Skip to main content
NetApp Knowledge Base

Can an ONTAP CIFS server join MS Entra ID?

Views:
311
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

Applies to

  • Azure NetApp Files (ANF) on ONTAP 9.16.1 and 9.17.1
  • ONTAP 9.18.1 and newer on all platforms
  • CIFS
  • MS Entra ID

Answer

  • Starting ONTAP 9.16 (Azure NetApp Files only) and ONTAP 9.18.1 (all ONTAP platforms), ONTAP supports CIFS access using a Microsoft Entra ID hybrid identity model.
  • On-premises Active Directory Domain Services (AD DS) remains required as the identity source.
  • This removes the need for network connectivity between ONTAP and an on-premises domain controller, not the need for on-premises AD DS itself.

Additional Information

  • This is not a pure Microsoft Entra ID-only join, rather the solution requires a hybrid identity model:
    • On-premises Active Directory Domain Services (AD DS) remains the authoritative identity source.
    • Users are synchronized from on-premises AD DS to Microsoft Entra ID using Microsoft Entra Connect.
    • Without this synchronization, Entra ID-joined clients cannot sign in as hybrid users to access the SMB share.
  • Prior to ONTAP 9.18.1, this feature was supported only on Azure NetApp Files (ANF).
    • Starting with ONTAP 9.18.1, it is supported on all ONTAP platforms.
  • Identity prerequisites (customer directory side):
    • A functioning on-premises AD DS environment where the users exist.
    • A Microsoft Entra ID tenant.
    • Microsoft Entra Connect configured to synchronize on-premises AD DS users to Entra ID.
  • Microsoft Entra application prerequisites:
    • tenant_id: Entra tenant/directory ID.
    • client_id: Application (client) ID from an Entra app registration with permission to create, modify, and delete additional Entra ID applications.
    • client_certificate: Client certificate used for certificate-based authentication to Entra ID.
  • The following commands will set up a new CIFS server with the hybrid Entra ID setup:
    • Cluster::> cifs server security modify -lm-compatibility-level krb
      Cluster::> set -privilege diagnostic
      Cluster::*> cifs create -vserver <SVM> -cifs-server <NETBIOS> -domain <AD_DOMAIN_FQDN> -auth-user-type hybrid-user -client-id "<client_id>" -tenant-id "<tenant_id>" -client-certificate "<client_certificate>"
  • Create a CIFS server (ONTAP REST API documentation)
  • Microsoft Documentation: How to find your Microsoft Entra tenant ID
  • Microsoft Documentation: Register an application in Microsoft Entra ID
  • Microsoft Documentation: New-SelfSignedCertificate
  • Microsoft Documentation: Register a Microsoft Entra app and create a service principal
NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.