Microsoft Certified: Azure Administrator AssociateImplement and manage storageMedium

A company is migrating its on-premises file servers to Azure File Shares. The company requires that users authenticate to the Azure File Shares using their existing Active Directory (AD) domain credentials, and that permissions are managed using standard NTFS ACLs. Which authentication method should be configured for the Azure File Share?

  1. AShared Key authentication
  2. BStorage Account Access Keys
  3. CAzure Active Directory Domain Services (Azure AD DS) authentication
  4. DAzure Active Directory (Azure AD) authentication
Show answer & explanation

Correct answer: C. Azure Active Directory Domain Services (Azure AD DS) authentication

Azure AD Domain Services (Azure AD DS) authentication for Azure Files provides domain-join capabilities for Azure File Shares, allowing virtual machines (VMs) joined to the Azure AD DS managed domain to access file shares using AD credentials and NTFS ACLs, replicating the on-premises experience.

Why the other options are wrong

  • A. Shared Key authentication uses the storage account key, which is not compatible with AD domain credentials or NTFS ACLs.
  • B. Storage Account Access Keys are the same as Shared Key authentication and do not support AD domain credentials or NTFS ACLs.
  • D. Azure AD authentication is for cloud-native AD identities, not for traditional AD domain services or NTFS ACLs directly.

Azure Files AD DS Authentication

Azure Active Directory Domain Services (Azure AD DS) authentication allows domain-joined Windows VMs to mount and access Azure File Shares using Active Directory credentials and to enforce directory and file-level permissions with NTFS ACLs.

  • Enables traditional domain-based authentication for Azure Files.
  • Supports NTFS ACLs for granular permissions.
  • Requires an Azure AD DS managed domain.

Memory trick: AD DS bridges on-prem to Azure Files.

More Implement and manage storage questions