Skip to content
Azure Files Goes Cloud-Native with Entra-Only Identities and Managed Identities

Azure Files Goes Cloud-Native with Entra-Only Identities and Managed Identities

Written By Anoop C Nair
Last Updated July 1, 2026
Posted In Azure
SHARE

Key Takeaways

  • Azure Files SMB now supports Entra-Only identities with General Availability (GA), enabling cloud-native identity-based access using Microsoft Entra ID.
  • Organizations no longer need on-premises Active Directory, hybrid sync, or managed domain controllers for Azure Files authentication.
  • The feature helps simplify infrastructure, reduce management overhead, and lower maintenance costs while supporting Zero Trust security principles.
  • Azure Virtual Desktop (AVD) environments can use Entra-Only identities for FSLogix profiles, including B2B access for external partners without duplicate accounts.
  • Users can securely access Azure Files from anywhere without VPNs, domain setup, or complex networking, making cloud migration easier for Windows-based workloads.

Managed Identity and Entra-Only identities for Azure Files help organizations build a fully cloud-native and secure storage environment by removing the need for passwords, storage account keys, on-premises Active Directory, or hybrid identity infrastructure. With native Microsoft Entra ID authentication, applications, virtual machines, and users can securely access Azure Files using identity-based authentication aligned with Zero Trust principles, while also reducing operational complexity, management overhead, and security risks.

Table of Content

Azure Files Goes Cloud-Native with Entra-Only Identities and Managed Identities

Microsoft Azure Files SMB now supports Entra-Only identities with General Availability (GA), enabling organizations to use native Microsoft Entra ID authentication for secure, cloud-native access to file shares. This removes the need for on-premises Active Directory, hybrid synchronization, or managed domain controllers, helping simplify infrastructure, reduce operational overhead, and strengthen Zero Trust security.

The feature also improves Azure Virtual Desktop (AVD) and Windows workload modernization by allowing secure remote access without VPNs or complex networking, while supporting B2B collaboration using existing external identities with FSLogix profiles.

  • What’s New with Entra-Only Identities
    • Manage NTFS permissions directly from the Azure portal without using domain-joined devices or legacy tools.
    • Configure granular file and folder access (ACLs) for both Entra-Only and hybrid users/groups.
    • Portal-based NTFS permissions management is now available globally across all regions.
    • Expanded RBAC support now allows share-level access control for specific Entra users and groups.
    • Share-level RBAC support for Entra-Only identities is currently available in limited regions.
FeatureExplanation
Cloud-Native IdentityUse native Microsoft Entra ID authentication without Active Directory or hybrid sync.
Simplified ManagementReduces maintenance, VPN dependency, and identity management overhead.
Hybrid and Cloud Co-ExistenceSupports both hybrid identities and cloud-native identities during migration.
Secure Remote AccessUsers can securely access Azure Files from anywhere using Entra-joined devices.
MacOS SupportModern macOS devices with Platform SSO can securely access Azure Files using Entra identity.
Azure Files Goes Cloud-Native with Entra-Only Identities and Managed Identities – Table 1
Azure Files Goes Cloud-Native with Entra-Only Identities and Managed Identities - Fig.1
Azure Files Goes Cloud-Native with Entra-Only Identities and Managed Identities – Fig.1

Azure Virtual Desktop and FSLogix Modernized with Entra-Only Identities

Microsoft Entra-Only identities help modernize Azure Virtual Desktop (AVD) deployments by enabling a fully cloud-native identity, compute, and storage environment with Azure Files. FSLogix profile containers can now be securely stored on Azure Files Premium and accessed using Microsoft Entra ID authentication with Kerberos, providing seamless SMB access without relying on on-premises infrastructure.

Patch My PC

This simplifies deployments, reduces operational overhead, and supports secure remote work scenarios. Users can sign in to virtual desktops and access their profiles using cloud-native identities with end-to-end single sign-on, without requiring connectivity to on-premises systems.

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community  and the Whatsapp channel to get the latest news on Microsoft Technologies. We are there on Reddit as well

Resources

Azure Files Entra-Only identities: Advancing cloud-native identity and security | Microsoft Azure Blog

Secure, Keyless Application Access with Managed Identities – Now GA in Azure Files SMB | Microsoft Community Hub

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,  Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Azure

Microsoft Dev Box Moves to Maintenance Mode as Windows 365 Takes Lead for Developer Scenarios

key Takeaways: Let’s discuss about Microsoft Dev Box Moves to Maintenance Mode as Windows 365 Takes Lead for Developer Scenarios. Microsoft announced the Maintenance mode in Dev Box, and no additional features are planned. Microsoft’s investments for developer cloud environments are focused on Windows 365, which provides a unified, scalable solution for developer scenarios. Microsoft […]

AC Anoop C Nair 3 min read
Azure

Multi-Zone Management Platform Architecture for Windows Cloud Solutions

Key Takeaways Multi-Zone Management Platform Architecture for Windows Cloud Solutions! This architecture highlights the core MicrosoftMicrosoft Azure components used to host and deliver Cloud PC services. To ensure high availability and reliability, the infrastructure is distributed across multiple availability zones within each region. This design helps protect the service from zonal outages and keeps workloads […]

AC Anoop C Nair 4 min read
Azure

How to Protect and Recover your Infrastructure with Azure Site Recovery

Key Takeaways Azure Site Recovery is a disaster-recovery service in Microsoft Azure that helps keep your applications running if a cloud region fails. Normally, your virtual machines (VMs) run in one region. ASR creates a copy of those machines in another region so that if the main region goes down, your services can continue running […]

AC Anoop C Nair 4 min read
Azure

Microsoft Expands Connectivity Infrastructure Across 40 Azure Regions to Support Global Cloud Access

Key Takeaways Microsoft Expands Connectivity Infrastructure Across 40 Azure Regions to Support Global Cloud Access! Microsoft operates its connectivity infrastructure across 40 regions worldwide. This global deployment ensures that users across geographic locations can reliably access cloud services without significant delays or interruptions. By distributing its infrastructure across multiple regions, Microsoft can provide consistent connectivity […]

AC Anoop C Nair 3 min read