Domain Join Storage Account
The script uses the cmdlet to create a computer account in your ad domain.
Domain join storage account. Overview on premises active directory domain services authentication over smb for azure file shares 09 13 2020 5 minutes to read 5 in this article azure files supports identity based authentication over server message block smb through two types of domain services. To join a computer to the domain the user account must be granted the create computer object permission in active directory. Once you ve enabled active directory domain services ad ds authentication on your storage account you must configure share level permissions in order to get access to your file shares. About press copyright contact us creators advertise developers terms privacy policy safety how youtube works test new features.
The join azstorageaccountforauth cmdlet performs the equivalent of an offline domain join on behalf of the specified storage account. You can host your domain controllers on azure vms or on premises. For example you can use the domain administrator account or an account with delegated permissions to join computers to the domain. In the settings section select configuration.
Portal powershell azure cli to enable azure ad ds authentication over smb with the azure portal follow these steps. Having the ability to active directory domain join adds an azure storage account has changed the game for many organizations deploying file service into azure. Either way your domain joined clients must have line of sight to the domain service so they must be within the corporate network or virtual network vnet of your domain service. Additionally make sure that the specified user account is allowed to log on locally to the client computer.
Join azstorageaccountforauth resourcegroupname resource group name name storage account name domainaccounttype computeraccount organizationalunitname ou friendly name when the string ran successfully you will see the following computer account named as your azure storage account created in your active directory ad environment. On premises active directory domain services ad ds and azure active directory domain services azure ad ds. In the azure portal go to your existing storage account or create a storage account. For on premises ad ds authentication you must set up your ad domain controllers and domain join your machines or vms.
Under identity based access for file shares switch the toggle for azure active directory domain service aad ds to enabled.