Once your host pools are running, the next step is to configure storage for user data and profiles. Nerdio Manager works with both Azure Files and Azure NetApp Files: native Azure services commonly used in place of a dedicated file-server VM, and often paired with a profile management solution such as FSLogix.
You can link Nerdio Manager to an existing Azure Files or Azure NetApp Files share, or have Nerdio Manager create and configure a new one for you, including permissions and domain-joining. Nerdio Manager also adds auto-scaling for both storage types, so you only pay for the capacity you're actually using instead of over-provisioning up front.
This article explains the permissions required for a non-administrator, delegated domain user service account used to join an Azure Files share to an Active Directory domain. If these permissions are not correct, you receive an error during the domain join step. Errors may include, but not limited to, "Access is denied" or "A required privilege is not held by the client."
This does not apply to Entra Domain Services environments. Entra Domain Services environments only need the feature enabled and they do not need to join the domain as a specialty service account. In Nerdio Manager, be sure to select Entra Domain Services in the Join to AD drop-down list.
Note
For ease of deployment, you can use a domain administrator or temporarily elevate the delegated service account to domain administrator rights.
A domain administrator account is sufficient to join the Azure Files share to your domain. However if you are using a service account and delegating specific permissions to that account, the "Add/Remove computer accounts" delegated permissions used for AVD session hosts are not sufficient to add Azure Files shares.
Note
-
The domain join process for Azure Files must be executed in the context of a domain user. Nerdio Manager completes this process using the domain administrator credentials provided, or user credentials that have been delegated sufficient privileges following the steps detailed below. If you are not using domain administrator credentials, or if the domain administrator user does not receive local administrator privileges, Nerdio Manager's automation may not be able to complete the domain join.
-
In order for Nerdio Manager to execute these commands as the specified user, a command to change the user context is required. In order for this to be successful, the specified user credentials must also be granted local administrator privileges on the temporary VM provisioned by Nerdio Manager to complete this process. If the specified user does not have local administrative privileges, you may receive an error message indicating “Connecting to remote server azfilestmp-* failed with the following error message : Access is denied.” Please ensure the user account specified is granted local administrator permissions (for the azfilestmp-* VM only).
-
Domain administrative (or delegated) privileges are a requirement for the Azure Files domain join module, Local administrative permissions are only required in order for Nerdio Manager to execute the domain join process automatically.
Azure Files joins the domain as a delegated service principal user object. In order to join the Azure Files storage account to the domain, the provided service account requires permissions on the target Organizational Unit (OU) that allows creating and writing new user objects. In addition, the service account also requires permission to set the Azure Files sign in account as delegated service. By default, this privilege is only provided to AD domain administrator users.
The following procedure describes how to delegate permission to create and write user objects using Active Directory Users & Computers (ADUC, or dsa.msc).
To delegate permission to create user objects:
-
Locate the OU where Azure Files are to be joined.
-
Right-click the OU and select Delegate Control.
-
Add the Service User Account to be used for joining Azure Files to the domain.
-
Delegate permissions to Create, delete, and manage user accounts.
-
Select Finish to apply the changes.
The following procedure describes how to allow the service user account used for joining Azure Files to the domain to mark the new object for Azure Files as a delegated service. This requires modifying the Default Domain Controllers group policy object in Group Policy Management (gpmc.msc).
To delete permission to create delegated users:
-
Right-click the Default Domain Controller's Policy and select Edit.
-
Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment.
-
Locate the Enable computer and user accounts to be trusted for delegation policy.
-
Add to the policy the service user account name that is used to join Azure Files to the domain.
-
Close the editor.
-
Run gpupdate /force on all domain controllers.
Note
The policy change may take several minutes to apply after gpupdate completes.
You must provide the service account under AD Profiles in Nerdio Manager. See Entra ID Join Feature for details.
The Azure Files page contains a list of all the configured and linked Azure Files shares. You can perform various actions on the Azure Files shares such as creating, linking, or managing shares. This includes options such as auto-scale, unlink, setting/changing permissions, closing file handles, and copy the Azure Files UNC path.
Nerdio Manager allows you to link to an existing Azure Files share.
