Remove User access to onprem Fileshare after migrating to Azure File Share

Ben Slade 20 Reputation points
2025-01-24T15:12:50.3233333+00:00

We have our on-premise file server syncing up to our Azure File Share with NTFS permissions all in place and an Entra SMB group created for all users ready to move access from onprem to the Azure share

My question is; when we come to remove user access to the onprem share, I was planning on removing the 'everyone' + 'authenticated users' AD user groups and then carry out a final sync and am concerned that this would break the current sync group relationship to allow the final sync

Is this the right approach when it comes to removing user access for the final syncronisation?

Thanks in advance

Azure Files
Azure Files
An Azure service that offers file shares in the cloud.
1,352 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Vinod Kumar Reddy Chilupuri 2,315 Reputation points Microsoft Vendor
    2025-01-27T03:54:20.54+00:00

    Hi @Ben Slade

    Welcome to Microsoft Q&A, thanks for posting your query.

    When migrating from an on-premises file share to Azure File Shares, it's important to carefully manage user access to ensure a smooth transition without disrupting the synchronization process

    Before removing user access to the on-premises file share, ensure the sync group relationship remains intact prior to the final synchronization to Azure File Share. Although removing the 'Everyone' and 'Authenticated Users' AD user groups may impact access, it should not disrupt the sync group relationship.

    To proceed safely, verify that all necessary data has been synced to Azure. Subsequently, you can remove user access. It is recommended to make the on-premises share read-only This prevents any modifications, deletions, or additions to the files during the final synchronization process. You can do this by adjusting the NTFS permissions or modifying the share permissions. or adjust the ACLs to prevent changes during the final sync. This ensures no new changes occur after initiating the final synchronization.

    Once you have confirmed that the final sync is complete and the data is stable, you can proceed to remove the 'Everyone' and 'Authenticated Users' groups from the on-premises file share. This step can be done safely since the data has already been synchronized. After the transition, monitor access to the Azure File Share to ensure that users can access the files as intended and that permissions are correctly applied.

    Additional Considerations:

    • Testing: If possible, conduct a test with a small group of users to ensure that the process works as expected before rolling it out to all users.
    • Documentation: Keep detailed documentation of the migration process, including any changes made to permissions and the steps taken during the final synchronization.
    • Backup: Consider backing up critical data before making significant changes to permissions or access.

    Hope the above answer helps! Please let us know do you have any further queries.


    Please do not forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members. 


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.