Misleading information regarding "authentication against computer accounts" not being supported
This page has this bullet:
"- Doesn't support authentication against computer accounts created in AD DS."
Maybe I misunderstand, but as I understand this today is exactly the default and preferred method.
Document Details
⚠ Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.
- ID: fba964be-3f77-d80c-f1a5-35bb1430bb8f
- Version Independent ID: fe70b11e-10fe-5a8c-1fad-b22a83693503
- Content: Overview - On-premises AD DS authentication to Azure file shares
- Content Source: articles/storage/files/storage-files-identity-auth-active-directory-enable.md
- Service: storage
- Sub-service: files
- GitHub Login: @khdownie
- Microsoft Alias: kendownie
@tom-ditlev Thanks for your feedback! We will investigate and update as appropriate.
@tom-ditlev I think what it means is that only AD user accounts (or service logon accounts) can authenticate with Azure Files - computer accounts can't. However, this gets confusing because the AD identity representing the Azure storage account (which is needed to enable AD DS authentication with Azure Files) is usually a computer account in AD (can also be a service logon account). I will confirm this with AD experts - thanks for calling it out.
@tom-ditlev if there are any further questions regarding the documentation, please tag me in your reply and we will be happy to continue the conversation.
@khdownie Thank for your contribution. 👍
@SaibabaBalapur-MSFT please keep this open for a few days, as I am confirming with the team.
@SaibabaBalapur-MSFT I am doing my best to get an answer from engineering. Please hold off for a little while longer.
@SaibabaBalapur-MSFT I have confirmed that this is outdated language that should be removed. Computer accounts didn't used to be supported for accessing Azure file shares because we don’t support RBAC share-level permissions for computer accounts. Identities that can’t be configured with RBAC (like computer accounts) can now get access to the share using the "default share permissions" feature. So I will remove this language from the docs.
@khdownie Thank for your input.
@tom-ditlev If there are any further questions regarding the documentation, please tag me in your reply and we will be happy to continue the conversation.
I updated the language on the page. #please-close