{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/",
        "slug": "dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/"
        },
        "title": "Check Azure Files failover history before proposing zone redundancy",
        "summary": "Can an Azure Files account made locally redundant by customer-managed failover later convert to ZRS or GZRS?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:38+00:00",
        "modified_at": "2026-09-10T00:52:39+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 250,
        "potentially_affected": "Azure classic file shares created through Microsoft.Storage, excluding shares created through Microsoft.FileShares.",
        "dse_recommendation": "Reconstruct the account's failover history before choosing conversion or a separately approved migration.",
        "primary_source": {
            "name": "Change Redundancy Configuration for Azure Files | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/storage/files/files-change-redundancy-configuration",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>After customer-managed failover of a GRS account during an outage, Microsoft says the account uses LRS in its new primary region. An LRS account produced by that failover cannot convert to ZRS or GZRS. Returning to the original primary through failback does not remove this restriction; Microsoft directs administrators to manual migration to add zone redundancy. That migration copies data into a new account and requires downtime. <a href=\"https://learn.microsoft.com/en-us/azure/storage/files/files-change-redundancy-configuration\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Azure classic file shares created through Microsoft.Storage, excluding shares created through Microsoft.FileShares. Review this question when recovery history may affect a proposed redundancy change. Check the remaining account, region and protocol requirements separately before approving a destination.</p>\n<h2>DSE recommendation</h2>\n<p>Reconstruct the account&#8217;s failover history before choosing conversion or a separately approved migration. Ask the recovery owner for the original primary, each subsequent primary and the operations performed between them. Do not use a current LRS setting alone as the eligibility record. If the documented restriction applies, have the storage and application owners plan the new account, data-copy method, downtime and client transition together.</p>\n<h2>Verification</h2>\n<p>Compare the proposed route with the retained failover evidence and record why in-place conversion is or is not eligible. For an approved manual migration, define data and application-access checks before the copy begins. Verify the destination&#8217;s intended redundancy and the agreed cutover results before considering source-account retirement. Keep retirement outside this eligibility decision; this review does not authorize deleting the original data.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/storage/files/files-change-redundancy-configuration\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Change Redundancy Configuration for Azure Files</a>.</p>",
        "content_text": "Source facts\nAfter customer-managed failover of a GRS account during an outage, Microsoft says the account uses LRS in its new primary region. An LRS account produced by that failover cannot convert to ZRS or GZRS. Returning to the original primary through failback does not remove this restriction; Microsoft directs administrators to manual migration to add zone redundancy. That migration copies data into a new account and requires downtime. Microsoft Learn.\nApplicability\nAzure classic file shares created through Microsoft.Storage, excluding shares created through Microsoft.FileShares. Review this question when recovery history may affect a proposed redundancy change. Check the remaining account, region and protocol requirements separately before approving a destination.\nDSE recommendation\nReconstruct the account’s failover history before choosing conversion or a separately approved migration. Ask the recovery owner for the original primary, each subsequent primary and the operations performed between them. Do not use a current LRS setting alone as the eligibility record. If the documented restriction applies, have the storage and application owners plan the new account, data-copy method, downtime and client transition together.\nVerification\nCompare the proposed route with the retained failover evidence and record why in-place conversion is or is not eligible. For an approved manual migration, define data and application-access checks before the copy begins. Verify the destination’s intended redundancy and the agreed cutover results before considering source-account retirement. Keep retirement outside this eligibility decision; this review does not authorize deleting the original data.\nOfficial references\nMicrosoft Learn: Change Redundancy Configuration for Azure Files.",
        "content_markdown": "## Source facts\n\nAfter customer-managed failover of a GRS account during an outage, Microsoft says the account uses LRS in its new primary region. An LRS account produced by that failover cannot convert to ZRS or GZRS. Returning to the original primary through failback does not remove this restriction; Microsoft directs administrators to manual migration to add zone redundancy. That migration copies data into a new account and requires downtime. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/files/files-change-redundancy-configuration).\n\n## Applicability\n\nAzure classic file shares created through Microsoft.Storage, excluding shares created through Microsoft.FileShares. Review this question when recovery history may affect a proposed redundancy change. Check the remaining account, region and protocol requirements separately before approving a destination.\n\n## DSE recommendation\n\nReconstruct the account’s failover history before choosing conversion or a separately approved migration. Ask the recovery owner for the original primary, each subsequent primary and the operations performed between them. Do not use a current LRS setting alone as the eligibility record. If the documented restriction applies, have the storage and application owners plan the new account, data-copy method, downtime and client transition together.\n\n## Verification\n\nCompare the proposed route with the retained failover evidence and record why in-place conversion is or is not eligible. For an approved manual migration, define data and application-access checks before the copy begins. Verify the destination’s intended redundancy and the agreed cutover results before considering source-account retirement. Keep retirement outside this eligibility decision; this review does not authorize deleting the original data.\n\n## Official references\n\n[Microsoft Learn: Change Redundancy Configuration for Azure Files](https://learn.microsoft.com/en-us/azure/storage/files/files-change-redundancy-configuration)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check Azure Files failover history before proposing zone redundancy",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/",
                "headline": "Check Azure Files failover history before proposing zone redundancy",
                "description": "Can an Azure Files account made locally redundant by customer-managed failover later convert to ZRS or GZRS?",
                "abstract": "Can an Azure Files account made locally redundant by customer-managed failover later convert to ZRS or GZRS?",
                "articleBody": "Source facts\nAfter customer-managed failover of a GRS account during an outage, Microsoft says the account uses LRS in its new primary region. An LRS account produced by that failover cannot convert to ZRS or GZRS. Returning to the original primary through failback does not remove this restriction; Microsoft directs administrators to manual migration to add zone redundancy. That migration copies data into a new account and requires downtime. Microsoft Learn.\nApplicability\nAzure classic file shares created through Microsoft.Storage, excluding shares created through Microsoft.FileShares. Review this question when recovery history may affect a proposed redundancy change. Check the remaining account, region and protocol requirements separately before approving a destination.\nDSE recommendation\nReconstruct the account’s failover history before choosing conversion or a separately approved migration. Ask the recovery owner for the original primary, each subsequent primary and the operations performed between them. Do not use a current LRS setting alone as the eligibility record. If the documented restriction applies, have the storage and application owners plan the new account, data-copy method, downtime and client transition together.\nVerification\nCompare the proposed route with the retained failover evidence and record why in-place conversion is or is not eligible. For an approved manual migration, define data and application-access checks before the copy begins. Verify the destination’s intended redundancy and the agreed cutover results before considering source-account retirement. Keep retirement outside this eligibility decision; this review does not authorize deleting the original data.\nOfficial references\nMicrosoft Learn: Change Redundancy Configuration for Azure Files.",
                "datePublished": "2026-09-10T00:29:38+00:00",
                "dateModified": "2026-09-10T00:52:39+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check Azure Files failover history before proposing zone redundancy"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 250,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Change Redundancy Configuration for Azure Files | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/storage/files/files-change-redundancy-configuration"
                }
            }
        ]
    }
}