# Secure both File Sync resources before closing their public paths

> A storage account service endpoint does not provide an equivalent restriction for the separate Storage Sync Service.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-258-secure-both-file-sync-resources-before-closing-their-public-paths/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:38+00:00
- Modified: 2026-09-10T01:23:48+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

A storage account service endpoint does not provide an equivalent restriction for the separate Storage Sync Service.

## Potentially affected

Azure File Sync deployments changing storage-account and Storage Sync Service network access.

## DSE recommendation

Review the two resource endpoints separately and establish the Storage Sync Service private path before disabling its public endpoint.

## Article

## Source facts

Azure File Sync communicates with two separate resources: the storage account holding the share and the Storage Sync Service coordinating synchronization. Each has its own network endpoints.

Storage accounts can restrict a public endpoint with service endpoints, but Storage Sync Service does not support that model. Its VNet restriction uses private endpoints. Microsoft requires creating a private endpoint before disabling its public endpoint, otherwise sync cannot work. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/file-sync/file-sync-networking-endpoints).

## Applicability

Inventory both resources, their endpoint configuration and the agent’s route and name-resolution path. Do not use a successful share connection as the only evidence that the coordination service remains reachable.

## DSE recommendation

DSE recommends a two-resource network change record with separate readiness checks and rollback decisions. Establish and test the intended private path before removing public access. Coordinate storage, network and file-service owners, and preserve the prior endpoint settings for comparison. Keep the resource names explicit so an operator cannot mistakenly apply a storage-account procedure to Storage Sync Service.

## Verification

From the approved agent location, check resolution and connectivity for each resource and perform a harmless end-to-end synchronization test. Compare behavior before and after the authorized public-access change. Verify the intended restricted path and investigate any fallback or coordination failure. Retain both endpoint configurations and the observed synchronization result before extending the change to additional deployments.

## Official references

[Microsoft Learn: Configure Azure File Sync network endpoints](https://learn.microsoft.com/en-us/azure/storage/file-sync/file-sync-networking-endpoints). Source retrieved September 9, 2026.

## Primary reference

- Name: Configure Azure File Sync network endpoints | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/storage/file-sync/file-sync-networking-endpoints
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Secure both File Sync resources before closing their public paths,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-258-secure-both-file-sync-resources-before-closing-their-public-paths/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
