# Check Azure Files failover history before proposing zone redundancy

> Can an Azure Files account made locally redundant by customer-managed failover later convert to ZRS or GZRS?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:38+00:00
- Modified: 2026-09-10T00:52:39+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Can an Azure Files account made locally redundant by customer-managed failover later convert to ZRS or GZRS?

## Potentially affected

Azure classic file shares created through Microsoft.Storage, excluding shares created through Microsoft.FileShares.

## DSE recommendation

Reconstruct the account's failover history before choosing conversion or a separately approved migration.

## Article

## Source facts

After customer-managed failover of a GRS account during an outage, Microsoft says the account uses LRS in its new primary region. An LRS account produced by that failover cannot convert to ZRS or GZRS. Returning to the original primary through failback does not remove this restriction; Microsoft directs administrators to manual migration to add zone redundancy. That migration copies data into a new account and requires downtime. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/files/files-change-redundancy-configuration).

## Applicability

Azure classic file shares created through Microsoft.Storage, excluding shares created through Microsoft.FileShares. Review this question when recovery history may affect a proposed redundancy change. Check the remaining account, region and protocol requirements separately before approving a destination.

## DSE recommendation

Reconstruct the account’s failover history before choosing conversion or a separately approved migration. Ask the recovery owner for the original primary, each subsequent primary and the operations performed between them. Do not use a current LRS setting alone as the eligibility record. If the documented restriction applies, have the storage and application owners plan the new account, data-copy method, downtime and client transition together.

## Verification

Compare the proposed route with the retained failover evidence and record why in-place conversion is or is not eligible. For an approved manual migration, define data and application-access checks before the copy begins. Verify the destination’s intended redundancy and the agreed cutover results before considering source-account retirement. Keep retirement outside this eligibility decision; this review does not authorize deleting the original data.

## Official references

[Microsoft Learn: Change Redundancy Configuration for Azure Files](https://learn.microsoft.com/en-us/azure/storage/files/files-change-redundancy-configuration).

## Primary reference

- Name: Change Redundancy Configuration for Azure Files | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/storage/files/files-change-redundancy-configuration
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check Azure Files failover history before proposing zone redundancy,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-138-check-azure-files-failover-history-before-proposing-zone-redundancy/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