To link to an existing Azure Files file share:
-
Navigate to Cloud Desktops > Storage > Azure Files.
-
Select Link Azure Files.
-
Enter the following information:
-
Storage Account: From the drop-down list, select the storage account.
-
File Share: From the drop-down list, select the file share.
-
-
Once you have entered all the desired information, select OK.
After a few moments, the Azure Files file share is added to Nerdio Manager.
Nerdio Manager allows you to create a new Azure Files file share and/or storage account.
Networking requirements
To ensure proper connectivity to Azure Files shares, make sure the following ports are open.
The additional ports may apply for Azure Government environments.
|
Port |
Protocol |
Purpose |
|---|---|---|
|
53 |
TCP/UDP |
DNS name resolution for Active Directory |
|
88 |
TCP/UDP |
Kerberos authentication (for AD DS integration) |
|
135 |
TCP RPC |
Endpoint Mapper (for AD DS integration) |
|
389 |
TCP/UDP |
LDAP for domain controller communication (for AD DS integration) |
|
443 |
TCP HTTPS |
REST API access, Azure File sync, SMB over QUIC |
|
445 |
TCP |
SMB file access |
|
636 |
TCP |
Secure LDAP (LDAPS) |
|
2049 |
TCP |
NFS protocol access |
|
3268 |
TCP |
Global Catalog (LDAP) |
|
3269 |
TCP |
Secure Global Catalog (LDAPS) |
|
49152–65535 |
TCP |
RPC Dynamic Ports (for AD DS integration) |
To create a new Azure Files file share and/or storage account:
-
Navigate to Cloud Desktops > Storage > Azure Files.
-
Select Add Azure Files.
-
Enter the following information:
-
Storage Account: From the drop-down list, select the storage account.
-
Storage Account Description: Type the description of the storage account.
-
Performance: From the drop-down list, select the performance tier for the file share.
Note
Premium storage accounts are backed by solid state drives and offer consistent, low-latency performance. They can only be used with Azure virtual machine disks, and are best for I/O-intensive applications, such as databases. Additionally, virtual machines that use premium storage for all disks qualify for a 99.9% SLA, even when running outside of an availability set. This setting can't be changed after the storage account is created.
-
Tip
It is strongly recommended that you select Premium for the best user experience.
-
Replication: From the drop-down list, select the type of storage replication.
Note
See Azure Storage redundancy for more information.
-
File Share Name: Type the share's name.
-
File Share Description: Type the share's description.
-
Provisioned Capacity (GiB): Type the size of the provisioned capacity.
-
-
Enter the following information in the Storage account configuration section:
-
Share-level permissions: Select this option to set default share-level permissions on storage account.
Note
-
SMB Share Contributor permission can be used to allow all authenticated users read/write access to the share.
-
SMB Share Reader can be used to allow all authenticated users read-only access to the share (for example, MSIX app attach).
See Share-level permissions for all authenticated identities for additional information.
-
-
Join to AD or Entra ID: Select this option and then from the drop-down list, select an Entra ID or an AD profile to directly join the share.
-
Create a computer-joined file share: Select this option to join Azure Files storage accounts to AD by creating either a user object or a computer object in Active Directory.
Note
It is recommended that a user object is used for the domain join process. Please ensure that no policies are in effect that may disable or remove this account or reset its password. If a computer object is selected, ensure this account is excluded from any automated cleanup process. All file shares are created with AES256 encryption enabled.
-
Enable SMB Multichannel: Select to enable.
Note
Azure Files SMB Multichannel enables clients to use multiple network connections that provide increased performance. Increased performance is achieved through bandwidth aggregation over multiple NICs and utilizing Receive Side Scaling (RSS) support for NICs to distribute the IO load across multiple CPUs.
-
-
Enter the following information in the File share configuration section:
-
Permissions (SMB Share Contributors): Specify users/groups that have Storage File Data SMB Share Contributor role on the share.
-
Add users / groups from host pools: From the drop-down list, select users/groups currently assigned to these host pools to be given Storage File Data SMB Share Contributor role on the share.
