Azure AD-Secured File Share

Job ID: 40303901

Budget: $250 – $750 AUD

I would like to implement shared folders to Azure Files and secure everything with native Azure AD authentication, not the classic storage-account keys. The share will serve mainly collaborative work but will also copy data models for Roughly 150 and growing cloud-only users need access, and I intend to grant that access through existing Azure AD groups and roles—no individual‐by‐individual assignments.

Here is the environment you will walk into:
• All services live in Microsoft 365; there is no on-prem AD, no servers, and no plans for VPN, ExpressRoute, or any VM-based work-arounds.
• Devices are Azure AD-joined and managed through Intune; I expect the drive to be mapped automatically via Intune configuration profiles.
• Several sub-folders (think “Finance,” “Projects and many more.) must each inherit the right group-based permissions.

What I need from you
1. A clear, step-by-step implementation plan that covers:
• Enabling Azure AD Kerberos for Azure Files in a pure cloud tenant
• Creating the share and sub-folders with the proper NTFS-style ACLs
• Automating drive mapping through Intune (PowerShell or Administrative Templates)
• Hardening recommendations—firewall rules, private endpoints, conditional access, and share snapshots for backup
2. Hands-on configuration inside my tenant (screen-shared session is fine).
3. A concise cost model that breaks down: capacity tier choices, snapshots/backup, outbound egress, and any Intune or licensing considerations, so I know what my monthly run rate will look like.
4. Post-implementation checklist and rollback notes so the setup can be audited or cloned later.

Acceptance criteria
• Users authenticate with their Azure AD credentials only; key-based access must be disabled.
• Group membership controls folder visibility and modify rights as agreed.
• Intune delivers the mapped drive seamlessly; no manual scripts needed on endpoints.
• A cost worksheet (Excel or similar) shows estimated spend for three storage scenarios (hot, cool, archive).

If you have recent experience deploying Azure Files with Azure AD only, plus Intune automation, I’d like to hear how quickly you can deliver and any potential blockers you foresee.