Azure File Share: Integrating DFS-N with AD DS Over SMB


Hello everyone, this is Andrew Coughlin again and I am a Customer Engineer at Microsoft.  A question I get asked is can you use Distribute File System Namespaces (DFS-N) with an Azure File Share.  In this blog I will explain how to do this by focusing on how to integrate DFS-N with Azure File Shares with AD DS over . On June 11, 2020 Domain Services (AD DS) over for Azure file shares was released.  

Enabling AD DS for your Azure Files Shares allows you to use your on-premises credentials.  This does require the synchronization of on-premises users into Azure , and gives the ability to control share level access via Azure while controlling the file system permissions with Active Directory Domain Services.

Using Active Directory authentication for Azure Files over gives the ability to use Azure Files as a replacement for traditional file servers. This gives customers the ability to shift their file services to Azure and retire their on-premises file servers.


  • Connectivity from your on-premises locations to Azure.
  • Ensure these steps have been completed before setting up the storage account.
  • Create a storage account as documented here, then create a Azure File Share as documented here.
  • Storage account that has Active Directory Domain Services Enabled.
  • DFS Namespace created as documented here.

Verify Azure File Share

First, we want to confirm permissions are setup correctly and the share does exist.  To do this we will do the following:

  1. Launch Windows Explorer.
  2. Type the storage account service endpoint with the share, example:


Create DFS Namespace

  1. Click Start > Click Server Manager.
  2. In Server Manager, click Tools > DFS Management.
  3. Right click on Namespaces and click Add Namespaces to Display…


  1. Select the Namespace you are going to add the Azure File share to.


  1. Right click the name space once added, then click New Folder.


  1. Provide the name of the new folder and click Add.


  1. Type the storage account service endpoint, then click OK.


NOTE: You should not click Browse as in doing so will generate an error message when trying to enumerate shares on the server.  Since the storage account is not , we won't be able to enumerate the shares on the storage account as of writing this article.

  1. Click OK, on the New folder window.



With the above steps we just setup a new dfs namespace share that your end users can navigate to. 

Verify DFS Namespace Share

  1. Next, we want to verify the DFS Namespace folder we just created. 
  2. Launch File Explorer.
  3. Type the DFS Namespace and share name, example: dfsnamespace.localpublic


  1. Select the folder we just created in the above steps.



In this post I have covered how to integrate DFS-N with Azure File Shares with Active Directory Domain Services authentication over SMB..  I hope you have found this article helpful and thank you for taking the time to read this post.


This article was originally published by Microsoft's Core Infrastructure and Security Blog. You can find the original article here.