What you need to know
An ownership permission in an NFSv4.x ACL does not override the default export-policy restriction.
Potentially affected
Azure NetApp Files volumes using NFSv4.x ACLs.
DSE recommendation
Review the export-policy Chown mode and specific ownership rights before changing either control.
Source facts
Azure NetApp Files defaults to permitting ownership changes only by root through its export policy. Under that restriction, an NFSv4.x ACL entry allowing ownership modification does not make a non-root ownership change succeed.
Microsoft documents an unrestricted Chown mode that permits non-root changes when the user has suitable rights. The source identifies the ownership permission, represented by o, or existing ownership as qualifying paths after that mode change. Microsoft Learn.
Applicability
Identify the volume, protocol, export rule, current owner, and identity making the request. Read the current rule and ACL before concluding that the failure is an absent file permission. Treat this as an authorization diagnosis, not a recommendation to relax every export.
DSE recommendation
DSE recommends recording the intended ownership workflow and asking the storage and data owners whether non-root ownership changes are necessary. If an exception is justified, review the scope of the export-policy change separately from the ACL. Preserve both settings and choose test files with no production dependency.
Verification
In an authorized pilot, compare the requester’s effective identity, current ownership, export mode, and requested operation. Include a user who should not be able to take ownership. Record the observed owner after each permitted test and restore the approved configuration; a successful read or write is not the ownership-change acceptance test.
Official references
Microsoft Learn: Understand NFSv4.x access control lists in Azure NetApp Files. Source retrieved September 9, 2026.
Review the official source
Understand NFSv4.x access control lists in Azure NetApp Files | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE