Prev Next

Java / Azure Files Interview questions

Last updated

1. What is Azure Files? 2. What protocols does Azure Files support? 3. What are the storage tiers in Azure Files? 4. What are the redundancy options for Azure Files? 5. What is the purpose of a storage account for Azure Files? 6. What are the types of storage accounts used for Azure Files? 7. What are the size limits of an Azure file share? 8. How do you mount an Azure file share on Windows? 9. How do you mount an Azure file share on Linux? 10. What is Azure File Sync? 11. What are the components of Azure File Sync? 12. What is cloud tiering in Azure File Sync? 13. What is a share snapshot in Azure Files? 14. What is soft delete for Azure file shares? 15. What are the authentication options for Azure Files? 16. Why does port 445 matter for Azure Files? 17. How do you back up an Azure file share? 18. What is SMB Multichannel in Azure Files? 19. What are the common use cases of Azure Files? 20. How do you create an Azure file share using Azure CLI? 21. What is the difference between Azure Files and Azure Blob Storage? 22. What is the difference between standard and premium Azure file shares? 23. How does billing work for Azure Files? 24. How do you configure identity-based authentication for Azure Files SMB? 25. How do share-level and NTFS permissions work together in Azure Files? 26. How does Azure Files encrypt data at rest and in transit? 27. How do private endpoints secure access to Azure Files? 28. How can you access Azure Files when port 445 is blocked? 29. When should you choose NFS over SMB for Azure Files? 30. What is the difference between Azure Files and Azure NetApp Files? 31. When would you choose Azure File Sync over a direct mount? 32. How does cloud tiering decide which files to tier? 33. How do you migrate an on-premises file server to Azure Files? 34. How does Azure Files support FSLogix profile containers in Azure Virtual Desktop? 35. How do you mount Azure Files in Azure Kubernetes Service? 36. What is the difference between share snapshots and Azure Backup for file shares? 37. How does geo-redundancy work for Azure Files? 38. How do you monitor Azure Files performance? 39. What happens when an Azure file share is throttled? 40. Why is Azure Files slow with many small files? 41. Explain the execution flow of a file recall in Azure File Sync? 42. Explain the internal working of Azure File Sync change detection? 43. How do you troubleshoot Azure File Sync not syncing? 44. How do you troubleshoot mount failures to Azure Files? 45. How can you optimize Azure Files performance for IOPS-heavy workloads? 46. How do you design a disaster recovery strategy for Azure Files? 47. What happens when the same file changes on two Azure File Sync endpoints? 48. How would you design a secure Azure Files deployment for a regulated workload? 49. How does Kerberos authentication work for Azure Files with AD DS? 50. Which is better for hybrid file serving: Azure Files with File Sync or a Windows file server cluster, and why?

1. What is Azure Files?

Azure Files is a fully managed cloud file share service. You create a share in a storage account and access it over SMB, NFS or the REST API, much like a share on a traditional file server.

The same share can be mounted at the same time by Windows, Linux and macOS clients, whether they run in Azure or on-premises. That makes it a common landing spot for lift-and-shift of file servers.

Microsoft runs the underlying servers, so there is no OS to patch, no disks to replace and no cluster to build. You manage the share, its size, its permissions and its network access.

Take quiz
Azure Files is best described as:
a message queue for decoupled services
a block device attached to a single VM
a managed file share reachable over SMB, NFS and REST
a NoSQL document database
Who patches and maintains the servers behind an Azure file share?
The VM that mounts the share
The domain controller
You, through Windows Update on the storage account
Microsoft, because it is a managed service

2. What protocols does Azure Files support?

Azure Files supports SMB (2.1, 3.0 and 3.1.1), NFS 4.1 and the FileREST API over HTTPS.

SMB is the usual choice for Windows workloads and identity-based access. NFS targets Linux and Unix workloads that need POSIX semantics. REST is handy for tools such as AzCopy, Storage Explorer and your own code.

A single share is created for either SMB or NFS, never both. REST data-plane operations such as AzCopy transfers apply to SMB shares, while NFS shares are mounted by Linux clients and managed through the management plane, so check the current feature matrix before you rely on REST for NFS.

Take quiz
Can one Azure file share be accessed over both SMB and NFS at the same time?
Yes, if secure transfer is disabled
Yes, but only on the cool tier
Yes, by using two mount points
No, a share is created for one of the two protocols
Which NFS version do Azure file shares support?
NFS 4.1
NFS 4.2 only
NFS 3 only
NFS 2

3. What are the storage tiers in Azure Files?

Azure Files has four tiers. Three are standard (HDD-backed): transaction optimized, hot and cool. One is premium (SSD-backed).

Tier Media Best for
Transaction optimized HDD Transaction-heavy workloads that do not need SSD latency
Hot HDD General file sharing and Azure File Sync
Cool HDD Online archive and rarely accessed data
Premium SSD Databases, FSLogix profiles, latency-sensitive apps

Cooler tiers charge less for storage but more for transactions and access. You can move a standard share between standard tiers without recreating it.

Take quiz
Which Azure Files tier runs on SSD media?
Premium
Cool
Hot
Transaction optimized
The cool tier is a good fit for data that is:
needed with sub-millisecond latency
stored for long periods and accessed rarely
used as user profile containers
read thousands of times per second

4. What are the redundancy options for Azure Files?

Standard shares can use LRS, ZRS, GRS or GZRS. Premium shares are limited to LRS and ZRS.

  • LRS keeps three copies inside one datacenter.
  • ZRS spreads three copies across availability zones in one region.
  • GRS is LRS plus asynchronous copy to a paired region.
  • GZRS is ZRS in the primary region plus asynchronous copy to the paired region.

Pick the level from your recovery goals. If you need geo protection on a premium share, you have to replicate it yourself, for example with AzCopy or Azure File Sync.

