Protocol for Windows file shares, used by Azure Files and supporting authentication based on identity.
Also called Server Message Block.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-5002V0-17.25AZ-900AI-200DP-900SC-200SC-300AZ-802SC-401
Each book explains SMB in context, with comparison tables and the common traps.
Terms in this definition
- Azure Files
Azure's managed file shares over SMB or NFS. There is no Archive tier, and a single encryption key applies across the whole storage account.
- Authentication
Checking an identity claim made by a person, device or app, for instance by asking for a password plus an extra factor. Authorisation only happens once this step has succeeded.
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
Related terms
- Access-based enumeration
When turned on for an SMB share or a DFS namespace, users only see the files, folders and links they're allowed to read; everything else is hidden from them.
- Access this computer from the network
Accounts holding this user right can connect across the network, to SMB shares for instance.
- AD DS authentication (Azure Files)
Option that domain-joins a storage account to on-premises AD DS, letting synced hybrid users mount its SMB shares using Kerberos. RBAC controls share-level access, while Windows ACLs govern files and folders.
- Azure Files OAuth over REST
Capability allowing Microsoft Entra users, groups and managed identities to use OAuth tokens against the FileREST data API. The roles that grant it carry
readFileBackupSemanticsorwriteFileBackupSemantics; the SMB share roles don't apply. - Azure NetApp Files
Azure service offering managed file volumes over NFS and SMB.
- Continuous availability
Clustered file servers can give SMB 3 shares this property so that clients keep going uninterrupted when the share fails over between nodes.
- Default share-level permission
Account-wide option granting one SMB share role to all authenticated identities on every file share, so individual users don't need their own assignments.
- Default to Microsoft Entra authorization in the Azure portal
When enabled on a storage account, the portal accesses data with the signed-in user's Entra identity instead of keys. Identity-based SMB access does not depend on it.