[AF 2.1] Build Sheet: Cloud-Native Identity for Azure Files

Named groups, real NTFS ACLs, the manifest tag, and the Conditional Access exclusion: the full identity build for an Azure file share with no domain controller.

Named groups, real NTFS ACLs, the manifest tag, and the Conditional Access exclusion: the full identity build for an Azure file share with no domain controller.

The identity source you pick for Azure Files is a one-per-account authority decision, and the right answer changed in May 2026. The four paths, the device matrix, and the MFA limitation nobody mentions.

From an empty subscription to a mounted drive letter with Kerberos sign-in, no domain controller required. The starter build for anyone who has never touched Azure Files.

The honest answer to "can Azure Files replace my file server" changed in 2026. Here is what the platform actually is now, and the three deployment postures I defend.

Cost views and budgets by tag, the subscription-vending checklist, the add-a-spoke runbook, and the monthly health and drift checks. The operating loop made concrete, and the final build sheet of the series.

The foundation is built; now it is operated and grown. Day-two cost management where the mandatory tags finally pay off, the where-does-new-X-go framework, and the series-closing argument that a real foundation grows by placement, not by rebuild.

Tags and locations assigned in audit, scanned, then promoted to deny; tag inheritance via Modify with remediation; the gateway subnet exempted; the crown jewels protected from deletion; and a test that a non-compliant resource is blocked and a compliant one accepted.

The management-group tree has organized, scoped, and inherited, but it has not yet refused anything. Policy is the enforcement layer: audit before deny, mandatory tags and inheritance, exemptions as designed carve-outs, and the tree finally saying no.