secure-file-transfer-entra-id-public/ba-p/4501937</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-14"&gt;&lt;STRONG&gt;&lt;EM&gt;Updated on June 23 2026: Microsoft Entra ID-based access for Azure Blob Storage SFTP is now Generally Available.&amp;nbsp; GA enhancements: Improved ABAC by resolving inconsistencies with the Storage Blob Data Owner role (eliminating timeout issues) while adding support for sub-operations to enable more granular access control. Learn more &lt;A href="https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support-entra-id-based-access?tabs=azurecli" target="_blank"&gt;here&lt;/A&gt;.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are excited to announce&amp;nbsp;&lt;A href="https://learn.microsoft.com/azure/storage/blobs/secure-file-transfer-protocol-support-entra-id-based-access?" target="_blank" rel="noopener"&gt;the public preview of Entra ID-based access&lt;/A&gt; for &lt;A href="https://learn.microsoft.com/azure/storage/blobs/secure-file-transfer-protocol-support" target="_blank" rel="noopener"&gt;Azure Blob Storage SFTP&lt;/A&gt;. This new capability enables you to use Microsoft Entra ID (formerly Azure Active Directory) identities (including guest users via Entra External Identities) to securely connect to Azure Blob Storage via SFTP without needing local users. This feature eliminates the operational overhead of managing local SFTP users and passwords by introducing enterprise-grade identity management powered by Microsoft Entra ID.&lt;/P&gt;
&lt;P&gt;For IT administrators and security teams, this means no more creating, tracking, rotating, or decommissioning local SFTP credentials. For developers and architects, it means seamless integration with your existing identity infrastructure. For business users, it means faster, more secure access to the data they need, all while maintaining compliance with enterprise security policies.&lt;/P&gt;
&lt;H1&gt;Azure Blob Storage SFTP&lt;/H1&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/azure/storage/blobs/secure-file-transfer-protocol-support-connect" target="_blank" rel="noopener"&gt;Azure Blob Storage SFTP&lt;/A&gt; natively enables secure file access and management without third-party solutions. This simplifies operations for customers and removes the need for complex, custom SFTP solutions. Until this Public Preview, Azure Blob Storage SFTP utilized a form of identity management called&amp;nbsp;&lt;EM&gt;local users &lt;/EM&gt;as the only authorization mechanism. Local users must use either a password or a Secure Shell (SSH) private key credential for authentication. Learn more about local users&amp;nbsp;&lt;A href="https://learn.microsoft.com/azure/storage/blobs/secure-file-transfer-protocol-support#sftp-permission-model" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;H1&gt;The Challenge: SFTP Local User Management&lt;/H1&gt;
&lt;P&gt;Organizations currently face challenges when managing SFTP access at scale with Azure Storage SFTP Local Users. Local User based SFTP access require IT teams to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Manually create and provision local user accounts for each SFTP user&lt;/LI&gt;
&lt;LI&gt;Generate, distribute, and securely store SSH keys or passwords&lt;/LI&gt;
&lt;LI&gt;Implement custom workflows for lifecycle management&lt;/LI&gt;
&lt;LI&gt;Manage offboarding processes to ensure departed users lose access immediately&lt;/LI&gt;
&lt;LI&gt;Audit and track access across disconnected identity silos&lt;/LI&gt;
&lt;LI&gt;Handle external partner and vendor access through ad-hoc, often insecure methods&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;The Solution: Enterprise Identity Meets Secure File Transfer&lt;/H1&gt;
&lt;P&gt;With Entra ID-based access for Azure Blob Storage SFTP, you can now leverage your organization's centralized identity platform to authenticate and authorize SFTP users. This integration brings the full power of Microsoft Entra ID to your file transfer workflows, delivering the following benefits:&lt;/P&gt;
&lt;H3&gt;1. Eliminate Local User Management&lt;/H3&gt;
&lt;P&gt;Simplify SFTP management by assigning access with Entra ID—no separate SFTP accounts needed.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;No local credential generation or distribution—users authenticate with their existing corporate credentials&lt;/LI&gt;
&lt;LI&gt;No orphaned accounts when users change roles or leave the organization&lt;/LI&gt;
&lt;LI&gt;Reduced attack surface by eliminating static, long-lived local credentials&lt;/LI&gt;
&lt;LI&gt;Centralized user lifecycle management through your existing identity platform&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;2. Enterprise-Grade Identity and Security&lt;/H3&gt;
&lt;P&gt;Leverage the full security capabilities of Microsoft Entra ID for your SFTP infrastructure:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Multi-Factor Authentication (MFA): Require additional verification factors beyond passwords, significantly reducing the risk of account compromise&lt;/LI&gt;
&lt;LI&gt;Conditional Access: Define policies that grant or block access based on user location, device compliance, sign-in risk, and other conditions&lt;/LI&gt;
&lt;LI&gt;Identity Protection: Benefit from Microsoft threat intelligence and risk detection to identify and respond to compromised accounts&lt;/LI&gt;
&lt;LI&gt;Privileged Identity Management (PIM): Provide just-in-time elevated access for administrative operations&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;3. Native Azure RBAC, ABAC, and ACL Integration&lt;/H3&gt;
