Azure Files Setup implements a cloud file sharing solution on Azure, integrated with the customer's existing infrastructure, providing up to 100 TB of high-performance share space and up to 200 point-in-time backup snapshots. The solution supports Kerberos authentication either through on-premises Active Directory, leveraging hybrid identities, or through Microsoft Entra ID.
Thanks to these integrations, Azure Files offers a secure and scalable cloud alternative to traditional on-premises file servers, enabling data access through the SMB 3.0 protocol (port 445).
Microsoft Azure and Microsoft 365 licenses, together with any required tools, are not included and remain the customer's responsibility. In particular, licenses required for authentication (such as Microsoft Entra ID P1) and Azure usage costs (storage, data traffic, backup) remain the customer's responsibility. What the implementation includes Configuration of a dedicated Azure Files storage account, selecting the optimal type (Standard or Premium) and redundancy (LRS/ZRS or GRS/GZRS) based on performance and resilience requirements.
Implementation of the Azure Files share with integrated user authentication through Kerberos.
Agreement on one of two authentication scenarios: authentication based on on-premises Active Directory (AD DS), with access controlled by on-premises domain controllers and domain-joined clients; or authentication based on Microsoft Entra ID Kerberos, supporting Microsoft Entra-joined or Hybrid AD-joined clients without a mandatory VPN.
Configuration of a Recovery Services Vault for file backup, using incremental snapshots for fast restore of individual files or folders, with short and long-term retention.
Activation of file share soft-delete, providing automatic 14-day retention as protection against accidental deletions.
For Microsoft Entra ID authentication scenarios, configuration of a dedicated Conditional Access policy to allow file share access without requiring interactive MFA, following Microsoft best practices for Microsoft Entra Kerberos.
Delivery of operational documentation and a handover session covering file share usage, permission (ACL) management, and backup restore operations. Deliverables Configured Azure Files storage account with agreed redundancy.
Implemented file share with Kerberos authentication.
Configured Recovery Services Vault with snapshot-based backup.
Soft-delete enabled on the file share.
Conditional Access policy configured, where Microsoft Entra ID authentication is used.
Operational documentation and handover session. Customer requirements Active Azure subscription.
Active Microsoft Entra ID tenant, and on-premises Active Directory if the AD DS scenario is selected.
Microsoft Entra ID P1 license for each user accessing the file share, where Microsoft Entra ID Kerberos is used.
Network connectivity to domain controllers, if hybrid identities or the AD DS scenario are used.
Required administrative access on the Azure subscription and identity environment.
Licenses, tools, certifications, and software beyond what is listed are not included unless otherwise specified. This service does not include migration of existing file server data, redesign of the customer's identity architecture, management of on-premises Active Directory infrastructure, or ongoing operational management of the file share after the handover session.
(0)Comments