# Select NFS authentication before creating a Windows file share

> Which authentication decision should precede the first NFS share?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-024-select-nfs-authentication-before-creating-a-windows-file-share/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:16:47+00:00
- Modified: 2026-09-08T18:17:14+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Which authentication decision should precede the first NFS share?

## Potentially affected

Use this review when planning a Windows-hosted NFS share for a defined client population.

## DSE recommendation

Document the authentication choice as part of the share design and have both Windows and UNIX administrators review it.

## Article

## Source facts

Microsoft describes NFS as a way to share files between Windows Server and UNIX systems using the NFS protocol. Windows Server NFS supports authentication choices including Kerberos and AUTH_SYS. Microsoft advises choosing the method according to security requirements and the NFS version before creating a share. For NFS 4.1 and 3.0, Microsoft recommends Kerberos through RPCSEC_GSS. Server for NFS and Client for NFS can be installed together or on different computers. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/nfs/deploy-nfs).

## Applicability

Use this review when planning a Windows-hosted NFS share for a defined client population. Inventory the client operating systems, protocol versions, intended identities, and access requirements before selecting the server components.

## DSE recommendation

Document the authentication choice as part of the share design and have both Windows and UNIX administrators review it. Identify representative users and the files they should and should not access. Keep the initial share scope small enough to inspect. Arrange a change window and an approved way to remove the test access if the agreed identity behavior is not achieved.

## Verification

Test the intended client types against the approved authentication design. Record the identity presented and the resulting permissions for allowed and disallowed operations. Include a client that should be refused access. Preserve the share configuration and test evidence together, and resolve unexpected identity mappings before adding more data or clients.

## Official references

[Microsoft Learn: Deploy Network File System](https://learn.microsoft.com/en-us/windows-server/storage/nfs/deploy-nfs). Source reviewed September 8, 2026.

## Primary reference

- Name: Deploy Network File System
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/storage/nfs/deploy-nfs
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Select NFS authentication before creating a Windows file share,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-024-select-nfs-authentication-before-creating-a-windows-file-share/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
