Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| azure:azure_storage [2022/07/20 13:05] – ↷ Page moved from azure_storage to azure:azure_storage mmuze | azure:azure_storage [2026/09/22 18:41] (current) – [Azure Files] mmuze | ||
|---|---|---|---|
| Line 4: | Line 4: | ||
| ====== Azure Storage Accounts ====== | ====== Azure Storage Accounts ====== | ||
| * //storage accounts// provide the logical container/ | * //storage accounts// provide the logical container/ | ||
| + | * By default, storage accounts are accessible from any network, including the Internet. | ||
| + | * If Public Access is enabled, but limited to certain networks, VNet traffic to the storage accounts will go over the Microsoft backbone and not the Internet, even though it is still going to a public endpoint. | ||
| + | * Blob containers are the only storage type that supports anonymous (unauthenticated access) | ||
| ====== Blob Storage ====== | ====== Blob Storage ====== | ||
| > A massively scalable object store for text and binary data. Also includes support for big data analytics through Data Lake Storage Gen2. | > A massively scalable object store for text and binary data. Also includes support for big data analytics through Data Lake Storage Gen2. | ||
| Line 19: | Line 22: | ||
| ====== Azure Files ====== | ====== Azure Files ====== | ||
| //Azure Files// provides managed file shares that are accessible via //SMB// or //NFS//. | //Azure Files// provides managed file shares that are accessible via //SMB// or //NFS//. | ||
| + | |||
| + | If you disable the public endpoint for a storage account you can only browse the share from the Azure portal on a machine that can reach the private endpoint (private) IP address. | ||
| + | |||
| + | If you are using Entra Kerberos authentication for Azure Files shares ACL management is only supported in the Azure Portal, not the Windows File Explore or icacls CLI tool. | ||
| + | |||
| + | When you configure an Azure Files share to use Entra Kerberos for authentication an Enterprise App/Service Principle is created. Admin consent needs to be granted to it for authentication to be enabled. | ||
| ====== Queue Storage ====== | ====== Queue Storage ====== | ||
| Line 28: | Line 37: | ||
| ====== Azure Disks ====== | ====== Azure Disks ====== | ||
| > Block-level storage volumes for Azure VMs. | > Block-level storage volumes for Azure VMs. | ||
| + | |||
| + | ====== Access Control ====== | ||
| + | |||