DEV Community

Olalekan Oladiran
Olalekan Oladiran

Posted on

Implementing Secure and Efficient File Sharing Solutions for Geographically Dispersed Offices

How to establish and set up an Azure Files storage account.

  • In the market place search for storage account and select create
  • In the project details, select the resource group you just created
  • Under the instance details, supply the name for your storage account.
  • Change performance to Premium
  • Change Premium account type to File shares
  • Select Zone-redundant storage in the redundancy drop down
  • click review
  • Click create after passing validation
  • Wait for it to deploy
  • Click Go to resource

How to establish and set up a directory-based file share.

  • Select File shares in the Data storage section
  • Click + File share
  • Provide a name for the new file share
  • Leave other settings as default and click review + create
  • Once validation is passed, click create

How to include a directory in the shared file.

  • Click + Add directory in the file share overview page
  • Type the name for your directory and click ok
  • Select Browse in the overview section
  • Select the newly created directory
  • Click upload, select browse for file and then click upload again
  • Your file will be displayed under your directory

How to Set up and check snapshots.

-In the file share overview page, select snapshot under operation section

  • Click + Add snapshot
  • Note that the comment is optional. Click Ok
  • Click the snapshot and verify that both the directory and the uploaded file are included

Practice restoring a file using snapshots.

  • Go back to the file share, in the overview page, click browse
  • Click on the uploaded file and and click delete in the file properties
  • Click yes to confirm delete
  • Click snapshot in the operations section
  • Select the snapshot created before
  • Click on the file you want to restore and click restore
  • Supply a restored file name and click Ok
  • You can verify the restored file by navigating to your directory to check by clicking browse.

How to set up a storage access restriction to only certain virtual networks.

  • Search for virtual network and click create
  • Fill in the project details which comprises of Subscription and Resource group
  • Provide a name for your virtual network and leave other parameters as default
  • Click review + create
  • Click create once validation is passed
  • Once the deployment is complete, click go to resource
  • Under settings section, click subnets
  • Click default subnet
  • Tick Microsoft.Storage in the services drop-down under service endpoints section, leave other settings as default and click save

How to access the storage account through the virtual network you just established.

  • Go back to the files storage account and select Networking under Security + networking, select Enabled from selected virtual networks and IP addresses under public network access
  • Click Add existing virtual network under virtual network and click the drop-down under virtual network.
  • Tick your virtual network
  • Tick your subnet
  • Then click Add
  • Select Storage browser
  • Click File share
  • Click the file under file share
  • A pane showing This request is not authorized indicates that you are not connecting from the virtual network.

Top comments (1)

Collapse
 
scsoi profile image
疏影 •

Multi-site file sharing with proper access control is the right framing. The piece the article doesn't cover: 'how does the Windows user in office B actually see the files in Explorer once we've picked a backend?' Two patterns that close that gap:

  • SMB-over-VPN works but drops on flaky WAN; modern alternatives (SMB-over-WAN acceleration / Cloud Attached Storage / S3-compatible buckets with mount client) keep the same Explorer UX but with better failover. ScsDriver handles SMB / S3 / SFTP / WebDAV so the same mount table also carries any other backend the company standardized on. Auto-reconnect across sleep / VPN / 网卡切换 is what makes the per-site drive letter stick across a normal workday.
  • For offices where the link between sites is unreliable, treat the WAN like another network — the mount client has to handle it the same way as the LAN. We've found that's where most 'drive disconnected' tickets come from, not from the server side.

A few operational notes for geographically dispersed file shares:

  • DFS-R is great for read-mostly content but conflicts on write-heavy shares; pick the model carefully or accept the merge conflicts you'll see.
  • For SMB targets, mind the 'multiple connections to server' default on Windows; using distinct service accounts per destination side-steps it.
  • One mount client with multiple backends keeps the user mental model to one filesystem — net use for SMB + rclone for S3 ends up costing more in tickets than it saves. Good writeup.