&lt;P&gt;Your SFTP access control seamlessly integrates with Azure comprehensive authorization framework:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Role-Based Access Control (RBAC): Assign built-in or custom roles at the storage account, container, or even blob level&lt;/LI&gt;
&lt;LI&gt;Attribute-Based Access Control (ABAC): Create sophisticated access policies based on resource tags, user attributes, and environmental conditions&lt;/LI&gt;
&lt;LI&gt;Access Control Lists (ACLs): Apply fine-grained permissions at the directory and file level for hierarchical namespace-enabled accounts&lt;/LI&gt;
&lt;LI&gt;Unified Permission Model: SFTP access respects the same permissions as REST API, Azure CLI, and other access methods—no separate permission system to manage&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;4. Faster SFTP Onboarding and Time-to-Value&lt;/H3&gt;
&lt;P&gt;Onboard new SFTP users or partners in minutes instead of hours or days, saving significant time and boosting business agility.&lt;/P&gt;
&lt;H3&gt;5. Secure External Collaboration with Entra External Identities&lt;/H3&gt;
&lt;P&gt;Seamlessly enable secure external SFTP access by allowing partners to authenticate with their own credentials using Entra External Identities (Azure AD B2B).&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;External users authenticate with credentials they already manage&lt;/LI&gt;
&lt;LI&gt;Full audit trail of external user activity&lt;/LI&gt;
&lt;LI&gt;Ability to apply Conditional Access policies to external users&lt;/LI&gt;
&lt;LI&gt;Automatic access revocation when B2B relationships end&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Real World Scenarios&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Financial Services:&lt;/STRONG&gt; A bank receives daily transaction files from merchants via SFTP. Merchants authenticate with their own Entra ID credentials (B2B collaboration), MFA is enforced, and access is restricted to assigned directories. Access is instantly revoked when a merchant is removed from the B2B directory.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Healthcare:&lt;/STRONG&gt; A hospital exchanges patient data with insurers and labs. Entra ID authentication ensures only authorized staff access sensitive PII, with full audit logs for HIPAA compliance. Conditional Access restricts connections to approved locations and devices.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Media &amp;amp; Entertainment:&lt;/STRONG&gt; A production company enables freelance editors and agencies to transfer large media files. Entra External Identities provide time-limited access and automatic revocation when projects end—no need for local SFTP accounts.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Manufacturing:&lt;/STRONG&gt; A manufacturer receives CAD files and orders from suppliers using SFTP. With Entra ID, suppliers use unified credentials and access policies across all systems, streamlining supply chain management.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;How It Works&lt;/H1&gt;
&lt;P&gt;Entra ID simplifies SFTP access to Azure Blob Storage by authenticating users with their corporate credentials. After authentication, users receive a short-lived Open SSH certificate to connect. The service verifies certificate validity and user permissions, enabling secure file operations and automatic access revocation in line with current identity policies. Learn more &lt;A href="https://learn.microsoft.com/azure/storage/blobs/secure-file-transfer-protocol-support-entra-id-based-access?#overview" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;H1&gt;Getting started with the Public Preview &amp;nbsp;&lt;/H1&gt;
&lt;P&gt;We encourage you to try Entra ID-based access for Azure Blob Storage SFTP in your non-production environments today. Learn more about how to register for the preview and get started with the detailed ms docs learn guide &lt;A href="https://learn.microsoft.com/azure/storage/blobs/secure-file-transfer-protocol-support-entra-id-based-access?#connecting-to-azure-blob-storage-with-microsoft-entra-ids" target="_blank" rel="noopener"&gt;here&lt;/A&gt;. &amp;nbsp;This preview gives you an opportunity to shape the feature development by providing feedback on what works well and what could be improved.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Note: Local user accounts for SFTP access are still supported, but we strongly recommend switching to Entra ID-based access for greater security, simpler management, and automatic access control. &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Questions or feedback? &lt;/STRONG&gt;We would love to hear from you! Reach out to our team at blobsftp@microsoft.com&lt;/P&gt;
&lt;P&gt;We are excited to bring enterprise-grade identity management to Azure Blob Storage SFTP, and we cannot wait to see how you use this capability to simplify operations, enhance security, and enable new collaboration scenarios.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Happy transferring!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 12:50:37 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/enterprise-identity-meets-secure-file-transfer-entra-id-public/ba-p/4501937</guid>
      <dc:creator>JeevanManoj</dc:creator>
      <dc:date>2026-06-23T12:50:37Z</dc:date>
    </item>
    <item>
