# Decide NetApp LDAP volume behavior before creating or cloning the volume

> Can an Azure NetApp Files volume's LDAP option be changed after creation or added through a snapshot clone?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-523-decide-netapp-ldap-volume-behavior-before-creating-or-cloning-the-volume/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:13+00:00
- Modified: 2026-09-10T02:11:18+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Can an Azure NetApp Files volume's LDAP option be changed after creation or added through a snapshot clone?

## Potentially affected

Use this check for the volume-level LDAP setting and a proposed snapshot-based volume creation. Do not confuse that flag with the wider Active Directory connection or ordinary SMB authentication requirements.

## DSE recommendation

Record the intended LDAP behavior in the volume design before provisioning.

## Article

## Source facts

Azure NetApp Files does not allow changing a volume’s LDAP option after creation. Microsoft also excludes creating an LDAP-enabled volume from a snapshot of an LDAP-disabled volume. Its documented alternative for that snapshot is another LDAP-disabled volume. An SMB volume cannot be created with the LDAP flag enabled; that option applies to NFS volumes. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-netapp-files/troubleshoot-volumes).

## Applicability

Use this check for the volume-level LDAP setting and a proposed snapshot-based volume creation. Do not confuse that flag with the wider Active Directory connection or ordinary SMB authentication requirements.

## DSE recommendation

Record the intended LDAP behavior in the volume design before provisioning. Have the storage and identity owners compare the source volume’s actual setting with the intended destination. Treat a mismatch as a design question, not a transient deployment error to retry indefinitely. If the required configuration differs, stop the clone plan and obtain a supported migration approach before changing data placement. Preserve the original volume and its recovery information while evaluating alternatives.

## Verification

In an approved test, inspect the source volume’s LDAP setting and identify the exact snapshot selected. Compare the proposed destination parameters with those constraints before submitting creation. After an accepted creation, check the resulting volume and authorized NFS access against the approved design. Keep any failed request and its parameter set so later reviewers can distinguish an incompatible configuration from a connectivity fault.

## Official references

[Microsoft Learn: Troubleshoot volume errors for Azure NetApp Files](https://learn.microsoft.com/en-us/azure/azure-netapp-files/troubleshoot-volumes).

## Primary reference

- Name: Troubleshoot volume errors for Azure NetApp Files | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-netapp-files/troubleshoot-volumes
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Decide NetApp LDAP volume behavior before creating or cloning the volume,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-523-decide-netapp-ldap-volume-behavior-before-creating-or-cloning-the-volume/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