Take quiz
Which redundancy options can a premium file share use?
LRS, ZRS and GRS
LRS and ZRS
GRS and GZRS
RA-GRS only
ZRS copies data across:
two paired regions
all regions in a geography
multiple availability zones in one region
three racks in one datacenter

5. What is the purpose of a storage account for Azure Files?

The storage account is the management and namespace boundary for your shares. Every share lives inside one, and the account decides the endpoint, the redundancy, the network rules and the authentication settings.

The file endpoint looks like <account>.file.core.windows.net. Settings such as firewall rules, private endpoints, secure transfer, encryption keys and identity-based authentication are applied at the account level and affect every share in it.

Some settings stay per share, for example the quota, the access tier and the protocol (SMB or NFS).

Take quiz
What is the file service endpoint of a storage account?
<account>.dfs.core.windows.net
<account>.queue.core.windows.net
<account>.file.core.windows.net
<account>.blob.core.windows.net
Which setting is applied at the storage account level rather than per file?
The file attributes
The last-modified time
The ACL of a single folder
Firewall and private endpoint rules

6. What are the types of storage accounts used for Azure Files?

Two account kinds host file shares: FileStorage for premium shares and general-purpose v2 (StorageV2) for standard shares.

A FileStorage account is dedicated to files on SSD media. A general-purpose v2 account can hold file shares next to blobs, queues and tables, which is convenient but means those services share the account's limits and network rules.

You cannot put a premium share in a general-purpose v2 account, and you cannot create standard shares in a FileStorage account.

Take quiz
Premium file shares require which account kind?
BlockBlobStorage
General-purpose v2
BlobStorage
FileStorage
A general-purpose v2 account can host:
file shares alongside blobs, queues and tables
only NFS shares
only premium SSD shares
only file shares

7. What are the size limits of an Azure file share?

A standard share defaults to 5 TiB. If you enable large file shares on the account, a share can grow to 100 TiB. Premium shares can also reach 100 TiB.

Item Limit
Standard share (default) 5 TiB
Share with large file shares enabled up to 100 TiB
Single file 4 TiB

Limits for IOPS, throughput and file counts change over time, so confirm them in the current Azure Files scalability targets before you size a design.

Take quiz
What is the maximum size of a single file in Azure Files?
4 TiB
100 TiB
1 TiB
5 TiB
To grow a standard share beyond 5 TiB you should:
switch the share to NFS
enable large file shares on the storage account
turn on soft delete
move the data to Blob Storage

8. How do you mount an Azure file share on Windows?

Use the UNC path \\<account>.file.core.windows.net\<share> and authenticate with the storage account key or an identity-based method. The portal's Connect blade generates the exact script.

cmdkey /add:myacct.file.core.windows.net /user:localhost\myacct /pass:<storage-key>
net use Z: \\myacct.file.core.windows.net\docs /persistent:Yes

The client needs outbound TCP 445 to the account. If your ISP or firewall blocks it, use a VPN, ExpressRoute or a private endpoint.

Take quiz
Which UNC format reaches an Azure file share?
smb://<account>.azure.com/<share>
\\<account>.file.core.windows.net\<share>
https://<account>.blob.core.windows.net/<share>
\\<account>.file.core.windows.net:443\<share>
Which outbound port must be open for an SMB mount?
3389
1433
445
2049

9. How do you mount an Azure file share on Linux?

Install cifs-utils, create a mount point, and mount with the CIFS driver using SMB 3.x. Keep the key in a root-only credentials file instead of on the command line.

  1. Install the helper: sudo apt install cifs-utils.
  2. Create the folder: sudo mkdir -p /mnt/docs.
  3. Store username and password in /etc/smbcredentials/myacct.cred with chmod 600.
  4. Mount the share with the command below.
sudo mount -t cifs //myacct.file.core.windows.net/docs /mnt/docs -o credentials=/etc/smbcredentials/myacct.cred,vers=3.1.1,dir_mode=0770,file_mode=0660,serverino

Add the same options to /etc/fstab with _netdev for a persistent mount.

Take quiz
Which package provides the CIFS mount helper on Ubuntu?
azure-cli
samba-common-bin only
cifs-utils
nfs-common
Where should credentials for a persistent mount be kept?
Inline in a world-readable fstab line
In the root folder of the share
In the shell history
In a root-only credentials file referenced from fstab

10. What is Azure File Sync?

Azure File Sync keeps a Windows Server file share in sync with an Azure file share. The server keeps hot files locally while the full dataset lives in Azure.

It lets you turn a file server into a fast local cache of Azure Files, with optional cloud tiering to save disk space. Several servers in different offices can sync to the same cloud share, so each site sees the same files.

An agent installed on Windows Server does the work, and it talks to Azure over HTTPS.

Take quiz
The Azure File Sync agent is installed on:
Azure Firewall
a Linux VM with cifs-utils
the storage account
Windows Server
A main benefit of Azure File Sync is:
local performance on a server while the full dataset lives in Azure
automatic conversion of SMB to NFS
removing the need for any network access
replacing identity providers

11. What are the components of Azure File Sync?

Azure File Sync has five moving parts: the Storage Sync Service, sync groups, cloud endpoints, server endpoints and the agent on registered servers.

Component What it is
Storage Sync Service Top-level Azure resource that holds sync groups and registered servers
Sync group Defines one set of files that stay in sync
Cloud endpoint The Azure file share inside a sync group
Server endpoint A path on a registered server inside a sync group
Agent Software on Windows Server that registers it and runs sync and tiering

A sync group has exactly one cloud endpoint and can have many server endpoints.

Take quiz
A cloud endpoint is:
the Azure file share in a sync group
the folder path being synced on the server
the storage account key
a public IP of the server
How many cloud endpoints can a sync group have?
One per server
One
Two, primary and secondary
Unlimited

12. What is cloud tiering in Azure File Sync?

Cloud tiering replaces rarely used files on the server with small pointers while the real content stays in the Azure file share. This frees local disk space without removing anything from the namespace.

