Skip to content

Commit ffd37de

Browse files
Merge pull request #313307 from MarcosJLR/patch-1
Clarification for group-based access for non-synced users
2 parents c80d74d + 314be6c commit ffd37de

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

articles/storage/files/storage-files-identity-assign-share-level-permissions.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -170,6 +170,9 @@ You can assign permissions to all authenticated Entra users and to specific Entr
170170

171171
## Understanding group-based access for non-synced users
172172

173+
> [!IMPORTANT]
174+
> This section applies only to Storage Accounts using Active Directory Domain Services (AD DS) authentication.
175+
173176
Users who aren't synced to Entra ID can still access Azure file shares through group membership. If a user belongs to an on-premises AD DS group that's synced to Entra ID and has an Azure RBAC role assignment, the user gets the group's permissions, even though they don't appear as a group member in the Microsoft Entra admin center.
174177

175178
Here's how it works:

0 commit comments

Comments
 (0)