Java / Azure Files Interview questions
Last updated
1. What is Azure Files?
Azure Files is a fully managed cloud file share service. You create a share in a storage account and access it over SMB, NFS or the REST API, much like a share on a traditional file server.
The same share can be mounted at the same time by Windows, Linux and macOS clients, whether they run in Azure or on-premises. That makes it a common landing spot for lift-and-shift of file servers.
Microsoft runs the underlying servers, so there is no OS to patch, no disks to replace and no cluster to build. You manage the share, its size, its permissions and its network access.
Take quiz
a message queue for decoupled services
a block device attached to a single VM
a managed file share reachable over SMB, NFS and REST
a NoSQL document database
The VM that mounts the share
The domain controller
You, through Windows Update on the storage account
Microsoft, because it is a managed service
2. What protocols does Azure Files support?
Azure Files supports SMB (2.1, 3.0 and 3.1.1), NFS 4.1 and the FileREST API over HTTPS.
SMB is the usual choice for Windows workloads and identity-based access. NFS targets Linux and Unix workloads that need POSIX semantics. REST is handy for tools such as AzCopy, Storage Explorer and your own code.
A single share is created for either SMB or NFS, never both. REST data-plane operations such as AzCopy transfers apply to SMB shares, while NFS shares are mounted by Linux clients and managed through the management plane, so check the current feature matrix before you rely on REST for NFS.
Take quiz
Yes, if secure transfer is disabled
Yes, but only on the cool tier
Yes, by using two mount points
No, a share is created for one of the two protocols
NFS 4.1
NFS 4.2 only
NFS 3 only
NFS 2
3. What are the storage tiers in Azure Files?
Azure Files has four tiers. Three are standard (HDD-backed): transaction optimized, hot and cool. One is premium (SSD-backed).
| Tier | Media | Best for |
| Transaction optimized | HDD | Transaction-heavy workloads that do not need SSD latency |
| Hot | HDD | General file sharing and Azure File Sync |
| Cool | HDD | Online archive and rarely accessed data |
| Premium | SSD | Databases, FSLogix profiles, latency-sensitive apps |
Cooler tiers charge less for storage but more for transactions and access. You can move a standard share between standard tiers without recreating it.
Take quiz
Premium
Cool
Hot
Transaction optimized
needed with sub-millisecond latency
stored for long periods and accessed rarely
used as user profile containers
read thousands of times per second
4. What are the redundancy options for Azure Files?
Standard shares can use LRS, ZRS, GRS or GZRS. Premium shares are limited to LRS and ZRS.
- LRS keeps three copies inside one datacenter.
- ZRS spreads three copies across availability zones in one region.
- GRS is LRS plus asynchronous copy to a paired region.
- GZRS is ZRS in the primary region plus asynchronous copy to the paired region.
Pick the level from your recovery goals. If you need geo protection on a premium share, you have to replicate it yourself, for example with AzCopy or Azure File Sync.
Take quiz
LRS, ZRS and GRS
LRS and ZRS
GRS and GZRS
RA-GRS only
two paired regions
all regions in a geography
multiple availability zones in one region
three racks in one datacenter
5. What is the purpose of a storage account for Azure Files?
The storage account is the management and namespace boundary for your shares. Every share lives inside one, and the account decides the endpoint, the redundancy, the network rules and the authentication settings.
The file endpoint looks like <account>.file.core.windows.net. Settings such as firewall rules, private endpoints, secure transfer, encryption keys and identity-based authentication are applied at the account level and affect every share in it.
Some settings stay per share, for example the quota, the access tier and the protocol (SMB or NFS).
Take quiz
<account>.dfs.core.windows.net
<account>.queue.core.windows.net
<account>.file.core.windows.net
<account>.blob.core.windows.net
The file attributes
The last-modified time
The ACL of a single folder
Firewall and private endpoint rules
6. What are the types of storage accounts used for Azure Files?
Two account kinds host file shares: FileStorage for premium shares and general-purpose v2 (StorageV2) for standard shares.
A FileStorage account is dedicated to files on SSD media. A general-purpose v2 account can hold file shares next to blobs, queues and tables, which is convenient but means those services share the account's limits and network rules.
You cannot put a premium share in a general-purpose v2 account, and you cannot create standard shares in a FileStorage account.
Take quiz
BlockBlobStorage
General-purpose v2
BlobStorage
FileStorage
file shares alongside blobs, queues and tables
only NFS shares
only premium SSD shares
only file shares
7. What are the size limits of an Azure file share?
A standard share defaults to 5 TiB. If you enable large file shares on the account, a share can grow to 100 TiB. Premium shares can also reach 100 TiB.
| Item | Limit |
| Standard share (default) | 5 TiB |
| Share with large file shares enabled | up to 100 TiB |
| Single file | 4 TiB |
Limits for IOPS, throughput and file counts change over time, so confirm them in the current Azure Files scalability targets before you size a design.
Take quiz
4 TiB
100 TiB
1 TiB
5 TiB
switch the share to NFS
enable large file shares on the storage account
turn on soft delete
move the data to Blob Storage
8. How do you mount an Azure file share on Windows?
Use the UNC path \\<account>.file.core.windows.net\<share> and authenticate with the storage account key or an identity-based method. The portal's Connect blade generates the exact script.
cmdkey /add:myacct.file.core.windows.net /user:localhost\myacct /pass:<storage-key> net use Z: \\myacct.file.core.windows.net\docs /persistent:Yes
The client needs outbound TCP 445 to the account. If your ISP or firewall blocks it, use a VPN, ExpressRoute or a private endpoint.
Take quiz
smb://<account>.azure.com/<share>
\\<account>.file.core.windows.net\<share>
https://<account>.blob.core.windows.net/<share>
\\<account>.file.core.windows.net:443\<share>
3389
1433
445
2049
9. How do you mount an Azure file share on Linux?
Install cifs-utils, create a mount point, and mount with the CIFS driver using SMB 3.x. Keep the key in a root-only credentials file instead of on the command line.
- Install the helper:
sudo apt install cifs-utils. - Create the folder:
sudo mkdir -p /mnt/docs. - Store
usernameandpasswordin/etc/smbcredentials/myacct.credwithchmod 600. - Mount the share with the command below.
sudo mount -t cifs //myacct.file.core.windows.net/docs /mnt/docs -o credentials=/etc/smbcredentials/myacct.cred,vers=3.1.1,dir_mode=0770,file_mode=0660,serverino
Add the same options to /etc/fstab with _netdev for a persistent mount.
Take quiz
azure-cli
samba-common-bin only
cifs-utils
nfs-common
Inline in a world-readable fstab line
In the root folder of the share
In the shell history
In a root-only credentials file referenced from fstab
10. What is Azure File Sync?
Azure File Sync keeps a Windows Server file share in sync with an Azure file share. The server keeps hot files locally while the full dataset lives in Azure.
It lets you turn a file server into a fast local cache of Azure Files, with optional cloud tiering to save disk space. Several servers in different offices can sync to the same cloud share, so each site sees the same files.
An agent installed on Windows Server does the work, and it talks to Azure over HTTPS.
Take quiz
Azure Firewall
a Linux VM with cifs-utils
the storage account
Windows Server
local performance on a server while the full dataset lives in Azure
automatic conversion of SMB to NFS
removing the need for any network access
replacing identity providers
11. What are the components of Azure File Sync?
Azure File Sync has five moving parts: the Storage Sync Service, sync groups, cloud endpoints, server endpoints and the agent on registered servers.
| Component | What it is |
| Storage Sync Service | Top-level Azure resource that holds sync groups and registered servers |
| Sync group | Defines one set of files that stay in sync |
| Cloud endpoint | The Azure file share inside a sync group |
| Server endpoint | A path on a registered server inside a sync group |
| Agent | Software on Windows Server that registers it and runs sync and tiering |
A sync group has exactly one cloud endpoint and can have many server endpoints.
Take quiz
the Azure file share in a sync group
the folder path being synced on the server
the storage account key
a public IP of the server
One per server
One
Two, primary and secondary
Unlimited
12. What is cloud tiering in Azure File Sync?
Cloud tiering replaces rarely used files on the server with small pointers while the real content stays in the Azure file share. This frees local disk space without removing anything from the namespace.
Users still see every file. When someone opens a tiered file, the agent recalls the data from Azure on demand. Two policies control tiering: volume free space (keep at least X% free) and date (tier files not accessed for N days).
Take quiz
a compressed zip kept locally
a pointer whose content is stored in Azure
moved to a different sync group
deleted from both server and cloud
the cloud share never exceeds its quota
files older than N days are deleted
a minimum percentage of the volume stays free
only the newest files are synced
13. What is a share snapshot in Azure Files?
A share snapshot is a read-only, point-in-time copy of an entire file share. It is incremental, so only changes since the previous snapshot take extra space.
You can have up to 200 snapshots per share. Users can browse them through the Previous Versions tab on Windows, or you can restore single files from the portal, PowerShell or AzCopy. Snapshots live in the same storage account as the share, so they do not replace a separate backup.
Take quiz
50
There is no limit
200
1,000
deleted automatically after 24 hours
stored in a different region by default
writable full copies
read-only and incremental
14. What is soft delete for Azure file shares?
Soft delete keeps a deleted file share recoverable for a retention period instead of removing it right away. It protects against accidental deletion of the whole share, not individual files.
It is on by default for new accounts with a 7-day retention, which you can set between 1 and 365 days. During that window you can undelete the share, along with its snapshots, from the portal or CLI.
Take quiz
365 days
1 day
30 days
7 days
accidental deletion of a whole share
a regional outage
a DDoS attack
a client mounting the wrong drive letter
15. What are the authentication options for Azure Files?
Azure Files supports storage account keys, shared access signatures (REST only) and identity-based access over SMB using Kerberos.
- Account key: full access to every share in the account. Treat it like a root password.
- SAS token: scoped and time-limited access through REST.