Users still see every file. When someone opens a tiered file, the agent recalls the data from Azure on demand. Two policies control tiering: volume free space (keep at least X% free) and date (tier files not accessed for N days).

Take quiz
A tiered file on the server is:
a compressed zip kept locally
a pointer whose content is stored in Azure
moved to a different sync group
deleted from both server and cloud
The volume free space policy makes sure that:
the cloud share never exceeds its quota
files older than N days are deleted
a minimum percentage of the volume stays free
only the newest files are synced

13. What is a share snapshot in Azure Files?

A share snapshot is a read-only, point-in-time copy of an entire file share. It is incremental, so only changes since the previous snapshot take extra space.

You can have up to 200 snapshots per share. Users can browse them through the Previous Versions tab on Windows, or you can restore single files from the portal, PowerShell or AzCopy. Snapshots live in the same storage account as the share, so they do not replace a separate backup.

Take quiz
How many snapshots can a single share hold?
50
There is no limit
200
1,000
Share snapshots are:
deleted automatically after 24 hours
stored in a different region by default
writable full copies
read-only and incremental

14. What is soft delete for Azure file shares?

Soft delete keeps a deleted file share recoverable for a retention period instead of removing it right away. It protects against accidental deletion of the whole share, not individual files.

It is on by default for new accounts with a 7-day retention, which you can set between 1 and 365 days. During that window you can undelete the share, along with its snapshots, from the portal or CLI.

Take quiz
What is the default soft delete retention for file shares?
365 days
1 day
30 days
7 days
Soft delete for file shares mainly protects against:
accidental deletion of a whole share
a regional outage
a DDoS attack
a client mounting the wrong drive letter

15. What are the authentication options for Azure Files?

Azure Files supports storage account keys, shared access signatures (REST only) and identity-based access over SMB using Kerberos.

  • Account key: full access to every share in the account. Treat it like a root password.
  • SAS token: scoped and time-limited access through REST.
  • Identity-based: on-premises AD DS, Microsoft Entra Domain Services, or Microsoft Entra Kerberos for hybrid identities.

Identity-based access is preferred because it gives per-user permissions and an audit trail.

Take quiz
An account key grants:
full access to every share in the storage account
access only to the portal
access only to snapshots
read-only access to one file
Which option supports hybrid identities without line-of-sight to a domain controller?
NTLM over the public internet
Microsoft Entra Kerberos
SSH keys
Anonymous access

16. Why does port 445 matter for Azure Files?

SMB runs over TCP port 445. A client cannot mount an Azure file share over SMB unless it can reach the storage account on that port.

Many home ISPs, hotels and corporate firewalls block outbound 445 because of old SMB worms. The usual symptom on Windows is System error 53 or 1231. Test it with Test-NetConnection -ComputerName myacct.file.core.windows.net -Port 445.

If it fails, route traffic through a VPN, ExpressRoute or a private endpoint, or use Azure File Sync, which uses HTTPS.

Take quiz
Which symptom suggests outbound 445 is blocked on a Windows client?
The share silently becomes NFS
System error 53 or 1231 when running net use
A 403 from the portal
Files show as empty
Which PowerShell cmdlet tests reachability of port 445?
Set-NetFirewallRule
Get-SmbShare
Test-NetConnection
Get-AzStorageAccount

17. How do you back up an Azure file share?

Use Azure Backup. It schedules share snapshots through a backup policy and tracks them in a Recovery Services vault.

  1. Create or choose a Recovery Services vault in the same region.
  2. Create a backup policy with frequency and retention.
  3. Select the storage account and file shares to protect.
  4. Run an on-demand backup to verify, then test a restore.

You can restore a full share or individual files, to the original or an alternate location.

Take quiz
Azure Backup for file shares is built on:
VM disk images
tape export of the share
share snapshots managed by a policy
Cosmos DB change feed
Where do you configure the backup policy?
An Azure Site Recovery group
A Log Analytics workspace
A storage lifecycle rule
A Recovery Services vault

18. What is SMB Multichannel in Azure Files?

SMB Multichannel lets one SMB session use several network connections at once. That raises throughput and keeps the session alive if one connection fails.

It is supported on premium SMB shares with SMB 3.x clients and is enabled by default on FileStorage accounts. The client needs a NIC that supports Receive Side Scaling (RSS) to benefit, which most modern Azure VM sizes do.

It does not apply to NFS shares.

Take quiz
SMB Multichannel mainly improves:
snapshot size
file compression ratio
Entra sign-in speed
throughput and resiliency of a session
SMB Multichannel is available on:
premium SMB file shares
NFS shares
Azure Queue storage
Blob containers

19. What are the common use cases of Azure Files?

Azure Files is used wherever you need a shared folder without running a file server.

  • Lift and shift of on-premises file servers and mapped drives.
  • Shared configuration and tools mounted on many VMs.
  • FSLogix profile containers for Azure Virtual Desktop.
  • Persistent volumes for containers in AKS and Azure Container Instances.
  • Hybrid caching with Azure File Sync for branch offices.

It is not a good fit for hosting a relational database engine that expects raw block storage.

Take quiz
Which is a classic lift-and-shift scenario for Azure Files?
Replacing an on-premises Windows file server
Hosting a SQL engine's data files on raw blocks
Running a serverless function
Streaming IoT telemetry
How can many VMs read the same configuration files?
Store them in the VM's temp disk
Mount the same file share on every VM
Copy the files at each boot only
Attach one managed disk read-write to all VMs

20. How do you create an Azure file share using Azure CLI?

Create the storage account first, then the share. The share-rm group uses the Azure Resource Manager API, so no account key is needed.

az storage account create -n myacct -g rg-files -l eastus --sku Standard_LRS --kind StorageV2
az storage share-rm create --storage-account myacct -g rg-files --name docs --quota 1024 --access-tier Hot

--quota is the maximum size in GiB. For a premium share, create a FileStorage account with --sku Premium_LRS and the quota becomes the provisioned size you pay for.

