Azure cloud only with on-premesis file server Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern) Come Celebrate our 10 Year Anniversary!If a Windows shop moves “everything” to the cloud, does it still need Active Directory?AD DC in azure as the only DCAzure File Sharing with domain permissions?Remote Desktop Connection to Azure Server using Office365 User not workingAzure AD Users logging into Remote Desktop ServerLocal username Windows 10 Azure AD Microsoft 365Password reset not working because password writeback not working in portal.azure.comWindows 10 subscription activation for hybrid Azure AD joined devicesAzure AD migrating from cloud to on-premisesAzure Active Directory Domain Services Identity and Server Roles

Selecting the same column from Different rows Based on Different Criteria

Can I cast Passwall to drop an enemy into a 20-foot pit?

What's the meaning of 間時肆拾貳 at a car parking sign

Check which numbers satisfy the condition [A*B*C = A! + B! + C!]

Using audio cues to encourage good posture

Are two submodules (where one is contained in the other) isomorphic if their quotientmodules are isomorphic?

Dating a Former Employee

What are the pros and cons of Aerospike nosecones?

ListPlot join points by nearest neighbor rather than order

Echoing a tail command produces unexpected output?

Denied boarding although I have proper visa and documentation. To whom should I make a complaint?

Withdrew £2800, but only £2000 shows as withdrawn on online banking; what are my obligations?

How do I stop a creek from eroding my steep embankment?

Extract all GPU name, model and GPU ram

Resolving to minmaj7

How to tell that you are a giant?

Is pollution the main cause of Notre Dame Cathedral's deterioration?

Generate an RGB colour grid

Why are there no cargo aircraft with "flying wing" design?

List *all* the tuples!

List of Python versions

porting install scripts : can rpm replace apt?

Fundamental Solution of the Pell Equation

The logistics of corpse disposal



Azure cloud only with on-premesis file server



Announcing the arrival of Valued Associate #679: Cesar Manara
Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern)
Come Celebrate our 10 Year Anniversary!If a Windows shop moves “everything” to the cloud, does it still need Active Directory?AD DC in azure as the only DCAzure File Sharing with domain permissions?Remote Desktop Connection to Azure Server using Office365 User not workingAzure AD Users logging into Remote Desktop ServerLocal username Windows 10 Azure AD Microsoft 365Password reset not working because password writeback not working in portal.azure.comWindows 10 subscription activation for hybrid Azure AD joined devicesAzure AD migrating from cloud to on-premisesAzure Active Directory Domain Services Identity and Server Roles



.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








0















Long time reader. First time poster!



Im a sysadmin at a small company. We utilize Azure + Office 365 and use a cloud-first approach. All Windows 10 PCs are Azure AD joined (we have no local AD).



We have a Windows Server 2016 running a file share on-premises. I have setup Azure Active Directory Domain Services (AAD DS) and joined this server to AAD DS. This enables me to assign cloud users on file shares.



My problem is that users cannot use single-sign-on (SSO) to access this network share. They have to re-type the username and password (and save it in Credential Manager to persist) when accessing the network drive. It appears that no kerberos ticket is given by Azure AD to the windows 10 PCs.



How can i solve this? I want users to simply type \servershare and avoid typing user/password.



Is it really not possible to use Azure AD today without a local AD and get a good SSO-experience to local file shares?



Thanks!










share|improve this question







New contributor




northwester is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.




















  • Do the file shares need to be local? Azure files with AAD DS has functionality to assign AAD users rights to files

    – Sam Cogan
    Apr 13 at 16:23











  • We use the file share for our developers/production. They sometimes produce large amounts of data. For this reason a local file server made more sense (Most of our business data is located in OneDrive for business) To me its odd that no one else has this problem. Is it that odd to have a local file server but relying fully on Azure AD?

    – northwester
    yesterday


















0















Long time reader. First time poster!



Im a sysadmin at a small company. We utilize Azure + Office 365 and use a cloud-first approach. All Windows 10 PCs are Azure AD joined (we have no local AD).



We have a Windows Server 2016 running a file share on-premises. I have setup Azure Active Directory Domain Services (AAD DS) and joined this server to AAD DS. This enables me to assign cloud users on file shares.



My problem is that users cannot use single-sign-on (SSO) to access this network share. They have to re-type the username and password (and save it in Credential Manager to persist) when accessing the network drive. It appears that no kerberos ticket is given by Azure AD to the windows 10 PCs.



How can i solve this? I want users to simply type \servershare and avoid typing user/password.



Is it really not possible to use Azure AD today without a local AD and get a good SSO-experience to local file shares?



Thanks!










share|improve this question







New contributor




northwester is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.




















