# Include File Sync's paired-region destinations in a GRS firewall review

> Review File Sync regional and discovery destinations against the storage redundancy choice.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-019-include-file-sync-s-paired-region-destinations-in-a-grs-firewall-review/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:37+00:00
- Modified: 2026-09-10T00:32:00+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Review File Sync regional and discovery destinations against the storage redundancy choice.

## Potentially affected

Azure File Sync servers connected to geo-redundant Azure storage accounts.

## DSE recommendation

Check primary-region, paired-region, and discovery destinations together before accepting the File Sync allowlist.

## Article

## Source facts

For public-cloud File Sync service endpoints, Microsoft distinguishes storage redundancy choices. LRS and ZRS use the listed primary endpoint; GRS requires the primary region’s endpoint, its paired region’s endpoint, and the region’s discovery URL.

After server registration, Test-StorageSyncNetworkConnectivity and ServerRegistration.exe can test communications with that server’s service endpoints. These checks help identify incomplete proxy or firewall access. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/file-sync/file-sync-firewall-and-proxy).

## Applicability

Identify the storage account’s actual redundancy configuration and the Storage Sync Service region. Use the current table for the correct Azure cloud. Treat the regional service list as one part of the complete File Sync network requirements, not the entire dependency inventory.

## DSE recommendation

DSE recommends recording each required destination alongside its role: primary service, paired-region service, or discovery. Ask the firewall owner to reconcile explicit entries with the deployed region rather than copying another server’s allowlist. Include a review trigger for region, redundancy, proxy, or endpoint-policy changes, and retain the previous rules.

## Verification

Run the documented endpoint test from the registered server and preserve the per-destination results. Investigate any blocked paired-region or discovery destination even when routine synchronization appears healthy. Recheck after approved firewall changes. Record this as connectivity evidence only; schedule a separate recovery exercise if recovery behavior must be proven.

## Official references

[Microsoft Learn: Azure File Sync on-premises firewall and proxy settings](https://learn.microsoft.com/en-us/azure/storage/file-sync/file-sync-firewall-and-proxy). Source retrieved September 9, 2026.

## Primary reference

- Name: Azure File Sync on-premises firewall and proxy settings | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/storage/file-sync/file-sync-firewall-and-proxy
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Include File Sync's paired-region destinations in a GRS firewall review,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-019-include-file-sync-s-paired-region-destinations-in-a-grs-firewall-review/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