      <title>Understanding the Standard HDD I/O unit size update and what it means for your workloads</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/understanding-the-standard-hdd-i-o-unit-size-update-and-what-it/ba-p/4499128</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As Azure continues to evolve to support modern workload patterns, we are refining how transactions are measured for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Standard HDD Managed Disks&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. This update helps align billing more closely with actual I/O behavior while&amp;nbsp;maintaining&amp;nbsp;predictable cost controls for customers.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In this post,&amp;nbsp;we’ll&amp;nbsp;walk through what’s changing, how transaction billing is calculated, and what this may mean for your workloads.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With this update, the number of billable transactions for select Standard HDD disk sizes (S4, S6) will be measured using&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;16 KiB I/O units&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;I/O operations&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;≤ 16 KiB&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;count as&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;one billable transaction&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;I/O operations &lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;gt; 16 KiB&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt; are counted as multiple billable transactions&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Example&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;A&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;64 KiB&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;read/write on an S4 disk =&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;4 billable transactions&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;A &lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;4 KiB&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;read/write&amp;nbsp;on an S4 disk&amp;nbsp;=&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;1 billable transaction&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This update provides more consistent alignment between workload behavior and transaction&amp;nbsp;billing.&amp;nbsp;For latest information on&amp;nbsp;regional availability, please refer to&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/virtual-machines/disks-understand-billing#standard-hdd-transactions" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Standard HDD Managed Disks documentation.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN data-contrast="auto"&gt;Built-in transaction caps to help manage costs&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To&amp;nbsp;maintain&amp;nbsp;predictable cost boundaries, Azure&amp;nbsp;will&amp;nbsp;implement&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;hourly caps on billable transactions&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;for&amp;nbsp;the&amp;nbsp;Standard HDD disk&amp;nbsp;sizes&amp;nbsp;with an I/O unit size.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If a disk exceeds its hourly cap,&amp;nbsp;additional&amp;nbsp;transactions in that hour are&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;not billed&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;The transaction caps are listed below and on the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://azure.microsoft.com/en-us/pricing/details/managed-disks/#pricing" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Disks Pricing Page&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Disk&amp;nbsp;Size&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Disk&amp;nbsp;GiB&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Hourly Billable Transaction Cap&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;S4&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;32 GiB&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;450,000&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;S6&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;64 GiB&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;858,000&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These caps help provide cost predictability, particularly for bursty workloads.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Understanding potential cost impact&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:299,&amp;quot;335559739&amp;quot;:299}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Workloads with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;larger I/O sizes and sustained IOPS&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;may see changes in&amp;nbsp;the number of billed transactions on their invoice. Workloads with small or infrequent I/O operations may see little to no impact.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="auto"&gt;Determining&amp;nbsp;your workload’s cost&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The&amp;nbsp;following table&amp;nbsp;lists&amp;nbsp;three different&amp;nbsp;examples&amp;nbsp;to&amp;nbsp;illustrate how transaction billing*&amp;nbsp;compares for&amp;nbsp;different&amp;nbsp;IO load&amp;nbsp;intensities&amp;nbsp;on an&amp;nbsp;S4 Standard HDD disk vs. an E4 Standard SSD disk. Assume the disks are in Central US region.