You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/azure-netapp-files/create-active-directory-connections.md
+16-11Lines changed: 16 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -22,9 +22,9 @@ Several features of Azure NetApp Files require that you have an Active Directory
22
22
23
23
* An Azure NetApp Files account must be created in the region where the Azure NetApp Files volumes are to be deployed.
24
24
25
-
*The default behavior of Azure NetApp Files is to allow only one Active Directory (AD) connection per subscription.
25
+
*By default, Azure NetApp Files allows only one Active Directory (AD) connection per subscription.
26
26
27
-
You can [one Active Directory connection per NetApp account](#multi-ad).
27
+
You can [create one Active Directory connection per NetApp account](#multi-ad).
28
28
29
29
Before enrolling in this feature, check the [Active Directory type](#netapp-accounts-and-active-directory-type) field in your account page.
30
30
@@ -83,11 +83,13 @@ You can use the NetApp account overview page to confirm the Active Directory acc
83
83
84
84
* **NA**: Existing NetApp account which supports only one AD configuration per subscription and region. The AD configuration is not shared with other NetApp accounts in the subscription.
85
85
* **Multi AD**: NetApp account supports one AD configuration in each NetApp account in the subscription. This allows for more than one AD connection per subscription when using multiple NetApp accounts.
86
-
* **Shared AD**: NetApp account supports only one AD configuration per subscription and region, but is shared across NetApp accounts in the subscription and region.
86
+
* **Shared AD**: NetApp account supports only one AD configuration per subscription and region, but the configuration is shared across NetApp accounts in the subscription and region.
87
+
88
+
For more information about the relationship between NetApp accounts and subscriptions, see [Storage hierarchy of Azure NetApp Files](azure-netapp-files-understand-storage-hierarchy.md).
87
89
88
90
## Create an Active Directory connection
89
91
90
-
1. From your NetApp account, select **Active Directory connections**, then select **Join**.
92
+
1. From your NetApp account, select **Active Directory connections** then **Join**.
91
93
92
94

93
95
@@ -105,11 +107,12 @@ You can use the NetApp account overview page to confirm the Active Directory acc
105
107
>[!NOTE]
106
108
>It is recommended that you configure a Secondary DNS server. See [Understand guidelines for Active Directory Domain Services site design and planning for Azure NetApp Files](understand-guidelines-active-directory-domain-service-site.md). Ensure that your DNS server configuration meets the requirements for Azure NetApp Files. Otherwise, Azure NetApp Files service operations, SMB authentication, Kerberos, or LDAP operations might fail.
107
109
108
-
If you use Microsoft Entra Domain Services, you should use the IP addresses of the Microsoft Entra Domain Services domain controllers for Primary DNS and Secondary DNS respectively.
110
+
If you use Microsoft Entra Domain Services, use the IP addresses of the Microsoft Entra Domain Services domain controllers for Primary DNS and Secondary DNS respectively.
111
+
109
112
* **AD DNS Domain Name (required)**
110
-
This is the fully qualified domain name of the AD DS that will be used with Azure NetApp Files (for example, `contoso.com`).
113
+
This is the fully qualified domain name of the AD DS used with Azure NetApp Files (for example, `contoso.com`).
111
114
* **AD Site Name (required)**
112
-
This is the AD DS site name that will be used by Azure NetApp Files for domain controller discovery.
115
+
This is the AD DS site name that Azure NetApp Files USES for domain controller discovery.
113
116
114
117
The default site name for both AD DS and Microsoft Entra Domain Services is `Default-First-Site-Name`. Follow the [naming conventions for site names](/troubleshoot/windows-server/identity/naming-conventions-for-computer-domain-site-ou#site-names) if you want to rename the site name.
115
118
@@ -278,7 +281,7 @@ You can use the NetApp account overview page to confirm the Active Directory acc
278
281
279
282

280
283
281
-
## <a name="multi-ad"></a> Create one Active Directory connections per NetApp account (preview)
284
+
## <a name="multi-ad"></a> Create one Active Directory connection per NetApp account (preview)
282
285
283
286
With this feature, each NetApp account within an Azure subscription can have its own AD connection. Once configured, the AD connection of the NetApp account is used when you create an [SMB volume](azure-netapp-files-create-volumes-smb.md), a [NFSv4.1 Kerberos volume](configure-kerberos-encryption.md), or a [dual-protocol volume](create-volumes-dual-protocol.md). That means, Azure NetApp Files supports more than one AD connection per Azure subscription when multiple NetApp accounts are used.
284
287
@@ -291,7 +294,7 @@ With this feature, each NetApp account within an Azure subscription can have its
291
294
292
295
### Register the feature
293
296
294
-
The feature to create one AD connection per NetApp account is currently in preview. You need to register the feature before using it for the first time. After registration, the feature is enabled and works in the background. No significant interface changes are introduced.
297
+
The feature to create one AD connection per NetApp account is currently in preview. You need to register the feature before using it for the first time. After registration, the feature is enabled and works in the background.
295
298
296
299
1. Register the feature:
297
300
@@ -311,10 +314,12 @@ You can also use [Azure CLI commands](/cli/azure/feature) `az feature register`
311
314
312
315
## <a name="shared_ad"></a>Map multiple NetApp accounts in the same subscription and region to one AD connection (preview)
313
316
314
-
If registered for this feature, the Shared AD feature enables all NetApp accounts to share an AD connection created by one of the NetApp accounts that belong to the same subscription and the same region. For example, using this feature, all NetApp accounts in the same subscription and region can use the common AD configuration to create an [SMB volume](azure-netapp-files-create-volumes-smb.md), a [NFSv4.1 Kerberos volume](configure-kerberos-encryption.md), or a [dual-protocol volume](create-volumes-dual-protocol.md). When you use this feature, the AD connection will be visible in all NetApp accounts that are under the same subscription and same region. With the introduction of the feature to [create an AD connection per NetApp account](#multi-ad), new feature registration for the Shared AD feature are not accepted.
317
+
The Shared AD feature enables all NetApp accounts to share an AD connection created by one of the NetApp accounts that belong to the same subscription and the same region. For example, using this feature, all NetApp accounts in the same subscription and region can use the common AD configuration to create an [SMB volume](azure-netapp-files-create-volumes-smb.md), a [NFSv4.1 Kerberos volume](configure-kerberos-encryption.md), or a [dual-protocol volume](create-volumes-dual-protocol.md). When you use this feature, the AD connection is visible in all NetApp accounts that are under the same subscription and same region.
318
+
319
+
With the introduction of the feature to [create an AD connection per NetApp account](#multi-ad), new feature registration for the Shared AD feature are not accepted.
315
320
316
321
>[!NOTE]
317
-
>You can register to use an AD connection per NetApp account if you're already enrolled in the preview for Shared AD. If you currently meet the maximum of 10 NetApp accounts per Azure region per subscription, you must initiate a [support request](azure-netapp-files-resource-limits.md#request-limit-increase) to increase the limit. You can confirm your configuration in your account overview page in the [AD type](#netapp-accounts-and-active-directory-type) field.
322
+
>You can register to use one AD connection per NetApp account if you're already enrolled in the preview for Shared AD. If you currently meet the maximum of 10 NetApp accounts per Azure region per subscription, you must initiate a [support request](azure-netapp-files-resource-limits.md#request-limit-increase) to increase the limit. You can confirm your configuration in your account overview page in the [AD type](#netapp-accounts-and-active-directory-type) field.
318
323
319
324
## <a name="reset-active-directory"></a> Reset Active Directory computer account password
0 commit comments