- Identity-based: on-premises AD DS, Microsoft Entra Domain Services, or Microsoft Entra Kerberos for hybrid identities.
Identity-based access is preferred because it gives per-user permissions and an audit trail.
Take quiz
full access to every share in the storage account
access only to the portal
access only to snapshots
read-only access to one file
NTLM over the public internet
Microsoft Entra Kerberos
SSH keys
Anonymous access
16. Why does port 445 matter for Azure Files?
SMB runs over TCP port 445. A client cannot mount an Azure file share over SMB unless it can reach the storage account on that port.
Many home ISPs, hotels and corporate firewalls block outbound 445 because of old SMB worms. The usual symptom on Windows is System error 53 or 1231. Test it with Test-NetConnection -ComputerName myacct.file.core.windows.net -Port 445.
If it fails, route traffic through a VPN, ExpressRoute or a private endpoint, or use Azure File Sync, which uses HTTPS.
Take quiz
The share silently becomes NFS
System error 53 or 1231 when running net use
A 403 from the portal
Files show as empty
Set-NetFirewallRule
Get-SmbShare
Test-NetConnection
Get-AzStorageAccount
17. How do you back up an Azure file share?
Use Azure Backup. It schedules share snapshots through a backup policy and tracks them in a Recovery Services vault.
- Create or choose a Recovery Services vault in the same region.
- Create a backup policy with frequency and retention.
- Select the storage account and file shares to protect.
- Run an on-demand backup to verify, then test a restore.
You can restore a full share or individual files, to the original or an alternate location.
Take quiz
VM disk images
tape export of the share
share snapshots managed by a policy
Cosmos DB change feed
An Azure Site Recovery group
A Log Analytics workspace
A storage lifecycle rule
A Recovery Services vault
18. What is SMB Multichannel in Azure Files?
SMB Multichannel lets one SMB session use several network connections at once. That raises throughput and keeps the session alive if one connection fails.
It is supported on premium SMB shares with SMB 3.x clients and is enabled by default on FileStorage accounts. The client needs a NIC that supports Receive Side Scaling (RSS) to benefit, which most modern Azure VM sizes do.
It does not apply to NFS shares.
Take quiz
snapshot size
file compression ratio
Entra sign-in speed
throughput and resiliency of a session
premium SMB file shares
NFS shares
Azure Queue storage
Blob containers
19. What are the common use cases of Azure Files?
Azure Files is used wherever you need a shared folder without running a file server.
- Lift and shift of on-premises file servers and mapped drives.
- Shared configuration and tools mounted on many VMs.
- FSLogix profile containers for Azure Virtual Desktop.
- Persistent volumes for containers in AKS and Azure Container Instances.
- Hybrid caching with Azure File Sync for branch offices.
It is not a good fit for hosting a relational database engine that expects raw block storage.
Take quiz
Replacing an on-premises Windows file server
Hosting a SQL engine's data files on raw blocks
Running a serverless function
Streaming IoT telemetry
Store them in the VM's temp disk
Mount the same file share on every VM
Copy the files at each boot only
Attach one managed disk read-write to all VMs
20. How do you create an Azure file share using Azure CLI?
Create the storage account first, then the share. The share-rm group uses the Azure Resource Manager API, so no account key is needed.
az storage account create -n myacct -g rg-files -l eastus --sku Standard_LRS --kind StorageV2 az storage share-rm create --storage-account myacct -g rg-files --name docs --quota 1024 --access-tier Hot
--quota is the maximum size in GiB. For a premium share, create a FileStorage account with --sku Premium_LRS and the quota becomes the provisioned size you pay for.
Take quiz
az file mount
az storage share-rm create
az share new
az storage fs create
The snapshot count
The number of files allowed
The maximum share size in GiB
The number of users
21. What is the difference between Azure Files and Azure Blob Storage?
Azure Files exposes a real file system (folders, locks, ACLs) over SMB and NFS. Blob Storage is an object store accessed mainly over HTTPS, with a flat namespace unless you enable hierarchical namespace.
| Aspect | Azure Files | Azure Blob Storage |
| Access | SMB, NFS, REST | REST, SDKs, NFS 3.0 and SFTP on supported accounts |
| Structure | Shares, directories, files | Containers and blobs |
| Locking and ACLs | Yes, native SMB semantics | Limited, no SMB-style locking |
| Typical use | Shared drives, app lift and shift, profiles | Images, backups, data lakes, streaming |
If an application expects a drive letter or a mount path with normal file semantics, pick Files. If it stores huge volumes of unstructured data and talks HTTP, pick Blob.
Take quiz
Azure Table Storage
Azure Queue Storage
Azure Files
Azure Blob Storage
Azure Files premium
A VM temp disk
Azure Files cool tier on a VM
Azure Blob Storage
22. What is the difference between standard and premium Azure file shares?
Standard shares run on HDD and bill mostly on what you use. Premium shares run on SSD, bill on what you provision and give low, consistent latency.
| Aspect | Standard | Premium |
| Account kind | General-purpose v2 | FileStorage |
| Media | HDD | SSD |
| Billing | Used capacity plus transactions | Provisioned capacity |
| Redundancy | LRS, ZRS, GRS, GZRS | LRS, ZRS |
| Performance | Shared, lower IOPS ceiling | IOPS and throughput scale with provisioned size |
Choose premium when latency or IOPS matter, such as for FSLogix, build agents or databases. Choose standard for general shares and archives.
