Reconfigure File Sync managed identity when registering an entirely new server

New endpoints on configured servers and newly registered Windows servers do not inherit identity settings in the same way.

Governed cloud identity system with connected service and lifecycle nodes.
DSE visual intelligenceIdentity & cloudGuide · 2 min read
Executive summary

What you need to know

New endpoints on configured servers and newly registered Windows servers do not inherit identity settings in the same way.

Potentially affected

Azure File Sync deployments using system-assigned managed identities.

DSE recommendation

Include explicit managed-identity enablement and authentication verification in new-server registration.

Source facts

After File Sync managed identity is configured, new endpoints on already configured servers use it. An entirely new registered Windows Server does not automatically inherit that configuration; managed identity must be explicitly enabled for the new server.

Servers without a system-assigned managed identity continue using Shared Key after the service is configured. The Storage Sync Service, server resource, identity and storage-account role assignments must belong to the same Microsoft Entra tenant; cross-tenant topologies are unsupported. Microsoft Learn.

Applicability

Distinguish adding an endpoint to an existing configured server from registering a new machine. Confirm the new server has the supported Azure VM or Arc identity arrangement before enabling File Sync authentication.

DSE recommendation

DSE recommends making authentication a new-server acceptance item, not assuming the service-wide setting covers it. Review the identity and approved grants with the storage owner. Keep any decision about disabling Shared Key separate until all dependent callers have been assessed.

Verification

After configuration, inspect the registered server’s reported authentication type and test the intended sync path. Allow for Microsoft’s documented transition period of up to 15 minutes before judging the result. Retain the new server identity and observed authentication state, without collecting tokens or account keys. Check a new endpoint on an existing server separately if that lifecycle is also in scope.

Official references

Microsoft Learn: How to Use Managed Identities with Azure File Sync. Source retrieved September 9, 2026.

Primary reference

Review the official source

How to Use Managed Identities with Azure File Sync | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE