[AF 6.1] Build Sheet: The Migration Run

RoboCopy with the right flags, root ACLs set before the bulk copy, incremental passes, a short freeze, and a DFS-N cutover: the enterprise migration executed end to end.

RoboCopy with the right flags, root ACLs set before the bulk copy, incremental passes, a short freeze, and a DFS-N cutover: the enterprise migration executed end to end.

File server migrations fail on permissions and sequencing, not on copying bytes. What actually survives the move, which SIDs go dead on arrival, and the order of operations that makes cutover boring.

Storage Sync Service, agent, sync group, cloud tiering, and a DFS namespace in front: the full hybrid cache build, including the conflict test you should run on purpose.

Azure File Sync turns the file server you already own into a local cache of a cloud share. It solves latency and the port 445 problem in one move, and it has three limits you must respect.

The billing model, not the technology, generated most Azure Files horror stories. Provisioned v2 replaces the transaction lottery with three dials you set on purpose.

The no-VPN remote access build: the share private endpoint published through Entra Private Access, with Conditional Access and MFA standing in front of the SMB tunnel.

The S2S VPN posture built end to end. Private endpoint, the privatelink DNS zone, on-prem resolution, a closed storage firewall, and hardened SMB, plus the Entra Kerberos step that teaches the storage application its private-link SPNs so mounts get a ticket instead of error 1326.

Yes, Azure Files is literally SMB on port 445 to a public endpoint. Whether that should scare you depends on facts most people arguing about it do not have.