{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design/",
        "slug": "dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design/"
        },
        "title": "Check Elastic SAN's iSCSI feature exclusions before copying a target design",
        "summary": "Can an existing CHAP-dependent iSCSI design be moved unchanged to Azure Elastic SAN?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:39+00:00",
        "modified_at": "2026-09-10T00:52:39+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 230,
        "potentially_affected": "Use this compatibility gate before moving an existing iSCSI workload to Elastic SAN. Identify the source target's actual authentication, recovery and target-to-LUN assumptions; protocol naming alone does not establish equivalent features.",
        "dse_recommendation": "Make unsupported initiator assumptions an explicit migration decision.",
        "primary_source": {
            "name": "Plan for an Azure Elastic SAN deployment | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-planning",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Azure Elastic SAN supports iSCSI but does not support CHAP authorization or initiator registration. Microsoft also lists iSCSI Error Recovery Levels 1 and 2 and more than one LUN per target as unsupported. Network access is configured at the volume-group level through private endpoints or service endpoints, and volumes inherit that configuration. <a href=\"https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-planning\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this compatibility gate before moving an existing iSCSI workload to Elastic SAN. Identify the source target&#8217;s actual authentication, recovery and target-to-LUN assumptions; protocol naming alone does not establish equivalent features.</p>\n<h2>DSE recommendation</h2>\n<p>Make unsupported initiator assumptions an explicit migration decision. Have the storage and security owners compare the existing design with Elastic SAN&#8217;s current support list. If CHAP or another excluded feature is required by the approved architecture, do not remove that requirement silently to make a connection succeed. Assess whether a separately approved network and access design can meet the workload&#8217;s needs, or whether another target service is required.</p>\n<h2>Verification</h2>\n<p>In a controlled pilot, inspect the intended volume-group network boundary and the initiator&#8217;s target configuration. Test the agreed permitted and denied client paths and the application&#8217;s recovery behavior using the supported feature set. Record every requirement that remains unmet. Do not accept a basic iSCSI login as evidence that CHAP, initiator registration or advanced recovery behavior was preserved from the source system.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-planning\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Plan for an Azure Elastic SAN deployment</a>.</p>",
        "content_text": "Source facts\nAzure Elastic SAN supports iSCSI but does not support CHAP authorization or initiator registration. Microsoft also lists iSCSI Error Recovery Levels 1 and 2 and more than one LUN per target as unsupported. Network access is configured at the volume-group level through private endpoints or service endpoints, and volumes inherit that configuration. Microsoft Learn.\nApplicability\nUse this compatibility gate before moving an existing iSCSI workload to Elastic SAN. Identify the source target’s actual authentication, recovery and target-to-LUN assumptions; protocol naming alone does not establish equivalent features.\nDSE recommendation\nMake unsupported initiator assumptions an explicit migration decision. Have the storage and security owners compare the existing design with Elastic SAN’s current support list. If CHAP or another excluded feature is required by the approved architecture, do not remove that requirement silently to make a connection succeed. Assess whether a separately approved network and access design can meet the workload’s needs, or whether another target service is required.\nVerification\nIn a controlled pilot, inspect the intended volume-group network boundary and the initiator’s target configuration. Test the agreed permitted and denied client paths and the application’s recovery behavior using the supported feature set. Record every requirement that remains unmet. Do not accept a basic iSCSI login as evidence that CHAP, initiator registration or advanced recovery behavior was preserved from the source system.\nOfficial references\nMicrosoft Learn: Plan for an Azure Elastic SAN deployment.",
        "content_markdown": "## Source facts\n\nAzure Elastic SAN supports iSCSI but does not support CHAP authorization or initiator registration. Microsoft also lists iSCSI Error Recovery Levels 1 and 2 and more than one LUN per target as unsupported. Network access is configured at the volume-group level through private endpoints or service endpoints, and volumes inherit that configuration. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-planning).\n\n## Applicability\n\nUse this compatibility gate before moving an existing iSCSI workload to Elastic SAN. Identify the source target’s actual authentication, recovery and target-to-LUN assumptions; protocol naming alone does not establish equivalent features.\n\n## DSE recommendation\n\nMake unsupported initiator assumptions an explicit migration decision. Have the storage and security owners compare the existing design with Elastic SAN’s current support list. If CHAP or another excluded feature is required by the approved architecture, do not remove that requirement silently to make a connection succeed. Assess whether a separately approved network and access design can meet the workload’s needs, or whether another target service is required.\n\n## Verification\n\nIn a controlled pilot, inspect the intended volume-group network boundary and the initiator’s target configuration. Test the agreed permitted and denied client paths and the application’s recovery behavior using the supported feature set. Record every requirement that remains unmet. Do not accept a basic iSCSI login as evidence that CHAP, initiator registration or advanced recovery behavior was preserved from the source system.\n\n## Official references\n\n[Microsoft Learn: Plan for an Azure Elastic SAN deployment](https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-planning)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check Elastic SAN's iSCSI feature exclusions before copying a target design",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design/",
                "headline": "Check Elastic SAN's iSCSI feature exclusions before copying a target design",
                "description": "Can an existing CHAP-dependent iSCSI design be moved unchanged to Azure Elastic SAN?",
                "abstract": "Can an existing CHAP-dependent iSCSI design be moved unchanged to Azure Elastic SAN?",
                "articleBody": "Source facts\nAzure Elastic SAN supports iSCSI but does not support CHAP authorization or initiator registration. Microsoft also lists iSCSI Error Recovery Levels 1 and 2 and more than one LUN per target as unsupported. Network access is configured at the volume-group level through private endpoints or service endpoints, and volumes inherit that configuration. Microsoft Learn.\nApplicability\nUse this compatibility gate before moving an existing iSCSI workload to Elastic SAN. Identify the source target’s actual authentication, recovery and target-to-LUN assumptions; protocol naming alone does not establish equivalent features.\nDSE recommendation\nMake unsupported initiator assumptions an explicit migration decision. Have the storage and security owners compare the existing design with Elastic SAN’s current support list. If CHAP or another excluded feature is required by the approved architecture, do not remove that requirement silently to make a connection succeed. Assess whether a separately approved network and access design can meet the workload’s needs, or whether another target service is required.\nVerification\nIn a controlled pilot, inspect the intended volume-group network boundary and the initiator’s target configuration. Test the agreed permitted and denied client paths and the application’s recovery behavior using the supported feature set. Record every requirement that remains unmet. Do not accept a basic iSCSI login as evidence that CHAP, initiator registration or advanced recovery behavior was preserved from the source system.\nOfficial references\nMicrosoft Learn: Plan for an Azure Elastic SAN deployment.",
                "datePublished": "2026-09-10T00:29:39+00:00",
                "dateModified": "2026-09-10T00:52:39+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-137-check-elastic-san-s-iscsi-feature-exclusions-before-copying-a-target-design/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check Elastic SAN's iSCSI feature exclusions before copying a target design"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 230,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Plan for an Azure Elastic SAN deployment | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-planning"
                }
            }
        ]
    }
}