Skip to content

Commit 46c02d9

Browse files
authored
Update storage-files-active-directory-domain-services-enable.md
1 parent 6f951d7 commit 46c02d9

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

articles/storage/files/storage-files-active-directory-domain-services-enable.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,8 @@ ms.author: rogarana
2222
> AD authentication can only be supported against one AD forest where the storage account is registered to. You can only access Azure file shares with the AD credentials from a single AD forest by default. If you need to access your Azure file share from a different forest, make sure that you have the proper forest trust configured, see [FAQ](https://docs.microsoft.com/azure/storage/files/storage-files-faq#security-authentication-and-access-control) for details.
2323
>
2424
> AD authentication for SMB access and ACL persistence is supported for Azure file shares managed by Azure File Sync.
25+
>
26+
> Azure Files supports Kerberos authentication with AD with RC4-HMAC encryption. AES Kerberos encryption is not yet supported.
2527
2628
When you enable AD for Azure file shares over SMB, your AD domain joined machines can mount Azure file shares using your existing AD credentials. This capability can be enabled with an AD environment hosted either in on-prem machines or hosted in Azure.
2729

0 commit comments

Comments
 (0)