Authentication Issues using AAD Kerberos for Azure file shares

Benjamin Ra 31 Reputation points
2022-09-30T17:39:54.11+00:00

I have ran and re-ran through the prerequisites.
"The Azure AD Kerberos functionality for hybrid identities is only available on the following operating systems:

Windows 11 Enterprise single or multi-session.  
Windows 10 Enterprise single or multi-session, versions 2004 or later with the latest cumulative updates installed, especially the KB5007253 - 2021-11 Cumulative Update Preview for Windows 10.  
Windows Server, version 2022 with the latest cumulative updates installed, especially the KB5007254 - 2021-11 Cumulative Update Preview for Microsoft server operating system version 21H2.  

To learn how to create and configure a Windows VM and log in by using Azure AD-based authentication, see Log in to a Windows virtual machine in Azure by using Azure AD.

This feature doesn't currently support user accounts that you create and manage solely in Azure AD. User accounts must be hybrid user identities, which means you'll also need AD DS and Azure AD Connect. You must create these accounts in Active Directory and sync them to Azure AD. To assign Azure Role-Based Access Control (RBAC) permissions for the Azure file share to a user group, you must create the group in Active Directory and sync it to Azure AD.

You must disable multi-factor authentication (MFA) on the Azure AD app representing the storage account.

Azure AD Kerberos authentication only supports using AES-256 encryption."

I have a test environment.
and trying to use an Azure VM to authenticate to AAD.

get error:
C:\Users\username>net use n: \StorageAccount.file.core.windows.net\FileShare
Enter the user name for 'StorageAccount.file.core.windows.net': ******@modeluemlab.com
Enter the password for StorageAccount.file.core.windows.net:
System error 86 has occurred.

The specified network password is not correct.

I can connected through the share access key with the username being the azure\StorageAccount

Azure Storage
Azure Storage

Globally unique resources that provide access to data management services and serve as the parent namespace for the services.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

7 answers

Sort by: Newest
  1. Michael Patrick Richter 5 Reputation points
    2024-03-08T17:55:22.3633333+00:00

    For us, it was Cloud Kerberos Tickets not arriving, because a mistake in Entra Connect Setup, because of that it was not able to match the account logging on to the on-prem machine and the account in Entra. Thus no Kerberos Ticket was issued to the Client even though the Reg entry was done.

    Was this answer helpful?


  2. Phillip Jeffrey Hurley 0 Reputation points
    2023-10-31T09:45:38.04+00:00

    I had the exact same issue described here but the fix was to allow the traffic through the firewall.

    so strange how these errors manifest.

    Was this answer helpful?

    0 comments No comments

  3. Mike Crowley 216 Reputation points
    2023-06-28T00:14:55.5266667+00:00

    Also worth mentioning that if you use 'Windows Hello', make sure you sign in with a password not the pin, since this doesn't normally work with AD authentication on any day.

    This matters if you're using NTLM, since that requires a cached password, however its not required for Azure Kerberos. Windows Hello / Pin is fine.

    Was this answer helpful?

    0 comments No comments

  4. Chris Robb 16 Reputation points
    2022-11-15T11:41:19.583+00:00

    It's going to sound super stupid but I think I found my issue.

    Despite following the documentation strictly and reading if over and over. I went back to basics. Seeing error 86 every time I tried to map the share, spent a whole day trying to figure out what was going on.

    My share was set up to deny access, explicit allow on a particular local AD group (Sync to AzureAD).

    What I hadn't accounted for was configuring NTFS permissions on the share as well. So I logged in as another dummy account, mapped the drive using the Storage Account Key and then set NTFS permissions for the same AzureAD Group but using the local AD Group as the target.

    Logged back in as my original user and the drive mapped straight away.

    I'm just confirming that this is working as expected; and not somehow using a cached storage key. As I believe the storage key gives you 'superuser' access, and the user was only able to read which is how I've configured share/ntfs. So looking good.

    Hope this helps someone else.

    Was this answer helpful?

    0 comments No comments

  5. Tom Luxton 81 Reputation points
    2022-10-05T17:31:51.177+00:00

    Got it working.

    My colleague spotted that you need Windows 10 Enterprise rather than Win 10 Pro. Either that, or the the build wasn't high enough.

    After deploying a new Win 10 Enterprise 21H2 19044.2006 and adding the registry key: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters /v CloudKerberosTicketRetrievalEnabled /t REG_DWORD /d 1, it connected immediately with no credentials or line of site from AD.

    Also worth noting that the machine needs to be Azure AD Joined (not registered), by setting up for an organization.

    References:

    The Azure AD Kerberos functionality for hybrid identities is only available on the following operating systems:
    Windows 11 Enterprise single or multi-session.
    Windows 10 Enterprise single or multi-session, versions 2004 or later with the latest cumulative updates installed, especially the KB5007253 - 2021-11 Cumulative Update Preview for Windows 10.
    Windows Server, version 2022 with the latest cumulative updates installed, especially the KB5007254 - 2021-11 Cumulative Update Preview for Microsoft server operating system version 21H2.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.