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN lia-align-left"&gt;&lt;table border="1" style="width: 100%; height: 598px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr style="height: 67px;"&gt;&lt;td style="height: 67px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Workload&amp;nbsp;Average&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 67px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Billable Transactions / hour on Standard HDD&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 67px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Billable Transactions / hour on Standard SSD&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 67px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Total Cost on Standard HDD&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 67px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Total Cost on Standard SSD&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 255px;"&gt;&lt;td class="lia-align-left" style="height: 255px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN data-contrast="auto"&gt;Low&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;4 KiB workload, 10 IOPS&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left" style="height: 255px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;36,000&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;(10 billable transactions * 60 seconds * 60 minutes)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left" style="height: 255px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;36,000 &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;(10 billable transactions * 60 seconds * 60 minutes)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left" style="height: 255px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;$2.85/mo&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;(36,000 * 730 hours * $0.0005 / 10,000 transactions) = $1.31 Transaction cost&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;$1.31 + $1.54 capacity/mo &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;cost = $2.85/mo&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left" style="height: 255px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;$7.66/mo&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;(36,000 * 730 hours * $0.002 / 10,000 transactions) = $5.26 Transaction cost &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;$5.26 + $2.40 capacity/mo cost = $7.66/mo&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 133px;"&gt;&lt;td class="lia-align-left" style="height: 133px;"&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Medium&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;32 KiB workload, 20 IOPS&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left" style="height: 133px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;144,000&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;(40 billable transactions with the IO Unit Size * 60 * 60)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left" style="height: 133px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;43,400&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;(after Standard SSD transaction cap)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left" style="height: 133px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;$6.80/mo&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left" style="height: 133px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;$8.73/mo&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 143px;"&gt;&lt;td class="lia-align-left" style="height: 143px;"&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;High&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;64 KiB&amp;nbsp;workload,&amp;nbsp;40 IOPS&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left" style="height: 143px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;450,000&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;(after Standard HDD transaction cap)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left" style="height: 143px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;43,400&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;(after Standard SSD transaction cap)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left" style="height: 143px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;$17.97/mo&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left" style="height: 143px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;$8.73/mo&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 20.2029%" /&gt;&lt;col style="width: 19.8342%" /&gt;&lt;col style="width: 18.9064%" /&gt;&lt;col style="width: 20.9453%" /&gt;&lt;col style="width: 20.1112%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;*Any operation against the storage is counted as a transaction,&amp;nbsp;including&amp;nbsp;reads, writes, and&amp;nbsp;deletes. Host caching being enabled might affect the number of transactions against the storage that are counted.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN data-contrast="auto"&gt;Choosing the right disk for your workload&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Running workloads on SSD-based disk types may also unlock higher availability, higher reliability, more consistent performance, and lower latency.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;For OS disks running on Standard HDD, consider migrating to Standard SSD&amp;nbsp;or Premium SSD&amp;nbsp;Managed Disks.&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/virtual-machines/disks-hdd-os-retirement" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Standard HDD OS disks will be retired&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;in September 2028.