-
Note
To use an Azure Files share as a storage location for FSLogix profiles and MSIX App Attach images, the storage account must be integrated with Active Directory, Entra Domain Services, or Entra ID. If you select not to join the storage account to AD or Entra ID, you can do so later. Joining the storage account to AD creates a temporary VM and uses the AD profile credentials to add the storage account as a Computer object in selected AD. Integrating storage account with Entra Domain Services sets the appropriate flag in Azure. Entra Domain Services admin profile credentials are necessary to create a temporary VM to be domain-joined and enable AES-256 encryption. Joining the storage account with Entra ID creates the necessary app registration and provides you with an option to grant needed consents.
-
Assign NTFS file-level permissions: Select this option to have Nerdio Manager assign NTFS file-level permissions to newly created file shares.
Note
-
This is in addition to assigning Azure RBAC roles selected above.
-
This process automatically creates a temporary VM to perform the permission assignment task.
-
See this Microsoft article for information about default file permissions used on new Azure Files shares.
-
App Attach: Select this option to grant Authenticated Users Read permission to sub-directories in the share. This is recommended for shares containing App Attach applications.
-
FSLogix: Select this option to grant Authenticated Users Modify permission to the root directory in the share, allowing for the creation of FSLogix profile folders.
Note
This is recommended for shares containing FSLogix profiles.
-
-
-
Show advanced settings: To join Azure Files to the Active Directory, Nerdio Manager creates a temporary VM to perform the operation. Select the settings to be used for this temporary VM.
Tip
It is strongly recommended that you allow Nerdio Manager to use the default settings when creating the temporary VM. That is, we recommend that you do not use the advanced settings.
-
Apply tags: Optionally, type the Name and Value of the Azure tag to apply to the Azure Files share.
-
Select OK to save the configuration.
Note
You may specify multiple tags. See this Microsoft article for details about using tags to organize your Azure resources.
Nerdio Manager allows you to manage existing Azure Files file shares.
To manage configured Azure Files file shares:
-
Navigate to Cloud Desktops > Storage > Azure Files.
-
Locate the Azure Files share you want to manage.
-
The action menu allows you to perform the following functions:
-
Manage storage account: Allows you to enable Entra ID host support. See Enable Entra ID Joined Host Support for details.
-
Auto-scale: See Auto-scale for Azure Files Storage Premium for more information.
-
File handles: Unlock files/Close open file handles.
-
Force collect FSLogix profiles: This will force a collection of FSLogix data on all the linked file shares
-
Copy UNC Path: Copy the UNC path to the clipboard.
-
Unlink: Remove the Azure Files file share from Nerdio Manager.
-
Delete FSLogix Profiles: Delete a selected FSLogix profile.
-
Restore FSLogix Profiles: Restore a selected FSLogix profile that was previously deleted.
-
-
From the action menu, select Manage to change the Azure Files share's parameters and permissions.
To bulk collect FSLogix data:
Nerdio Manager allows you to select multiple file shares that enables you to collect FSLogix data in bulk and on demand.
-
Navigate to Cloud Desktops > Storage > Azure Files.
-
Select the file shares that you want to collect FSLogix data for.
-
From the Bulk actions menu, select Force collect FSLogix profiles for selected File Shares (x).
Note
The (x) denotes the number of Azure Files shares the bulk action is applied to. In the example, 4 Azure Files shares have been selected.
Entra ID-joined hosts can now benefit from using App Attach applications, which expands the options for application delivery.
Prerequisites
-
You should be familiar with App Attach . See this Microsoft article App attach and MSIX app attach in Azure Virtual Desktop for details.