Take quiz
Which command creates a share through the ARM API?
az file mount
az storage share-rm create
az share new
az storage fs create
What does the --quota parameter set?
The snapshot count
The number of files allowed
The maximum share size in GiB
The number of users

21. What is the difference between Azure Files and Azure Blob Storage?

Azure Files exposes a real file system (folders, locks, ACLs) over SMB and NFS. Blob Storage is an object store accessed mainly over HTTPS, with a flat namespace unless you enable hierarchical namespace.

Aspect Azure Files Azure Blob Storage
Access SMB, NFS, REST REST, SDKs, NFS 3.0 and SFTP on supported accounts
Structure Shares, directories, files Containers and blobs
Locking and ACLs Yes, native SMB semantics Limited, no SMB-style locking
Typical use Shared drives, app lift and shift, profiles Images, backups, data lakes, streaming

If an application expects a drive letter or a mount path with normal file semantics, pick Files. If it stores huge volumes of unstructured data and talks HTTP, pick Blob.

Take quiz
Which service gives native SMB file locking?
Azure Table Storage
Azure Queue Storage
Azure Files
Azure Blob Storage
A data lake of raw analytics files is usually better placed in:
Azure Files premium
A VM temp disk
Azure Files cool tier on a VM
Azure Blob Storage

22. What is the difference between standard and premium Azure file shares?

Standard shares run on HDD and bill mostly on what you use. Premium shares run on SSD, bill on what you provision and give low, consistent latency.

Aspect Standard Premium
Account kind General-purpose v2 FileStorage
Media HDD SSD
Billing Used capacity plus transactions Provisioned capacity
Redundancy LRS, ZRS, GRS, GZRS LRS, ZRS
Performance Shared, lower IOPS ceiling IOPS and throughput scale with provisioned size

Choose premium when latency or IOPS matter, such as for FSLogix, build agents or databases. Choose standard for general shares and archives.

Take quiz
Premium file shares are billed on:
only transactions
only egress traffic
the number of users
provisioned capacity
Which share type supports GRS?
Standard
Premium NFS only
Premium only
Neither

23. How does billing work for Azure Files?

The model depends on the share type. Standard pay-as-you-go charges for data stored (including snapshots), for transactions in blocks, and for outbound data. Premium charges for provisioned GiB, which also sets your IOPS and throughput.

Within standard, the tier moves the balance: transaction optimized has the lowest transaction price but a higher storage price, while cool is the reverse.

Azure also offers a provisioned v2 billing model, where you set storage, IOPS and throughput independently. Confirm availability and regions in the current pricing page before choosing it.

Take quiz
Which standard tier has the lowest per-transaction cost?
Transaction optimized
All three are equal
Hot
Cool
In the provisioned v2 model you can:
only change the region
set storage, IOPS and throughput separately
pay nothing for transactions and storage
only change redundancy

24. How do you configure identity-based authentication for Azure Files SMB?

You enable an identity source on the storage account, assign share-level permissions with Azure RBAC, then set file and folder permissions with Windows ACLs.

  1. Pick the source: AD DS, Microsoft Entra Domain Services or Microsoft Entra Kerberos for hybrid identities.
  2. Enable it on the account. For AD DS, run Join-AzStorageAccount (AzFilesHybrid module) to create the account object in the domain.
  3. Assign an RBAC role such as Storage File Data SMB Share Contributor to a user or group.
  4. Mount once with the account key and set NTFS permissions using Explorer or icacls.
  5. Mount again using the user's own identity.

Users also need network line-of-sight to a domain controller when the source is AD DS.

Take quiz
Which command-line step joins a storage account to AD DS?
Add-Computer -Domain only
Join-AzStorageAccount
az ad sp create
Set-AzVMExtension
File and folder level permissions are set with:
SAS token scopes
Azure Policy assignments
Windows ACLs such as icacls
Storage lifecycle rules

25. How do share-level and NTFS permissions work together in Azure Files?

Access is checked in two layers, and a user needs both to allow the action. The most restrictive result wins.

Layer Controlled by Scope
Share level Azure RBAC roles Entire share
File and folder level Windows ACLs (NTFS style) Individual directories and files

Three built-in roles cover most cases: SMB Share Reader, SMB Share Contributor and SMB Share Elevated Contributor. Only the elevated role can change ACLs. A common pattern is to give a group Contributor at share level and then let ACLs narrow access per folder.

Take quiz
Which RBAC role can modify NTFS ACLs on a share?
Reader
Storage File Data SMB Share Reader
Storage File Data SMB Share Elevated Contributor
Storage Queue Data Contributor
If the share-level role allows write but the folder ACL denies it, the user:
can write only on weekdays
can write, because RBAC overrides ACLs
can write, because ACLs are ignored over SMB
cannot write, because the most restrictive layer wins

26. How does Azure Files encrypt data at rest and in transit?

Data at rest is always encrypted with 256-bit AES through Storage Service Encryption. You can use Microsoft-managed keys or customer-managed keys held in Azure Key Vault.

In transit, SMB 3.x clients use SMB encryption (AES-128-GCM, and AES-256-GCM with 3.1.1), and REST calls use HTTPS. The account setting Secure transfer required rejects unencrypted connections.

Because SMB 2.1 cannot encrypt, an SMB 2.1 client can only mount from the same Azure region when secure transfer is disabled. Older Windows 7 or Server 2008 R2 clients are the usual cases.

Take quiz
What does the Secure transfer required setting do?
Blocks all REST calls
Forces cool tier
Disables Azure RBAC
Rejects connections that are not encrypted
Customer-managed keys for Azure Files are stored in:
Azure Key Vault
Azure Advisor
The file share itself
Azure Monitor

27. How do private endpoints secure access to Azure Files?

A private endpoint gives the storage account a private IP address inside your virtual network. Traffic to the file service stays on the Microsoft backbone and never crosses the public internet.