&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;For non-OS disk workloads, consider high performance and flexible provisioning benefits of Premium SSD v2 Managed Disks, or benefits of Standard SSD or Premium SSD Managed Disks.&amp;nbsp;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://learn.microsoft.com/en-us/azure/virtual-machines/disks-types" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Learn more here about the different disk types and their benefits.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;To learn more about switching your disk types, &lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://learn.microsoft.com/en-us/azure/virtual-machines/disks-convert-types?tabs=azure-powershell" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;view our documentation page.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To learn more about the billing changes, view the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://azure.microsoft.com/en-us/pricing/details/managed-disks/#pricing" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Pricing Page&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/virtual-machines/disks-understand-billing#standard-hdd" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;documentation for Standard HDD Managed Disks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2026 15:18:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/understanding-the-standard-hdd-i-o-unit-size-update-and-what-it/ba-p/4499128</guid>
      <dc:creator>austin-ma</dc:creator>
      <dc:date>2026-04-22T15:18:03Z</dc:date>
    </item>
    <item>
      <title>Public Preview: Restrict usage of user delegation SAS to an Entra ID identity</title>
      <link>https://techcommunity.microsoft.com/t5/azure-storage-blog/public-preview-restrict-usage-of-user-delegation-sas-to-an-entra/ba-p/4497196</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Shared access signatures (SAS) grant time-bound, scoped access to Azure Storage resources without sharing account keys. Over time, Azure Storage has continued to strengthen SAS security,&amp;nbsp;moving from account&amp;nbsp;keys to&amp;nbsp;user delegation&amp;nbsp;(UD)&amp;nbsp;SAS&amp;nbsp;secured&amp;nbsp;by Microsoft Entra ID.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Today,&amp;nbsp;we’re&amp;nbsp;taking the next step forward&amp;nbsp;by announcing&amp;nbsp;public&amp;nbsp;preview&amp;nbsp;for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;user-bound user delegation SAS&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;, an extension of&amp;nbsp;UD&amp;nbsp;SAS that ensures a SAS token can only be used by a specific Entra&amp;nbsp;ID&amp;nbsp;identity. This new capability helps customers significantly reduce the risk of unintended access&amp;nbsp;while preserving the flexibility&amp;nbsp;of&amp;nbsp;SAS.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;UD SAS&amp;nbsp;is an&amp;nbsp;existing&amp;nbsp;feature which&amp;nbsp;utilizes Entra ID and Azure role-based access control (RBAC). Users retrieve a user delegation key tied to their Entra ID account and then use it to create SAS tokens granting a subset of their own access rights.&amp;nbsp;The resulting token can be traced to the delegator and can only be valid for up to 7 days.&amp;nbsp;User-bound&amp;nbsp;UD SAS&amp;nbsp;is an extension of user delegation&amp;nbsp;(UD)&amp;nbsp;SAS&amp;nbsp;which&amp;nbsp;allows&amp;nbsp;users to create a more secure SAS token by&amp;nbsp;restricting the usage of&amp;nbsp;the SAS token to&amp;nbsp;an end user&amp;nbsp;identity.&amp;nbsp;The delegator&amp;nbsp;specifies&amp;nbsp;the Entra identity (security principal) of the end user in the SAS&amp;nbsp;token&amp;nbsp;and&amp;nbsp;the end user&amp;nbsp;needs to&amp;nbsp;authenticate&amp;nbsp;to&amp;nbsp;Entra&amp;nbsp;ID&amp;nbsp;to use the token. The end user can either be in the same tenant or a different tenant as the delegator.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Pricing and availability&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:360,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;There is no&amp;nbsp;additional&amp;nbsp;cost for user-bound user&amp;nbsp;delegation&amp;nbsp;SAS. Pricing is based on the standard read/write transaction costs for your storage account&amp;nbsp;type. To learn more, please see&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://azure.microsoft.com/pricing/details/storage/blobs/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Azure Storage Pricing.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;User-bound user delegation SAS is in preview in all&amp;nbsp;public&amp;nbsp;regions. This preview will be available via&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/rest/api/storageservices/get-user-delegation-key" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;REST APIs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/storage/blobs/storage-blob-user-delegation-sas-create-dotnet?tabs=packages-dotnetcli%2Ccontainer" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;SDKs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/storage/blobs/storage-blob-user-delegation-sas-create-powershell" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;PowerShell&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;, and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/storage/blobs/storage-blob-user-delegation-sas-create-cli" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;CLI&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;experiences.