# Check Azure Files per-protocol encryption settings instead of assuming creation defaults match

> Portal-created accounts and scripted accounts do not start with the same explicit SMB and NFS encryption selections.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-506-check-azure-files-per-protocol-encryption-settings-instead-of-assuming-creation/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:30+00:00
- Modified: 2026-09-10T02:11:17+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Portal-created accounts and scripted accounts do not start with the same explicit SMB and NFS encryption selections.

## Potentially affected

Azure Files storage accounts reviewed for SMB, NFS and FileREST encryption in transit.

## DSE recommendation

Record each protocol's effective encryption requirement and the legacy setting before approving a deployment template.

## Article

## Source facts

For new storage accounts created in the Azure portal, the SMB and NFS encryption-in-transit requirements default to enabled. PowerShell, CLI and FileREST API creation leave these per-protocol choices Not selected for compatibility. On existing accounts, Secure transfer required continues governing SMB or NFS until its corresponding per-protocol setting is explicitly configured.

FileREST uses Secure transfer required: when enabled, FileREST access must use HTTPS. A Not selected protocol choice should therefore be investigated with the existing account setting, not simply reported as encryption disabled. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/files/storage-files-networking-overview).

## Applicability

Identify the account’s creation path, actual settings and protocols used by its clients. Keep the review focused on effective requirements rather than a screenshot from a differently created account.

## DSE recommendation

DSE recommends making intended encryption requirements explicit in the approved deployment design. Compare portal and automated provisioning results before standardizing a template. Investigate client compatibility through an approved test rather than disabling a requirement to reproduce an older default. Preserve the legacy setting when documenting why an unset protocol choice behaves as observed.

## Verification

Inspect a representative deployment’s SMB, NFS and FileREST settings as applicable, then test the permitted encrypted path and an appropriate noncompliant test case. Record configuration and negotiated behavior separately. Confirm that a change to one protocol has the intended scope and does not leave another protocol’s requirement undocumented.

## Official references

[Microsoft Learn: Networking Considerations for Azure Files](https://learn.microsoft.com/en-us/azure/storage/files/storage-files-networking-overview). Source retrieved September 9, 2026.

## Primary reference

- Name: Networking Considerations for Azure Files | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/storage/files/storage-files-networking-overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check Azure Files per-protocol encryption settings instead of assuming creation defaults match,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-506-check-azure-files-per-protocol-encryption-settings-instead-of-assuming-creation/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