Take quiz
only transactions
only egress traffic
the number of users
provisioned capacity
Standard
Premium NFS only
Premium only
Neither
23. How does billing work for Azure Files?
The model depends on the share type. Standard pay-as-you-go charges for data stored (including snapshots), for transactions in blocks, and for outbound data. Premium charges for provisioned GiB, which also sets your IOPS and throughput.
Within standard, the tier moves the balance: transaction optimized has the lowest transaction price but a higher storage price, while cool is the reverse.
Azure also offers a provisioned v2 billing model, where you set storage, IOPS and throughput independently. Confirm availability and regions in the current pricing page before choosing it.
Take quiz
Transaction optimized
All three are equal
Hot
Cool
only change the region
set storage, IOPS and throughput separately
pay nothing for transactions and storage
only change redundancy
24. How do you configure identity-based authentication for Azure Files SMB?
You enable an identity source on the storage account, assign share-level permissions with Azure RBAC, then set file and folder permissions with Windows ACLs.
- Pick the source: AD DS, Microsoft Entra Domain Services or Microsoft Entra Kerberos for hybrid identities.
- Enable it on the account. For AD DS, run
Join-AzStorageAccount(AzFilesHybrid module) to create the account object in the domain. - Assign an RBAC role such as Storage File Data SMB Share Contributor to a user or group.
- Mount once with the account key and set NTFS permissions using Explorer or
icacls. - Mount again using the user's own identity.
Users also need network line-of-sight to a domain controller when the source is AD DS.
Take quiz
Add-Computer -Domain only
Join-AzStorageAccount
az ad sp create
Set-AzVMExtension
SAS token scopes
Azure Policy assignments
Windows ACLs such as icacls
Storage lifecycle rules
25. How do share-level and NTFS permissions work together in Azure Files?
Access is checked in two layers, and a user needs both to allow the action. The most restrictive result wins.
| Layer | Controlled by | Scope |
| Share level | Azure RBAC roles | Entire share |
| File and folder level | Windows ACLs (NTFS style) | Individual directories and files |
Three built-in roles cover most cases: SMB Share Reader, SMB Share Contributor and SMB Share Elevated Contributor. Only the elevated role can change ACLs. A common pattern is to give a group Contributor at share level and then let ACLs narrow access per folder.
Take quiz
Reader
Storage File Data SMB Share Reader
Storage File Data SMB Share Elevated Contributor
Storage Queue Data Contributor
can write only on weekdays
can write, because RBAC overrides ACLs
can write, because ACLs are ignored over SMB
cannot write, because the most restrictive layer wins
26. How does Azure Files encrypt data at rest and in transit?
Data at rest is always encrypted with 256-bit AES through Storage Service Encryption. You can use Microsoft-managed keys or customer-managed keys held in Azure Key Vault.
In transit, SMB 3.x clients use SMB encryption (AES-128-GCM, and AES-256-GCM with 3.1.1), and REST calls use HTTPS. The account setting Secure transfer required rejects unencrypted connections.
Because SMB 2.1 cannot encrypt, an SMB 2.1 client can only mount from the same Azure region when secure transfer is disabled. Older Windows 7 or Server 2008 R2 clients are the usual cases.
Take quiz
Blocks all REST calls
Forces cool tier
Disables Azure RBAC
Rejects connections that are not encrypted
Azure Key Vault
Azure Advisor
The file share itself
Azure Monitor
27. How do private endpoints secure access to Azure Files?
A private endpoint gives the storage account a private IP address inside your virtual network. Traffic to the file service stays on the Microsoft backbone and never crosses the public internet.
You also need DNS to resolve <account>.file.core.windows.net to that private IP, normally through the privatelink.file.core.windows.net private DNS zone. Once it works, you can disable public network access on the account.
Compared with service endpoints, a private endpoint is reachable from on-premises over VPN or ExpressRoute and gets a dedicated address, so it is the preferred choice for hybrid access.
Take quiz
privatelink.file.core.windows.net
privatelink.database.windows.net
privatelink.blob.core.windows.net
file.azure.local
disable encryption at rest
disable public network access on the account
switch the share to NFS
delete the share snapshots
28. How can you access Azure Files when port 445 is blocked?
You either avoid SMB over the open internet or use a path that does not depend on port 445.
- VPN or ExpressRoute: reach a private endpoint over a private link, where 445 is not filtered.
- Azure File Sync: the server talks to Azure over HTTPS (443), and users hit the local server.
- REST tools: AzCopy and Storage Explorer use HTTPS.
- Azure VMs: run the workload in Azure so SMB stays inside the network.
Asking the ISP to unblock 445 rarely works, so a VPN is the quickest fix for remote users.
Take quiz
Telnet
HTTPS between the server and Azure
FTP
NFS 4.1 only
mount -t cifs
net use
AzCopy over HTTPS
robocopy to a mapped drive only
29. When should you choose NFS over SMB for Azure Files?
Choose NFS for Linux or Unix workloads that need POSIX permissions, symbolic links and hard links. Choose SMB for Windows clients, identity-based permissions and in-transit encryption.
| Need | SMB | NFS 4.1 |
| Typical clients | Windows, Linux, macOS | Linux and Unix |
| Permissions | Windows ACLs plus Entra or AD identity | POSIX mode bits, no identity auth |
| Security model | Kerberos, SMB encryption | Network based: private or service endpoints |
| Redundancy and tiers | Standard and premium | Offered on premium (SSD); check the current docs |
NFS shares require locking the network down, because access control relies on the VNet rather than a user identity.
Take quiz
SAS tokens
Storage account keys
Network rules such as private or service endpoints
Kerberos tickets from AD DS
Blob SFTP
REST only
NFS with POSIX modes
SMB with identity-based authentication
30. What is the difference between Azure Files and Azure NetApp Files?
Both are managed file services, but they target different tiers of workload. Azure Files is the broad, cost-effective option. Azure NetApp Files is a high-performance service built on NetApp technology for demanding enterprise workloads.
| Aspect | Azure Files | Azure NetApp Files |
| Positioning | General file shares, lift and shift | Latency-sensitive enterprise and HPC workloads |
| Protocols | SMB, NFS 4.1, REST | SMB, NFS 3 and 4.1, dual protocol |
| Capacity model | Per share, pay as you go or provisioned | Capacity pools with service levels |
| Cost | Lower for typical shares | Higher, justified by performance features |
Pick Azure Files first. Move to NetApp Files when you need its sub-millisecond latency, dual-protocol access or specific application certifications.
Take quiz
Azure Files
Azure Table Storage
Azure Blob Storage
Azure NetApp Files
Azure Files
Azure NetApp Files
Azure Managed Disks
Azure Data Lake
31. When would you choose Azure File Sync over a direct mount?
Choose Azure File Sync when users or apps need local-speed access to files and the link to Azure is slow, shared or unreliable. Choose a direct mount when the clients run in Azure or have a fast, stable connection.
- Branch offices that currently have their own file servers.
- Large datasets where only a small hot subset is used often.
- Several sites that need the same files kept consistent.
- Gradual migration, where the server stays online while data moves to Azure.
File Sync adds a Windows Server to manage, so do not use it if a plain mount over VPN or ExpressRoute meets the latency target.
Take quiz
A branch office needing local-speed access to cloud-hosted files
A serverless function reading one blob
A Linux container using NFS
A VM in Azure reading a share in the same region
Several sites needing a local cache
Azure VMs in the same region as the share
A remote office on a slow WAN link
A server with a small disk and a huge dataset
32. How does cloud tiering decide which files to tier?
The agent tracks a heat value per file, based on last access (reads and writes). The coldest files are tiered first.
- Volume free space policy: when free space falls below the target percentage, the agent tiers the least recently accessed files until it reaches the target.
- Date policy: files not accessed within N days are tiered, even if there is plenty of space.
- Both together: a file is tiered when either condition requires it.
Very small files, roughly under 64 KiB, are not tiered, and files must be fully synced to Azure before they are eligible. After setup, the initial download mode decides whether new servers get only the namespace or also file contents.
Take quiz
Lifecycle policy
Volume free space policy
Date policy
Snapshot policy
only when the server restarts
only when a user deletes it locally
either the free space or date policy requires it
only when both policies agree
33. How do you migrate an on-premises file server to Azure Files?
Pick a copy method based on size and downtime, then move data, permissions and users in that order.
- Assess: data size, file count, open files, ACL complexity, and bandwidth.
- Prepare: create the storage account, share and identity configuration.
- Copy: use Robocopy over SMB, AzCopy over HTTPS, Azure Storage Mover, or Azure File Sync to seed and sync. Use Data Box for very large offline transfers.
- Cut over: run a final delta pass, then repoint drive mappings or DFS namespaces.
robocopy D:\Data Z:\ /MIR /COPYALL /DCOPY:DAT /MT:16 /R:2 /W:1 /LOG:C:\mig.log
/MIR deletes files in the target that do not exist in the source, so use it carefully.
Take quiz
/MT
/R
/MIR
/LOG
SAS tokens
SMB Multichannel
Soft delete
Azure Data Box
34. How does Azure Files support FSLogix profile containers in Azure Virtual Desktop?
FSLogix stores each user's profile as a VHD(X) file on an Azure file share. At sign-in, the file is mounted over SMB so the profile looks local to the session host.
Logon time depends on IOPS and latency, especially during a morning logon storm. That is why premium shares in the same region as the session hosts are the usual choice, with identity-based authentication so each user only reaches their own profile.
Set share-level RBAC for the host pool users group, then use NTFS ACLs so each profile folder is private to its owner. Add Cloud Cache only if you need multiple storage locations.
Take quiz
a Cosmos DB document
a set of loose registry files only
a blob in a container
a VHD or VHDX file on the share
They handle logon storms with low latency
They remove the need for identity
They store profiles in memory
They are the only tier that supports SMB
35. How do you mount Azure Files in Azure Kubernetes Service?
AKS ships with the Azure Files CSI driver. You request a volume with a PersistentVolumeClaim that references a storage class, and AKS creates the share and mounts it into the pod.
Built-in classes include azurefile-csi (standard) and azurefile-csi-premium. Use ReadWriteMany so many pods can use the same volume.
apiVersion: v1 kind: PersistentVolumeClaim metadata: name: shared-data spec: accessModes: [ReadWriteMany] storageClassName: azurefile-csi-premium resources: requests: storage: 100Gi
Take quiz
ReadWriteMany
ReadOnlyOnce
ReadWriteOnce
WriteOnly
azurefile-csi
azurefile-csi-premium
azureblob-nfs-premium
managed-csi
36. What is the difference between share snapshots and Azure Backup for file shares?
A snapshot is a single point-in-time copy. Azure Backup is the management layer that creates snapshots on a schedule, keeps them according to a policy and records them in a vault.
| Aspect | Manual share snapshots | Azure Backup |
| Scheduling | You script it | Policy based |
| Retention | Up to 200 per share, you prune them | Daily, weekly, monthly, yearly rules |
| Management | Per share | Central vault with reports and alerts |
| Deletion protection | Anyone with rights can delete | Vault guards against accidental removal of recovery points |
For anything beyond ad hoc safety copies, use Azure Backup.
Take quiz
Soft delete
Azure Backup
SAS tokens
A manual snapshot
2,000
20
200
Unlimited
37. How does geo-redundancy work for Azure Files?
With GRS or GZRS, the platform asynchronously copies your data to the paired region, where it is kept in LRS. Writes are acknowledged after they reach the primary, so a recent change can be lost in a disaster.
Unlike blobs, file shares do not offer a read-access secondary endpoint. The secondary is used only after failover. Microsoft can trigger it for a regional outage, and you can start a customer-managed failover on the account.
Check the Last Sync Time property before failing over to understand the possible data loss. After failover the account becomes LRS in the new primary region, and you must reconfigure geo-redundancy.
Take quiz
SMB drops all files on reconnect
The paired region uses a different file system
Replication to the secondary is asynchronous
Snapshots are deleted at failover
Secure transfer required
Quota
Access tier
Last Sync Time
38. How do you monitor Azure Files performance?
Use Azure Monitor metrics for quick health checks and diagnostic logs for per-request detail.
- Metrics: Transactions, Ingress, Egress, SuccessE2ELatency, SuccessServerLatency, FileCapacity, Availability. Split by the FileShare and ResponseType dimensions.
- Logs: enable diagnostic settings for the file service and send StorageRead, StorageWrite and StorageDelete to Log Analytics.
- Alerts: notify on throttling responses or when latency or capacity thresholds are crossed.
- Storage insights: a ready-made workbook with trends across accounts.
StorageFileLogs | where TimeGenerated > ago(1h) | summarize count() by OperationName, StatusText | order by count_ desc
Take quiz
QueueName
BlobType
TableName
FileShare
Diagnostic logs sent to Log Analytics
The share's quota setting
Azure Advisor tips
Only the portal overview page
39. What happens when an Azure file share is throttled?
When requests exceed the share's IOPS or throughput limit, the service slows or rejects them. Clients see higher latency, and SMB operations may succeed but take longer.
In metrics, filter Transactions by ResponseType. SuccessWithThrottling shows SMB requests that were delayed, and ClientThrottlingError shows REST requests that were rejected.
- Confirm throttling in metrics.
- Increase the provisioned size, or move up a tier.
- Spread load over several shares or accounts.
- Add retry with backoff and more parallelism in the client.
Take quiz
SuccessWithThrottling
NetworkError
AuthorizationError
ClientOtherError
enable soft delete
increase the provisioned size to raise IOPS limits
turn on cool tier
disable SMB signing on the share
40. Why is Azure Files slow with many small files?
Small files are dominated by metadata operations: create, open, set attributes and close. Each is a network round trip, so latency matters far more than bandwidth, and a standard HDD share is slowest at this.
- Use premium SSD shares and enable metadata caching where available.
- Copy in parallel with
robocopy /MTor AzCopy instead of a single thread. - Use SMB Multichannel and keep clients in the same region.
- Pack many tiny files into an archive when moving them and extract on the other side.
Measure with a small-file workload, because large-file throughput numbers will not predict this behaviour.
Take quiz
compression ratio
metadata operation latency
the account name length
the number of snapshots
/NP
/LOG
/MT
/MIR
41. Explain the execution flow of a file recall in Azure File Sync?
A recall happens when a user or app opens a tiered file. The file looks normal in Explorer, but its content is in the Azure file share, so the agent has to fetch it first.
sequenceDiagram
participant U as User App
participant F as Sync Filter Driver
participant A as Sync Agent
participant S as Azure File Share
U->>F: Open tiered file
F->>A: Request file data
A->>S: Download over HTTPS
S-->>A: File content
A-->>F: Write data to local disk
F-->>U: Return data to the app
- The app opens the file and the file system filter driver sees that it is a reparse point.