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Getting started&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:360,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Getting started is simple:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;User-bound user&amp;nbsp;delegation&amp;nbsp;SAS is available&amp;nbsp;on&amp;nbsp;all GPv2 storage&amp;nbsp;accounts&amp;nbsp;in public regions.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;If&amp;nbsp;the&amp;nbsp;end&amp;nbsp;user of the&amp;nbsp;SAS&amp;nbsp;token&amp;nbsp;is&amp;nbsp;in a&amp;nbsp;different&amp;nbsp;tenant, the&amp;nbsp;allowCrossTenantDelegationSas&amp;nbsp;setting must be enabled on the storage account. If you are not planning&amp;nbsp;on using&amp;nbsp;this feature cross-tenant,&amp;nbsp;the account setting&amp;nbsp;can remain&amp;nbsp;disabled.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Perform the following steps in the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas#construct-a-user-delegation-sas" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;create a user delegation SAS documentation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;to generate and use a&amp;nbsp;user-bound&amp;nbsp;UD SAS token:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="Aptos" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Ensure you have the correct RBAC roles assigned&amp;nbsp;to the delegator&amp;nbsp;to create a user delegation key. These roles will include the Storage &amp;lt;Service&amp;gt; Data Contributor and Storage &amp;lt;Service&amp;gt; Delegator (replace Service with the respective service you are using). Here are&amp;nbsp;all of&amp;nbsp;the applicable roles for each service:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Azure Blob&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Azure Table&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Azure Files&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Azure Queue&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Storage Blob Data Contributor&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Storage Table Data Contributor&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Storage Files Data Contributor&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Storage Queue Data Contributor&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Storage Blob Delegator&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Storage Table Delegator&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Storage Files Delegator&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Storage Queue Delegator&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="Aptos" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Get a user delegation key (instructions&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas#request-the-user-delegation-key" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;)&lt;/SPAN&gt; &lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="Aptos" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;Get the OAuth object ID and tenant ID from your end user. They will have to get these IDs (instructions&amp;nbsp;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://learn.microsoft.com/en-us/partner-center/account-settings/find-ids-and-domain-names#find-the-user-object-id" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="none"&gt;) and provide them to you.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="Aptos" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;Create the user-bound user delegation SAS token (instructions&amp;nbsp;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas#construct-a-user-delegation-sas" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="none"&gt;. Note that the steps are the same as for a normal UD SAS token; you will just have to specify the end user and tenant if applicable).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="Aptos" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;Share the SAS token to the application/user intended to access Azure Storage.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="Aptos" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;Tokens should be passed within applications automatically or shared via key vault for best practice.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Fee&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;dbac&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;k&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:360,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;If you have questions or feedback, please fill out this&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://forms.office.com/Pages/DesignPageV2.aspx?origin=NeoPortalPage&amp;amp;subpage=design&amp;amp;id=v4j5cvGGr0GRqy180BHbR9iuLyDgXDNIkMaAAVSMpJxUOTNNNDFGTVZIUTdRU0w0Qjg0QjdTSlNSNy4u" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;feedback form.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;If you need help, create a&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://portal.azure.com/#blade/Microsoft_Azure_Support/HelpAndSupportBlade/newsupportrequest" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;support request.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 22:43:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/azure-storage-blog/public-preview-restrict-usage-of-user-delegation-sas-to-an-entra/ba-p/4497196</guid>
      <dc:creator>ellievail</dc:creator>
      <dc:date>2026-03-03T22:43:07Z</dc:date>
    </item>
  </channel>
</rss>

