What you need to know
Which authentication decision should precede the first NFS share?
Potentially affected
Use this review when planning a Windows-hosted NFS share for a defined client population.
DSE recommendation
Document the authentication choice as part of the share design and have both Windows and UNIX administrators review it.
Source facts
Microsoft describes NFS as a way to share files between Windows Server and UNIX systems using the NFS protocol. Windows Server NFS supports authentication choices including Kerberos and AUTH_SYS. Microsoft advises choosing the method according to security requirements and the NFS version before creating a share. For NFS 4.1 and 3.0, Microsoft recommends Kerberos through RPCSEC_GSS. Server for NFS and Client for NFS can be installed together or on different computers. Microsoft documentation.
Applicability
Use this review when planning a Windows-hosted NFS share for a defined client population. Inventory the client operating systems, protocol versions, intended identities, and access requirements before selecting the server components.
DSE recommendation
Document the authentication choice as part of the share design and have both Windows and UNIX administrators review it. Identify representative users and the files they should and should not access. Keep the initial share scope small enough to inspect. Arrange a change window and an approved way to remove the test access if the agreed identity behavior is not achieved.
Verification
Test the intended client types against the approved authentication design. Record the identity presented and the resulting permissions for allowed and disallowed operations. Include a client that should be refused access. Preserve the share configuration and test evidence together, and resolve unexpected identity mappings before adding more data or clients.
Official references
Microsoft Learn: Deploy Network File System. Source reviewed September 8, 2026.
Review the official source
Deploy Network File System · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE