Home / News & Releases / ANF Entra Kerberos preview

Azure NetApp Files previews Microsoft Entra Kerberos for SMB

Azure NetApp Files now previews SMB authentication for hybrid and cloud-only identities using cloud-issued Microsoft Entra Kerberos tickets. NetApp says SMB clients no longer need network line-of-sight to Active Directory Domain Services domain controllers in the authentication path.

Critical boundary This announcement is for Azure NetApp Files and is labeled preview. It does not announce Microsoft Entra ID as an SMB/NFS data-access identity provider for on-premises ONTAP.

AZURE NETAPP FILES SMB IDENTITY PREVIEW Sep 24, 2026

What changes in the authentication path

The client obtains a Kerberos ticket through Microsoft Entra ID and presents it for SMB access to Azure NetApp Files. Removing client-to-domain-controller line-of-sight can simplify routing and firewall dependencies for Entra-joined clients and cloud-first users. It does not remove the need to validate identity lifecycle, ticket issuance, authorization, DNS naming, time synchronization, share and NTFS permissions, or failure behavior.

The short product update does not state supported regions, client operating-system builds, cross-tenant behavior, identity synchronization rules, protocol dialects, private-endpoint requirements, limitations, service-level commitments, or a general-availability date. Those are deployment blockers to resolve in current Microsoft and NetApp preview documentation, not assumptions to fill in.

Do not transfer the claim to ONTAP

NetApp’s ONTAP knowledge base says ONTAP currently supports Active Directory Kerberos for SMB/NFS data access and does not publish a roadmap for direct Microsoft Entra ID, Local KDC, or IAKerb data authentication. Entra support for ONTAP administrative login is a different control-plane capability. Product name and authentication purpose matter here: ANF SMB data access, ONTAP SMB/NFS data access, and ONTAP administrator sign-in are three separate support statements.

A safe preview validation plan

  1. Confirm preview enrollment, supported region, ANF account and volume type, client build, tenant model, and identity prerequisites from the current service documentation.
  2. Capture successful Kerberos-only access for Entra-joined cloud-only and hybrid users; prove NTLM fallback is not masking a failure.
  3. Test group membership changes, disabled users, ticket expiry/renewal, clock skew, DNS aliases, permission denial, and reconnect after network interruption.
  4. Map the residual paths to Entra, Azure control plane, DNS, private endpoints, and ANF; test each dependency’s outage behavior.
  5. Keep a rollback path and avoid production SLA assumptions until GA terms, limits, support boundaries, and regional coverage are published.

Bottom line: the preview can remove a major domain-controller network dependency for eligible ANF SMB clients. It is not evidence that AD DS has disappeared from every identity workflow, nor that the same authentication model is available in ONTAP.

SMB/CIFS deep dive · NAS identity and authentication · Azure NetApp Files and ONTAP

Sources

NetApp product update: Microsoft Entra Kerberos authentication preview for ANF · NetApp KB: ONTAP data-access support boundary

← Back to the news index