You also need DNS to resolve <account>.file.core.windows.net to that private IP, normally through the privatelink.file.core.windows.net private DNS zone. Once it works, you can disable public network access on the account.

Compared with service endpoints, a private endpoint is reachable from on-premises over VPN or ExpressRoute and gets a dedicated address, so it is the preferred choice for hybrid access.

Take quiz
Which private DNS zone is used for the file service?
privatelink.file.core.windows.net
privatelink.database.windows.net
privatelink.blob.core.windows.net
file.azure.local
After a private endpoint works, you can additionally:
disable encryption at rest
disable public network access on the account
switch the share to NFS
delete the share snapshots

28. How can you access Azure Files when port 445 is blocked?

You either avoid SMB over the open internet or use a path that does not depend on port 445.

  • VPN or ExpressRoute: reach a private endpoint over a private link, where 445 is not filtered.
  • Azure File Sync: the server talks to Azure over HTTPS (443), and users hit the local server.
  • REST tools: AzCopy and Storage Explorer use HTTPS.
  • Azure VMs: run the workload in Azure so SMB stays inside the network.

Asking the ISP to unblock 445 rarely works, so a VPN is the quickest fix for remote users.

Take quiz
Azure File Sync avoids the 445 problem because it uses:
Telnet
HTTPS between the server and Azure
FTP
NFS 4.1 only
Which tool can copy to a share without SMB?
mount -t cifs
net use
AzCopy over HTTPS
robocopy to a mapped drive only

29. When should you choose NFS over SMB for Azure Files?

Choose NFS for Linux or Unix workloads that need POSIX permissions, symbolic links and hard links. Choose SMB for Windows clients, identity-based permissions and in-transit encryption.

Need SMB NFS 4.1
Typical clients Windows, Linux, macOS Linux and Unix
Permissions Windows ACLs plus Entra or AD identity POSIX mode bits, no identity auth
Security model Kerberos, SMB encryption Network based: private or service endpoints
Redundancy and tiers Standard and premium Offered on premium (SSD); check the current docs

NFS shares require locking the network down, because access control relies on the VNet rather than a user identity.

Take quiz
What controls access to an NFS Azure file share?
SAS tokens
Storage account keys
Network rules such as private or service endpoints
Kerberos tickets from AD DS
A Windows-only user base with AD groups points to:
Blob SFTP
REST only
NFS with POSIX modes
SMB with identity-based authentication

30. What is the difference between Azure Files and Azure NetApp Files?

Both are managed file services, but they target different tiers of workload. Azure Files is the broad, cost-effective option. Azure NetApp Files is a high-performance service built on NetApp technology for demanding enterprise workloads.

Aspect Azure Files Azure NetApp Files
Positioning General file shares, lift and shift Latency-sensitive enterprise and HPC workloads
Protocols SMB, NFS 4.1, REST SMB, NFS 3 and 4.1, dual protocol
Capacity model Per share, pay as you go or provisioned Capacity pools with service levels
Cost Lower for typical shares Higher, justified by performance features

Pick Azure Files first. Move to NetApp Files when you need its sub-millisecond latency, dual-protocol access or specific application certifications.

Take quiz
Which service supports dual-protocol (SMB and NFS) access to the same data?
Azure Files
Azure Table Storage
Azure Blob Storage
Azure NetApp Files
The default choice for a general departmental file share is:
Azure Files
Azure NetApp Files
Azure Managed Disks
Azure Data Lake

31. When would you choose Azure File Sync over a direct mount?

Choose Azure File Sync when users or apps need local-speed access to files and the link to Azure is slow, shared or unreliable. Choose a direct mount when the clients run in Azure or have a fast, stable connection.

  • Branch offices that currently have their own file servers.
  • Large datasets where only a small hot subset is used often.
  • Several sites that need the same files kept consistent.
  • Gradual migration, where the server stays online while data moves to Azure.

File Sync adds a Windows Server to manage, so do not use it if a plain mount over VPN or ExpressRoute meets the latency target.

Take quiz
Which scenario best suits Azure File Sync?
A branch office needing local-speed access to cloud-hosted files
A serverless function reading one blob
A Linux container using NFS
A VM in Azure reading a share in the same region
Which scenario favours a direct mount?
Several sites needing a local cache
Azure VMs in the same region as the share
A remote office on a slow WAN link
A server with a small disk and a huge dataset

32. How does cloud tiering decide which files to tier?

The agent tracks a heat value per file, based on last access (reads and writes). The coldest files are tiered first.

  • Volume free space policy: when free space falls below the target percentage, the agent tiers the least recently accessed files until it reaches the target.
  • Date policy: files not accessed within N days are tiered, even if there is plenty of space.
  • Both together: a file is tiered when either condition requires it.

Very small files, roughly under 64 KiB, are not tiered, and files must be fully synced to Azure before they are eligible. After setup, the initial download mode decides whether new servers get only the namespace or also file contents.

Take quiz
Which policy keeps a minimum percentage of the volume empty?
Lifecycle policy
Volume free space policy
Date policy
Snapshot policy
A file is tiered when:
only when the server restarts
only when a user deletes it locally
either the free space or date policy requires it
only when both policies agree

33. How do you migrate an on-premises file server to Azure Files?

Pick a copy method based on size and downtime, then move data, permissions and users in that order.

  1. Assess: data size, file count, open files, ACL complexity, and bandwidth.
  2. Prepare: create the storage account, share and identity configuration.
  3. Copy: use Robocopy over SMB, AzCopy over HTTPS, Azure Storage Mover, or Azure File Sync to seed and sync. Use Data Box for very large offline transfers.
  4. Cut over: run a final delta pass, then repoint drive mappings or DFS namespaces.
robocopy D:\Data Z:\ /MIR /COPYALL /DCOPY:DAT /MT:16 /R:2 /W:1 /LOG:C:\mig.log

/MIR deletes files in the target that do not exist in the source, so use it carefully.

Take quiz
Which Robocopy switch mirrors the source and can delete target-only files?
/MT
/R
/MIR
/LOG
Which option suits very large offline transfers?
SAS tokens
SMB Multichannel
Soft delete
Azure Data Box

34. How does Azure Files support FSLogix profile containers in Azure Virtual Desktop?

FSLogix stores each user's profile as a VHD(X) file on an Azure file share. At sign-in, the file is mounted over SMB so the profile looks local to the session host.

Logon time depends on IOPS and latency, especially during a morning logon storm. That is why premium shares in the same region as the session hosts are the usual choice, with identity-based authentication so each user only reaches their own profile.

Set share-level RBAC for the host pool users group, then use NTFS ACLs so each profile folder is private to its owner. Add Cloud Cache only if you need multiple storage locations.

Take quiz
FSLogix stores a profile as:
a Cosmos DB document
a set of loose registry files only
a blob in a container
a VHD or VHDX file on the share
Why are premium shares often used for FSLogix?
They handle logon storms with low latency
They remove the need for identity
They store profiles in memory
They are the only tier that supports SMB

35. How do you mount Azure Files in Azure Kubernetes Service?

AKS ships with the Azure Files CSI driver. You request a volume with a PersistentVolumeClaim that references a storage class, and AKS creates the share and mounts it into the pod.

Built-in classes include azurefile-csi (standard) and azurefile-csi-premium. Use ReadWriteMany so many pods can use the same volume.

apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: shared-data
spec:
  accessModes: [ReadWriteMany]
  storageClassName: azurefile-csi-premium
  resources:
    requests:
      storage: 100Gi

Take quiz
Which access mode lets many pods read and write the same Azure Files volume?
ReadWriteMany
ReadOnlyOnce
ReadWriteOnce
WriteOnly
Which built-in storage class gives SSD-backed shares?
azurefile-csi
azurefile-csi-premium
azureblob-nfs-premium
managed-csi

36. What is the difference between share snapshots and Azure Backup for file shares?

A snapshot is a single point-in-time copy. Azure Backup is the management layer that creates snapshots on a schedule, keeps them according to a policy and records them in a vault.

Aspect Manual share snapshots Azure Backup
Scheduling You script it Policy based
Retention Up to 200 per share, you prune them Daily, weekly, monthly, yearly rules
Management Per share Central vault with reports and alerts
Deletion protection Anyone with rights can delete Vault guards against accidental removal of recovery points

For anything beyond ad hoc safety copies, use Azure Backup.

Take quiz
Which option provides policy-based retention such as weekly and yearly points?
Soft delete
Azure Backup
SAS tokens
A manual snapshot
The snapshot limit on a single share is:
2,000
20
200
Unlimited

37. How does geo-redundancy work for Azure Files?

With GRS or GZRS, the platform asynchronously copies your data to the paired region, where it is kept in LRS. Writes are acknowledged after they reach the primary, so a recent change can be lost in a disaster.

Unlike blobs, file shares do not offer a read-access secondary endpoint. The secondary is used only after failover. Microsoft can trigger it for a regional outage, and you can start a customer-managed failover on the account.

Check the Last Sync Time property before failing over to understand the possible data loss. After failover the account becomes LRS in the new primary region, and you must reconfigure geo-redundancy.

Take quiz
Why can data be lost during a geo failover?
SMB drops all files on reconnect
The paired region uses a different file system
Replication to the secondary is asynchronous
Snapshots are deleted at failover
Which property helps estimate possible data loss before failover?
Secure transfer required
Quota
Access tier
Last Sync Time

38. How do you monitor Azure Files performance?

Use Azure Monitor metrics for quick health checks and diagnostic logs for per-request detail.

  • Metrics: Transactions, Ingress, Egress, SuccessE2ELatency, SuccessServerLatency, FileCapacity, Availability. Split by the FileShare and ResponseType dimensions.
  • Logs: enable diagnostic settings for the file service and send StorageRead, StorageWrite and StorageDelete to Log Analytics.
  • Alerts: notify on throttling responses or when latency or capacity thresholds are crossed.
  • Storage insights: a ready-made workbook with trends across accounts.
StorageFileLogs
| where TimeGenerated > ago(1h)
| summarize count() by OperationName, StatusText
| order by count_ desc

Take quiz
Which dimension helps you see per-share activity in metrics?
QueueName
BlobType
TableName
FileShare
Per-request details come from:
Diagnostic logs sent to Log Analytics
The share's quota setting
Azure Advisor tips
Only the portal overview page

39. What happens when an Azure file share is throttled?

When requests exceed the share's IOPS or throughput limit, the service slows or rejects them. Clients see higher latency, and SMB operations may succeed but take longer.

In metrics, filter Transactions by ResponseType. SuccessWithThrottling shows SMB requests that were delayed, and ClientThrottlingError shows REST requests that were rejected.

  1. Confirm throttling in metrics.
  2. Increase the provisioned size, or move up a tier.
  3. Spread load over several shares or accounts.
  4. Add retry with backoff and more parallelism in the client.
Take quiz
Which ResponseType shows delayed SMB requests?
SuccessWithThrottling
NetworkError
AuthorizationError
ClientOtherError
A premium share is throttled. A direct fix is to:
enable soft delete
increase the provisioned size to raise IOPS limits
turn on cool tier
disable SMB signing on the share

40. Why is Azure Files slow with many small files?

Small files are dominated by metadata operations: create, open, set attributes and close. Each is a network round trip, so latency matters far more than bandwidth, and a standard HDD share is slowest at this.

  • Use premium SSD shares and enable metadata caching where available.
  • Copy in parallel with robocopy /MT or AzCopy instead of a single thread.
  • Use SMB Multichannel and keep clients in the same region.
  • Pack many tiny files into an archive when moving them and extract on the other side.

Measure with a small-file workload, because large-file throughput numbers will not predict this behaviour.

Take quiz
Small-file workloads are limited mainly by:
compression ratio
metadata operation latency
the account name length
the number of snapshots
Which Robocopy switch increases copy parallelism?
/NP
/LOG
/MT
/MIR

41. Explain the execution flow of a file recall in Azure File Sync?

A recall happens when a user or app opens a tiered file. The file looks normal in Explorer, but its content is in the Azure file share, so the agent has to fetch it first.

sequenceDiagram
    participant U as User App
    participant F as Sync Filter Driver
    participant A as Sync Agent
    participant S as Azure File Share
    U->>F: Open tiered file
    F->>A: Request file data
    A->>S: Download over HTTPS
    S-->>A: File content
    A-->>F: Write data to local disk
    F-->>U: Return data to the app
  1. The app opens the file and the file system filter driver sees that it is a reparse point.
  2. The driver asks the agent to recall the content.
  3. The agent downloads it from the cloud endpoint over HTTPS and writes it back to the local volume.
  4. The data is returned to the app, and the file is now fully present again.

The file is tiered again later only if the policies select it. Large files can start streaming back before the whole download finishes, and the first-access delay depends on file size and bandwidth.

Take quiz
What intercepts a read of a tiered file on the server?
The storage account firewall
The domain controller
The Azure File Sync file system filter driver
A DNS forwarder
After a successful recall, the file is:
converted to a snapshot
permanently deleted from Azure
moved to the cool tier of the server
stored locally again until policies tier it

42. Explain the internal working of Azure File Sync change detection?

Azure File Sync detects changes differently on the server and in the cloud, and then reconciles both through sync sessions that upload and download only the changed data.

  • Server side: the agent reads the Windows USN change journal on the volume, so local changes are noticed almost immediately and queued for upload.
  • Cloud side: changes made directly in the Azure file share are found by a scheduled change detection job, which scans the share about once every 24 hours.
  • Sync session: the server uploads its detected changes and downloads changes from the cloud, working through each server endpoint.

Because of the cloud scan interval, a file added straight to the share may not appear on the server for up to a day. You can trigger it sooner with Invoke-AzStorageSyncChangeDetection for a given path.

Take quiz
How does the server learn about local file changes?
By an Azure Policy event
By a DNS notification
By polling every file hash hourly
By reading the NTFS USN change journal
How often does the cloud share scan run by default?
About every 24 hours
Every 5 minutes
Every second
Only at agent install

43. How do you troubleshoot Azure File Sync not syncing?

Start from the portal, then the server, then the network. Work through the layers rather than guessing.

  1. In the Storage Sync Service, open the sync group and check the server endpoint health: last sync result, files not syncing and error codes.
  2. On the server, open Event Viewer under Applications and Services Logs > Microsoft > FileSync > Agent > Telemetry. Event 9102 summarises each sync session and 9121 reports per-item errors.
  3. Run Debug-StorageSyncServer -Diagnose on recent agent versions to check connectivity and registration.
  4. Confirm outbound HTTPS 443 access and any proxy settings.
  5. Check free disk space, agent version, server time and unsupported file names or open handles.
Symptom Likely cause
Server shows offline Agent service stopped, network or certificate issue
Some files never sync Unsupported characters, locked files, path length
Sync is slow Large first-time upload, limited bandwidth, antivirus scanning

Fix the cause, then wait for the next session or trigger one. Per-item errors usually clear automatically after a successful retry.

Take quiz
Which event ID in the Telemetry log reports per-item sync errors?
9121
7036
1000
4624
Which network port must the server be able to reach for sync?
21
443
2049
445 only

44. How do you troubleshoot mount failures to Azure Files?

Match the error to its layer: name resolution, network path, authentication or authorization.

Error Usual cause Check or fix
System error 53 or 67 Name cannot be resolved or path not found DNS, private endpoint zone, typo in account name
System error 1231 Network location unreachable, port 445 blocked Test-NetConnection to port 445, NSG, ISP, VPN
Access denied (5) Missing RBAC role or ACL Share-level role and NTFS permissions
Error 1326 or 86 Bad credentials Use the storage account name as user, correct key
Linux: mount error(13) Permission denied Credentials file, SMB version, key rotation
Linux: mount error(115) Connection timeout Firewall, port 445, DNS

Test-NetConnection -ComputerName myacct.file.core.windows.net -Port 445
nslookup myacct.file.core.windows.net

Microsoft also provides the AzFileDiagnostics script for Windows clients. Also check that Secure transfer required matches what the client can do, since SMB 2.1 cannot mount an encrypted-only account.

Take quiz
System error 1231 most often points to:
a full snapshot quota
outbound port 445 being unreachable
a missing tag on the account
an expired Entra license
Which Linux error means permission denied?
mount error(28) only
mount error(2) only
mount error(13)
mount error(115)

45. How can you optimize Azure Files performance for IOPS-heavy workloads?

Remove the storage ceiling first, then remove client and network bottlenecks.

  1. Use premium SSD shares and provision enough capacity, because IOPS and throughput scale with provisioned size (a baseline plus a rate per GiB).
  2. Increase queue depth and parallelism on the client, since one thread cannot saturate a share.
  3. Enable SMB Multichannel and use VM sizes with enough network bandwidth and RSS-capable NICs.
  4. Keep the VM and the share in the same region and, if you use ZRS, in a matching zone where possible.
  5. Turn on metadata caching for metadata-heavy workloads.
  6. Split independent datasets across multiple shares so each has its own limits.

Validate with a tool such as fio or DiskSpd and compare against the Transactions and latency metrics. If the metrics show throttling, increase provisioning rather than tuning the client further.

Take quiz
What is the first lever for more IOPS on a premium share?
Enable soft delete
Switch to the cool tier
Provision a larger share
Add a snapshot
Why raise client parallelism?
It changes the account kind
It lowers the storage price
It disables throttling
A single thread cannot saturate the share limits

46. How do you design a disaster recovery strategy for Azure Files?

Start from RPO and RTO, then layer protections, because each one covers a different failure.

Failure Protection
Datacenter or zone loss ZRS or GZRS
Region loss (standard) GRS or GZRS, then account failover
Region loss (premium) Replicate with AzCopy or Azure File Sync to a second account
Accidental file change or ransomware Share snapshots and Azure Backup
Accidental share deletion Soft delete

Premium shares cannot use geo-redundancy, so cross-region copies must be scheduled by you. Document the runbook: failover, then validate DNS and mounts, reapply private endpoints and firewall rules in the recovery region, and confirm identity configuration works there.

Test the plan with a real restore at least once a year, since an untested backup is only an assumption.

Take quiz
Which feature protects against accidental share deletion?
GRS
SMB Multichannel
ZRS
Soft delete
How do you get geo protection for a premium share?
Replicate it yourself, for example with AzCopy
Enable GZRS on the premium account
Turn on cool tier
Select RA-GRS

47. What happens when the same file changes on two Azure File Sync endpoints?

Azure File Sync does not lock files across endpoints. If the same file is changed in two places before a sync, one version wins and the other is kept as a conflict file.

The first change that reaches the sync service keeps the original name. The other is renamed with the endpoint name and a counter, such as Budget-Server02.xlsx or Budget-Server02-1.xlsx, and then synced so that every endpoint ends up with both copies.

Nothing is overwritten silently, but users must merge the content manually. To reduce conflicts, route teams to one endpoint per project, avoid editing the same documents from the cloud share and a server at once, and use a collaboration tool for co-authoring.

Take quiz
What happens to the losing version of a conflicting file?
It is saved as a renamed conflict file and synced
It is silently overwritten
It is moved to cool tier
It is deleted at the next snapshot
Does Azure File Sync lock a file across all endpoints while it is open?
Yes, through Azure RBAC
No, it has no cross-endpoint locking
Yes, using SMB leases only
Yes, but only for Office files

48. How would you design a secure Azure Files deployment for a regulated workload?

Layer controls so that no single setting is the only barrier. For a regulated workload, a solid baseline looks like this.

  1. Network: create a private endpoint, add the private DNS zone and set public network access to disabled.
  2. Identity: use identity-based SMB access through AD DS or Entra Kerberos, and assign RBAC to groups, not individuals.
  3. Keys: disable shared key access where your clients support identity-based access, and rotate keys otherwise.
  4. Protocol: require secure transfer and SMB 3.1.1 with AES-256-GCM, and block older SMB versions.
  5. Encryption: use customer-managed keys in Key Vault if policy demands key control.
  6. Protection: enable soft delete and Azure Backup, and consider Microsoft Defender for Storage for threat detection.
  7. Audit: send diagnostic logs to Log Analytics and alert on unusual access.

Document each control against the regulation's requirements so an auditor can trace it.

Take quiz
Which setting stops the account being reachable over the public internet?
Selecting the hot tier
Disabling public network access with a private endpoint in place
Enabling soft delete
Turning off snapshots
Assigning RBAC to groups rather than individuals mainly helps with:
lower storage prices
bigger file size limits
easier and auditable access management
faster snapshots

49. How does Kerberos authentication work for Azure Files with AD DS?

With AD DS, the storage account is represented by an account object in the domain that holds a service principal name such as cifs/myacct.file.core.windows.net. Clients use that SPN to get a Kerberos service ticket.

sequenceDiagram
    participant C as Domain Joined Client
    participant D as Domain Controller
    participant S as Azure Files
    C->>D: Request ticket for cifs SPN
    D-->>C: Service ticket
    C->>S: SMB session setup with ticket
    S->>S: Validate ticket with account key
    S->>S: Check share-level RBAC
    S->>S: Check NTFS ACLs on access
    S-->>C: Session granted
  1. The user signs in and gets a TGT from the domain controller.
  2. The client asks for a service ticket for the storage account SPN.
  3. The client presents the ticket during SMB session setup.
  4. Azure Files validates the ticket, evaluates the RBAC role, then the ACL on each file operation.

The client needs a line of sight to a domain controller, which is why remote users often need a VPN, or Entra Kerberos for hybrid identities.

Take quiz
What does the client request from the domain controller to reach the share?
A SAS token
A TLS client certificate from Azure Key Vault
A Kerberos service ticket for the storage account SPN
An account key
Which two checks come after the ticket is validated?
Tier and redundancy
DNS and DHCP
Snapshot count and quota
Share-level RBAC and then file-level ACLs

50. Which is better for hybrid file serving: Azure Files with File Sync or a Windows file server cluster, and why?

For most organisations, Azure Files with Azure File Sync is the better default. It removes the clustered storage you have to build and patch, and gives you cloud-based capacity, backup and DR, while the local server still gives LAN speed.

Aspect Azure Files plus File Sync Windows file server cluster
Capacity growth Cloud capacity, local disk used as cache Buy and add local disks or SAN
Backup and DR Azure Backup, snapshots, geo-redundancy Separate backup and DR design
Multi-site Many servers sync one cloud share Replication tooling such as DFS-R
Operations Agent and Azure management Full cluster and storage administration
Cost model Pay for cloud storage and transactions Hardware and licences up front

A cluster still makes sense when you must keep all data on-premises for compliance, have no usable internet link, or run apps that need features Azure Files does not offer. Even then, check whether Azure File Sync with a small cache could replace it.

Take quiz
A key reason to prefer Azure File Sync over a cluster is:
it stores data only on local disks
it removes the need for any network
it needs no Windows Server at all
no clustered storage to build and maintain, plus built-in cloud backup and DR
When does an on-premises cluster remain a valid choice?
When data must stay entirely on-premises
When you want geo-redundancy by default
When you want less operational work
When you want cloud tiering
«
»

Comments & Discussions