- The driver asks the agent to recall the content.
- The agent downloads it from the cloud endpoint over HTTPS and writes it back to the local volume.
- The data is returned to the app, and the file is now fully present again.
The file is tiered again later only if the policies select it. Large files can start streaming back before the whole download finishes, and the first-access delay depends on file size and bandwidth.
Take quiz
The storage account firewall
The domain controller
The Azure File Sync file system filter driver
A DNS forwarder
converted to a snapshot
permanently deleted from Azure
moved to the cool tier of the server
stored locally again until policies tier it
42. Explain the internal working of Azure File Sync change detection?
Azure File Sync detects changes differently on the server and in the cloud, and then reconciles both through sync sessions that upload and download only the changed data.
- Server side: the agent reads the Windows USN change journal on the volume, so local changes are noticed almost immediately and queued for upload.
- Cloud side: changes made directly in the Azure file share are found by a scheduled change detection job, which scans the share about once every 24 hours.
- Sync session: the server uploads its detected changes and downloads changes from the cloud, working through each server endpoint.
Because of the cloud scan interval, a file added straight to the share may not appear on the server for up to a day. You can trigger it sooner with Invoke-AzStorageSyncChangeDetection for a given path.
Take quiz
By an Azure Policy event
By a DNS notification
By polling every file hash hourly
By reading the NTFS USN change journal
About every 24 hours
Every 5 minutes
Every second
Only at agent install
43. How do you troubleshoot Azure File Sync not syncing?
Start from the portal, then the server, then the network. Work through the layers rather than guessing.
- In the Storage Sync Service, open the sync group and check the server endpoint health: last sync result, files not syncing and error codes.
- On the server, open Event Viewer under Applications and Services Logs > Microsoft > FileSync > Agent > Telemetry. Event 9102 summarises each sync session and 9121 reports per-item errors.
- Run
Debug-StorageSyncServer -Diagnoseon recent agent versions to check connectivity and registration. - Confirm outbound HTTPS 443 access and any proxy settings.
- Check free disk space, agent version, server time and unsupported file names or open handles.
| Symptom | Likely cause |
| Server shows offline | Agent service stopped, network or certificate issue |
| Some files never sync | Unsupported characters, locked files, path length |
| Sync is slow | Large first-time upload, limited bandwidth, antivirus scanning |
Fix the cause, then wait for the next session or trigger one. Per-item errors usually clear automatically after a successful retry.
Take quiz
9121
7036
1000
4624
21
443
2049
445 only
44. How do you troubleshoot mount failures to Azure Files?
Match the error to its layer: name resolution, network path, authentication or authorization.
| Error | Usual cause | Check or fix |
| System error 53 or 67 | Name cannot be resolved or path not found | DNS, private endpoint zone, typo in account name |
| System error 1231 | Network location unreachable, port 445 blocked | Test-NetConnection to port 445, NSG, ISP, VPN |
| Access denied (5) | Missing RBAC role or ACL | Share-level role and NTFS permissions |
| Error 1326 or 86 | Bad credentials | Use the storage account name as user, correct key |
| Linux: mount error(13) | Permission denied | Credentials file, SMB version, key rotation |
| Linux: mount error(115) | Connection timeout | Firewall, port 445, DNS |
Test-NetConnection -ComputerName myacct.file.core.windows.net -Port 445 nslookup myacct.file.core.windows.net
Microsoft also provides the AzFileDiagnostics script for Windows clients. Also check that Secure transfer required matches what the client can do, since SMB 2.1 cannot mount an encrypted-only account.
Take quiz
a full snapshot quota
outbound port 445 being unreachable
a missing tag on the account
an expired Entra license
mount error(28) only
mount error(2) only
mount error(13)
mount error(115)
45. How can you optimize Azure Files performance for IOPS-heavy workloads?
Remove the storage ceiling first, then remove client and network bottlenecks.
- Use premium SSD shares and provision enough capacity, because IOPS and throughput scale with provisioned size (a baseline plus a rate per GiB).
- Increase queue depth and parallelism on the client, since one thread cannot saturate a share.
- Enable SMB Multichannel and use VM sizes with enough network bandwidth and RSS-capable NICs.
- Keep the VM and the share in the same region and, if you use ZRS, in a matching zone where possible.
- Turn on metadata caching for metadata-heavy workloads.
- Split independent datasets across multiple shares so each has its own limits.
Validate with a tool such as fio or DiskSpd and compare against the Transactions and latency metrics. If the metrics show throttling, increase provisioning rather than tuning the client further.
