# Check NetApp export policy before granting ownership changes in an NFS ACL

> An ownership permission in an NFSv4.x ACL does not override the default export-policy restriction.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-278-check-netapp-export-policy-before-granting-ownership-changes-in-an-nfs-acl/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:18+00:00
- Modified: 2026-09-10T01:23:49+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

An ownership permission in an NFSv4.x ACL does not override the default export-policy restriction.

## Potentially affected

Azure NetApp Files volumes using NFSv4.x ACLs.

## DSE recommendation

Review the export-policy Chown mode and specific ownership rights before changing either control.

## Article

## Source facts

Azure NetApp Files defaults to permitting ownership changes only by root through its export policy. Under that restriction, an NFSv4.x ACL entry allowing ownership modification does not make a non-root ownership change succeed.

Microsoft documents an unrestricted Chown mode that permits non-root changes when the user has suitable rights. The source identifies the ownership permission, represented by o, or existing ownership as qualifying paths after that mode change. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-netapp-files/nfs-access-control-lists).

## Applicability

Identify the volume, protocol, export rule, current owner, and identity making the request. Read the current rule and ACL before concluding that the failure is an absent file permission. Treat this as an authorization diagnosis, not a recommendation to relax every export.

## DSE recommendation

DSE recommends recording the intended ownership workflow and asking the storage and data owners whether non-root ownership changes are necessary. If an exception is justified, review the scope of the export-policy change separately from the ACL. Preserve both settings and choose test files with no production dependency.

## Verification

In an authorized pilot, compare the requester’s effective identity, current ownership, export mode, and requested operation. Include a user who should not be able to take ownership. Record the observed owner after each permitted test and restore the approved configuration; a successful read or write is not the ownership-change acceptance test.

## Official references

[Microsoft Learn: Understand NFSv4.x access control lists in Azure NetApp Files](https://learn.microsoft.com/en-us/azure/azure-netapp-files/nfs-access-control-lists). Source retrieved September 9, 2026.

## Primary reference

- Name: Understand NFSv4.x access control lists in Azure NetApp Files | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-netapp-files/nfs-access-control-lists
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check NetApp export policy before granting ownership changes in an NFS ACL,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-278-check-netapp-export-policy-before-granting-ownership-changes-in-an-nfs-acl/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
