MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.28k stars 21.46k forks source link

(Azure FileShare MacOsx) : Mounting method SMB share on mac, using access key is not secure #97002

Closed gusman7 closed 1 year ago

gusman7 commented 2 years ago

Hello team, Actual procedure delivered from microsoft (https://docs.microsoft.com/en-us/azure/storage/files/storage-how-to-use-files-mac) to mount a smb share on Finder use share account name and acces key.

This method is not really secure for exemple has it give a complete access to a global Storage account, Multiple shares and NTFS rights are bypassed.

In a company with more than 500 macs (this is our case) this not a secure industrial way to mount a share on mac.

Can you improve this feature to work same as windows/linux mapping without using acces key of storage account. (with access key method what is going on for rotation key, and full access to storage account)

Regards


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Grace-MacJones-MSFT commented 2 years ago

thanks for bringing this to our attention. Your feedback has been shared with the content owner for further review.

roygara commented 2 years ago

assign: khdownie

jithubhaijabs commented 1 year ago

@khdownie this is a feature request to add AD or similar authentication support against Azure Files for MacOS. Today only storage account key is supported. Customer could use Azure file sync as front-end, but I am not sure how much MacOS scenarios (AD auth/KDC proxy) will it cover and if this is officially supported/recommended workaround.

khdownie commented 1 year ago

@jithubhaijabs thanks for looking into this. I will route the feature request to the product team.

please-close