Take quiz
Enable soft delete
Switch to the cool tier
Provision a larger share
Add a snapshot
It changes the account kind
It lowers the storage price
It disables throttling
A single thread cannot saturate the share limits
46. How do you design a disaster recovery strategy for Azure Files?
Start from RPO and RTO, then layer protections, because each one covers a different failure.
| Failure | Protection |
| Datacenter or zone loss | ZRS or GZRS |
| Region loss (standard) | GRS or GZRS, then account failover |
| Region loss (premium) | Replicate with AzCopy or Azure File Sync to a second account |
| Accidental file change or ransomware | Share snapshots and Azure Backup |
| Accidental share deletion | Soft delete |
Premium shares cannot use geo-redundancy, so cross-region copies must be scheduled by you. Document the runbook: failover, then validate DNS and mounts, reapply private endpoints and firewall rules in the recovery region, and confirm identity configuration works there.
Test the plan with a real restore at least once a year, since an untested backup is only an assumption.
Take quiz
GRS
SMB Multichannel
ZRS
Soft delete
Replicate it yourself, for example with AzCopy
Enable GZRS on the premium account
Turn on cool tier
Select RA-GRS
47. What happens when the same file changes on two Azure File Sync endpoints?
Azure File Sync does not lock files across endpoints. If the same file is changed in two places before a sync, one version wins and the other is kept as a conflict file.
The first change that reaches the sync service keeps the original name. The other is renamed with the endpoint name and a counter, such as Budget-Server02.xlsx or Budget-Server02-1.xlsx, and then synced so that every endpoint ends up with both copies.
Nothing is overwritten silently, but users must merge the content manually. To reduce conflicts, route teams to one endpoint per project, avoid editing the same documents from the cloud share and a server at once, and use a collaboration tool for co-authoring.
Take quiz
It is saved as a renamed conflict file and synced
It is silently overwritten
It is moved to cool tier
It is deleted at the next snapshot
Yes, through Azure RBAC
No, it has no cross-endpoint locking
Yes, using SMB leases only
Yes, but only for Office files
48. How would you design a secure Azure Files deployment for a regulated workload?
Layer controls so that no single setting is the only barrier. For a regulated workload, a solid baseline looks like this.
- Network: create a private endpoint, add the private DNS zone and set public network access to disabled.
- Identity: use identity-based SMB access through AD DS or Entra Kerberos, and assign RBAC to groups, not individuals.
- Keys: disable shared key access where your clients support identity-based access, and rotate keys otherwise.
- Protocol: require secure transfer and SMB 3.1.1 with AES-256-GCM, and block older SMB versions.
- Encryption: use customer-managed keys in Key Vault if policy demands key control.
- Protection: enable soft delete and Azure Backup, and consider Microsoft Defender for Storage for threat detection.
- Audit: send diagnostic logs to Log Analytics and alert on unusual access.
Document each control against the regulation's requirements so an auditor can trace it.
Take quiz
Selecting the hot tier
Disabling public network access with a private endpoint in place
Enabling soft delete
Turning off snapshots
lower storage prices
bigger file size limits
easier and auditable access management
faster snapshots
49. How does Kerberos authentication work for Azure Files with AD DS?
With AD DS, the storage account is represented by an account object in the domain that holds a service principal name such as cifs/myacct.file.core.windows.net. Clients use that SPN to get a Kerberos service ticket.
sequenceDiagram
participant C as Domain Joined Client
participant D as Domain Controller
participant S as Azure Files
C->>D: Request ticket for cifs SPN
D-->>C: Service ticket
C->>S: SMB session setup with ticket
S->>S: Validate ticket with account key
S->>S: Check share-level RBAC
S->>S: Check NTFS ACLs on access
S-->>C: Session granted
- The user signs in and gets a TGT from the domain controller.
- The client asks for a service ticket for the storage account SPN.
- The client presents the ticket during SMB session setup.
- Azure Files validates the ticket, evaluates the RBAC role, then the ACL on each file operation.
The client needs a line of sight to a domain controller, which is why remote users often need a VPN, or Entra Kerberos for hybrid identities.
Take quiz
A SAS token
A TLS client certificate from Azure Key Vault
A Kerberos service ticket for the storage account SPN
An account key
Tier and redundancy
DNS and DHCP
Snapshot count and quota
Share-level RBAC and then file-level ACLs
50. Which is better for hybrid file serving: Azure Files with File Sync or a Windows file server cluster, and why?
For most organisations, Azure Files with Azure File Sync is the better default. It removes the clustered storage you have to build and patch, and gives you cloud-based capacity, backup and DR, while the local server still gives LAN speed.
| Aspect | Azure Files plus File Sync | Windows file server cluster |
| Capacity growth | Cloud capacity, local disk used as cache | Buy and add local disks or SAN |
| Backup and DR | Azure Backup, snapshots, geo-redundancy | Separate backup and DR design |
| Multi-site | Many servers sync one cloud share | Replication tooling such as DFS-R |
| Operations | Agent and Azure management | Full cluster and storage administration |
| Cost model | Pay for cloud storage and transactions | Hardware and licences up front |
A cluster still makes sense when you must keep all data on-premises for compliance, have no usable internet link, or run apps that need features Azure Files does not offer. Even then, check whether Azure File Sync with a small cache could replace it.