  • Do the file shares need to be local? Azure files with AAD DS has functionality to assign AAD users rights to files

    – Sam Cogan
    Apr 13 at 16:23











  • We use the file share for our developers/production. They sometimes produce large amounts of data. For this reason a local file server made more sense (Most of our business data is located in OneDrive for business) To me its odd that no one else has this problem. Is it that odd to have a local file server but relying fully on Azure AD?

    – northwester
    yesterday














0












0








0








Long time reader. First time poster!



Im a sysadmin at a small company. We utilize Azure + Office 365 and use a cloud-first approach. All Windows 10 PCs are Azure AD joined (we have no local AD).



We have a Windows Server 2016 running a file share on-premises. I have setup Azure Active Directory Domain Services (AAD DS) and joined this server to AAD DS. This enables me to assign cloud users on file shares.



My problem is that users cannot use single-sign-on (SSO) to access this network share. They have to re-type the username and password (and save it in Credential Manager to persist) when accessing the network drive. It appears that no kerberos ticket is given by Azure AD to the windows 10 PCs.



How can i solve this? I want users to simply type \servershare and avoid typing user/password.



Is it really not possible to use Azure AD today without a local AD and get a good SSO-experience to local file shares?



Thanks!










share|improve this question







New contributor




northwester is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.












Long time reader. First time poster!



Im a sysadmin at a small company. We utilize Azure + Office 365 and use a cloud-first approach. All Windows 10 PCs are Azure AD joined (we have no local AD).



We have a Windows Server 2016 running a file share on-premises. I have setup Azure Active Directory Domain Services (AAD DS) and joined this server to AAD DS. This enables me to assign cloud users on file shares.



My problem is that users cannot use single-sign-on (SSO) to access this network share. They have to re-type the username and password (and save it in Credential Manager to persist) when accessing the network drive. It appears that no kerberos ticket is given by Azure AD to the windows 10 PCs.



How can i solve this? I want users to simply type \servershare and avoid typing user/password.



Is it really not possible to use Azure AD today without a local AD and get a good SSO-experience to local file shares?



Thanks!







azure cloud azure-active-directory azure-active-directory-ds






share|improve this question







New contributor




northwester is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.











share|improve this question







New contributor




northwester is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.









share|improve this question




share|improve this question






New contributor




northwester is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.









asked Apr 11 at 9:40









northwesternorthwester

11




11




New contributor




northwester is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.





New contributor





northwester is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.






northwester is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.












  • Do the file shares need to be local? Azure files with AAD DS has functionality to assign AAD users rights to files

    – Sam Cogan
    Apr 13 at 16:23











  • We use the file share for our developers/production. They sometimes produce large amounts of data. For this reason a local file server made more sense (Most of our business data is located in OneDrive for business) To me its odd that no one else has this problem. Is it that odd to have a local file server but relying fully on Azure AD?

    – northwester
    yesterday


















  • Do the file shares need to be local? Azure files with AAD DS has functionality to assign AAD users rights to files

    – Sam Cogan
    Apr 13 at 16:23











  • We use the file share for our developers/production. They sometimes produce large amounts of data. For this reason a local file server made more sense (Most of our business data is located in OneDrive for business) To me its odd that no one else has this problem. Is it that odd to have a local file server but relying fully on Azure AD?

    – northwester
    yesterday

















Do the file shares need to be local? Azure files with AAD DS has functionality to assign AAD users rights to files

– Sam Cogan
Apr 13 at 16:23





Do the file shares need to be local? Azure files with AAD DS has functionality to assign AAD users rights to files

– Sam Cogan
Apr 13 at 16:23













We use the file share for our developers/production. They sometimes produce large amounts of data. For this reason a local file server made more sense (Most of our business data is located in OneDrive for business) To me its odd that no one else has this problem. Is it that odd to have a local file server but relying fully on Azure AD?

– northwester
yesterday






We use the file share for our developers/production. They sometimes produce large amounts of data. For this reason a local file server made more sense (Most of our business data is located in OneDrive for business) To me its odd that no one else has this problem. Is it that odd to have a local file server but relying fully on Azure AD?

– northwester
yesterday











0






active

oldest

votes












Your Answer








StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);






northwester is a new contributor. Be nice, and check out our Code of Conduct.









draft saved

draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f962580%2fazure-cloud-only-with-on-premesis-file-server%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes








northwester is a new contributor. Be nice, and check out our Code of Conduct.









draft saved

draft discarded


















northwester is a new contributor. Be nice, and check out our Code of Conduct.












northwester is a new contributor. Be nice, and check out our Code of Conduct.











northwester is a new contributor. Be nice, and check out our Code of Conduct.














Thanks for contributing an answer to Server Fault!


  • Please be sure to answer the question. Provide details and share your research!

But avoid


  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.

To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f962580%2fazure-cloud-only-with-on-premesis-file-server%23new-answer', 'question_page');

);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown