Can an ONTAP CIFS server join MS Entra ID?
Applies to
- Azure NetApp Files (ANF) on ONTAP 9.16.1 and 9.17.1
- ONTAP 9.18.1 and newer on all platforms
- CIFS
- MS Entra ID
Answer
- Starting ONTAP 9.16 (Azure NetApp Files only) and ONTAP 9.18.1 (all ONTAP platforms), ONTAP supports CIFS access using a Microsoft Entra ID hybrid identity model.
- On-premises Active Directory Domain Services (AD DS) remains required as the identity source.
- This removes the need for network connectivity between ONTAP and an on-premises domain controller, not the need for on-premises AD DS itself.
Additional Information
- This is not a pure Microsoft Entra ID-only join, rather the solution requires a hybrid identity model:
- On-premises Active Directory Domain Services (AD DS) remains the authoritative identity source.
- Users are synchronized from on-premises AD DS to Microsoft Entra ID using Microsoft Entra Connect.
- Without this synchronization, Entra ID-joined clients cannot sign in as hybrid users to access the SMB share.
- Prior to ONTAP 9.18.1, this feature was supported only on Azure NetApp Files (ANF).
- Starting with ONTAP 9.18.1, it is supported on all ONTAP platforms.
- Identity prerequisites (customer directory side):
- A functioning on-premises AD DS environment where the users exist.
- A Microsoft Entra ID tenant.
- Microsoft Entra Connect configured to synchronize on-premises AD DS users to Entra ID.
- Microsoft Entra application prerequisites:
tenant_id: Entra tenant/directory ID.client_id: Application (client) ID from an Entra app registration with permission to create, modify, and delete additional Entra ID applications.client_certificate: Client certificate used for certificate-based authentication to Entra ID.
- The following commands will set up a new CIFS server with the hybrid Entra ID setup:
Cluster::> cifs server security modify -lm-compatibility-level krbCluster::> set -privilege diagnosticCluster::*> cifs create -vserver <SVM> -cifs-server <NETBIOS> -domain <AD_DOMAIN_FQDN> -auth-user-type hybrid-user -client-id "<client_id>" -tenant-id "<tenant_id>" -client-certificate "<client_certificate>"
- Create a CIFS server (ONTAP REST API documentation)
- Microsoft Documentation: How to find your Microsoft Entra tenant ID
- Microsoft Documentation: Register an application in Microsoft Entra ID
- Microsoft Documentation: New-SelfSignedCertificate
- Microsoft Documentation: Register a Microsoft Entra app and create a service principal
