Azure File Sync Managed Identity - Improved and Simplified Security and Operations

THE SUMMARYAI-generated

Key Concepts

  • Azure File Sync
  • Server Endpoints
  • Cloud Endpoint (Azure File Share)
  • Storage Sync Service
  • File Sync Agent
  • Sync Group
  • Managed Identities (System Assigned)
  • Azure Arc for Servers
  • Shared Access Signatures (SAS)
  • Role-Based Access Control (RBAC)
  • Entra ID (formerly Azure Active Directory)

Azure File Sync Overview

Azure File Sync enables the synchronization of on-premises Windows file shares (server endpoints) with an Azure file share (cloud endpoint) within a storage account. A Storage Sync Service orchestrates this process. The file sync agent is installed on each Windows file server, registering them with the Storage Sync Service. A sync group consists of one cloud endpoint and up to 100 server endpoints. Data synchronizes between server endpoints via the cloud endpoint. This provides capabilities like multiple on-premises copies, cloud backup for disaster recovery, and cloud tiering (least used content is offloaded to Azure).

The Challenge with Traditional Authentication

Previously, Windows file servers authenticated to the Storage Sync Service using certificates. Communication between the file servers/Storage Sync Service and the Azure file share relied on Shared Access Signatures (SAS). This approach required managing certificates (including rotation) and SAS keys. Certificate validation also necessitated opening specific URLs on the server endpoints.

Managed Identities: A Solution

Managed identities eliminate the need for certificate and SAS key management. A system-assigned managed identity is a one-to-one identity tied to an Azure resource (e.g., a VM). Entra ID creates and manages this identity. Processes running within the resource can request a token for the identity, which can then be granted access to other Azure resources.

Leveraging Managed Identities with Azure File Sync

The goal is to replace certificate-based authentication and SAS with Entra ID-integrated authentication using managed identities. This applies to both server endpoint authentication to the Storage Sync Service and data plane communication to the Azure file share.

New Storage Sync Service Deployments

Creating a new Storage Sync Service now defaults to using managed identities. This enhances security by eliminating SAS keys and simplifying certificate management.

Migrating Existing Deployments to Managed Identities

Migrating existing deployments requires a few steps:

  1. Azure File Sync Agent Version: Ensure all registered servers have Azure File Sync agent version 20.0.0.0 or higher.
  2. Enable Managed Identities on Server Endpoints:
    • Azure VMs: If the Windows file server is running in an Azure VM, enable the system-assigned managed identity on the VM.
    • On-Premises Servers: For servers outside of Azure, use Azure Arc for Servers to extend the Azure control plane. Arc-enabling the server allows you to enable a system-assigned managed identity. The file sync agent can also be deployed as an Azure Arc extension.
  3. Enable Managed Identities on the Storage Sync Service: In the Azure portal, navigate to the Storage Sync Service and enable the "Managed Identity" option. The portal will perform a check to determine how many registered servers have a managed identity.

Automatic Permissioning (RBAC)

Enabling managed identities on the Storage Sync Service triggers several actions:

  1. The Storage Sync Service is enabled with a system-assigned managed identity.
  2. RBAC permissions are automatically set on the Storage Sync Service and the Azure file share. This grants the necessary permissions to the server endpoints' and Storage Sync Service's managed identities.

The specific permissions granted are:

  • Storage Sync Service system-assigned identity: Storage Account Contributor role.
  • Storage Sync Service identity: Storage File Data Privileged Contributor role.
  • Registered servers: Storage File Data Privileged Contributor role.

Resetting Permissions

In certain scenarios (e.g., resource moves, policy deletions, manual configuration), RBAC permissions may need to be reset. The documentation outlines the required permissions. PowerShell commandlets are available to reset permissions on the cloud endpoint (Set-StorageSyncCloudEndpointPermission) and server endpoints. Verbose mode provides detailed information about role assignments.

Hybrid Environments

Server endpoints without managed identities will continue to use server certificates. However, the recommendation is to migrate all endpoints to managed identities.

Benefits of Managed Identities

  • Improved Security: Eliminates the risk associated with leaked SAS keys and simplifies certificate management.
  • Simplified Network Configuration: Removes the need to open specific URLs for server certificate validation.
  • No Loss of Functionality: Switching to managed identities does not impact existing features.

Conclusion

Migrating to managed identities for Azure File Sync simplifies management, enhances security, and streamlines network configuration. The key step is enabling managed identities on the server endpoints, either directly on Azure VMs or via Azure Arc for Servers for on-premises machines. The Azure portal automates the permissioning process, making the transition relatively straightforward.

AI summaries can miss context or contain errors. Check important details against the original video.

MAKE IT YOURS

Read. Remember. Reuse.

Free tools

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.