# Reconfigure File Sync managed identity when registering an entirely new server

> New endpoints on configured servers and newly registered Windows servers do not inherit identity settings in the same way.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-486-reconfigure-file-sync-managed-identity-when-registering-an-entirely-new-server/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:50+00:00
- Modified: 2026-09-10T02:08:05+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

New endpoints on configured servers and newly registered Windows servers do not inherit identity settings in the same way.

## Potentially affected

Azure File Sync deployments using system-assigned managed identities.

## DSE recommendation

Include explicit managed-identity enablement and authentication verification in new-server registration.

## Article

## Source facts

After File Sync managed identity is configured, new endpoints on already configured servers use it. An entirely new registered Windows Server does not automatically inherit that configuration; managed identity must be explicitly enabled for the new server.

Servers without a system-assigned managed identity continue using Shared Key after the service is configured. The Storage Sync Service, server resource, identity and storage-account role assignments must belong to the same Microsoft Entra tenant; cross-tenant topologies are unsupported. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/file-sync/file-sync-managed-identities).

## Applicability

Distinguish adding an endpoint to an existing configured server from registering a new machine. Confirm the new server has the supported Azure VM or Arc identity arrangement before enabling File Sync authentication.

## DSE recommendation

DSE recommends making authentication a new-server acceptance item, not assuming the service-wide setting covers it. Review the identity and approved grants with the storage owner. Keep any decision about disabling Shared Key separate until all dependent callers have been assessed.

## Verification

After configuration, inspect the registered server’s reported authentication type and test the intended sync path. Allow for Microsoft’s documented transition period of up to 15 minutes before judging the result. Retain the new server identity and observed authentication state, without collecting tokens or account keys. Check a new endpoint on an existing server separately if that lifecycle is also in scope.

## Official references

[Microsoft Learn: How to Use Managed Identities with Azure File Sync](https://learn.microsoft.com/en-us/azure/storage/file-sync/file-sync-managed-identities). Source retrieved September 9, 2026.

## Primary reference

- Name: How to Use Managed Identities with Azure File Sync | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/storage/file-sync/file-sync-managed-identities
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Reconfigure File Sync managed identity when registering an entirely new server,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-486-reconfigure-file-sync-managed-identity-when-registering-an-entirely-new-server/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