Useful information
App Attach supports the following identity providers:
-
Microsoft Entra ID
-
Active Directory Domain Services (AD DS)
Default file share NTFS permissions:
-
BUILTIN\Administrators:(OI)(CI)(F)
-
BUILTIN\Users:(RX)
-
BUILTIN\Users:(OI)(CI)(IO)(GR,GE)
-
NT AUTHORITY\Authenticated Users:(OI)(CI)(M)
-
NT AUTHORITY\SYSTEM:(OI)(CI)(F)
-
NT AUTHORITY\SYSTEM:(F)
-
CREATOR OWNER:(OI)(CI)(IO)(F)
File share NTFS permissions for App Attach:
-
BUILTIN\Users:(RX)
-
BUILTIN\Users:(OI)(CI)(IO)(GR,GE)
-
NT AUTHORITY\Authenticated Users:(OI)(CI)(M)
-
CREATOR OWNER:(OI)(CI)(IO)(F)
Area of Usage
Hosts that are going to use App Attach are joined to Microsoft Entra ID
The only mandatory condition for App Attach working on such hosts is that the storage account that stores the App Attach images must be in the same subscription and have Reader and Data Access role assignment with Azure Virtual Desktop and Windows Virtual Desktop ARM Provider members. Storage account can be integrated with any identity provider (Microsoft Entra ID, AD DS) or not integrated at all.
Hosts that are going to use App Attach are joined to AD DS
Mandatory conditions:
-
Storage account that stores App Attach images is joined to AD DS
-
App Attach NTFS permissions are configured on file share
-
Share-level permissions are configured
Variations of share-level permissions configuration:
-
Read-only access for all authenticated identities: Default share-level permission with at least Storage File Data SMB Share Reader role for all authenticated identities on the storage account.
-
Read-only access for domain computers:
-
In Active Directory, create a new Global Security group in an Organization Unit (OU) that is being synched to Entra ID with ADConnect.
-
Add the Domain Computers to the new group.
-
Add the newly created security group with at least Storage File Data SMB Share Reader role to file share through the Access Control in the Azure Portal.
-
-
Some custom configuration.
Related topics:
Azure Files premium storage supports two generations of file shares, each billed — and auto-scaled — differently:
-
Provisioned V1: billed by provisioned share size only, regardless of used capacity. Share sizes range from 100 GiB to 102,400 GiB. IO and network bandwidth limits scale automatically with the provisioned size, but are not separately configurable.
-
Provisioned V2: billed by three independently provisioned values — share size, IOPS, and throughput. Share sizes range from 32 GiB to 262,144 GiB, provisioned IOPS from 3,000 to 102,400, and provisioned throughput from 100 to 10,340 MiB/s. Billing rates for all three vary by region and other parameters — see Azure Files Pricing for details.
When enabled, storage auto-scale grows the provisioned values in response to anticipated usage demand or increased storage latency. It also decreases them to reduce costs when the extra performance is no longer needed (not more than once every 24 hours per value).
Storage auto-scaling with Azure Files can also be used to maintain a specified headroom to avoid running out of space on the volume or capacity pool.
Note
Auto-scale is not available for Azure Files standard storage, because both capacity cost and performance are not controlled by the size of the share.
Note
Auto-scale is disabled by default on a newly linked share. There is no conversion between Provisioned V1 and Provisioned V2 — the generation is fixed when the share is created, and a share is always one or the other.
You must configure these auto-scale parameters:
-
Provisioned Size (Quota), IOPS and Throughput (the values scaled depend on whether the share is Provisioned V1 or Provisioned V2 — see below)
-
Scheduled Data Increase (Optional)
-
Scaling Logic
To configure and manage auto-scale for Azure Files premium:
-
Navigate to Cloud Desktops > Storage > Azure Files.
-
Locate the files share you want to manage.
-
From the action menu, select Auto-scale > Configure.
-
Toggle the Auto-Scale option to On.
-
Refer to the table that matches your share's generation (Provisioned V1 or Provisioned V2), and enter the Provisioned Size (Quota), IOPS and Throughput settings listed.
UI Element
Type
Description
Quota unit
Drop-down list
Select the unit used for Minimum size and Maximum size: Relative (%), a percentage of currently used capacity, or Absolute (GiB), a fixed value in GiB.
Minimum size
Text field
The smallest size auto-scale will maintain, entered in GiB or % above used capacity. The minimum is 100 GiB, and cannot be set smaller than the share's current used capacity. This value defines the buffer of free space auto-scale always keeps available as used capacity grows.
Maximum size
Text field
The largest size auto-scale will grow the share to, entered in GiB or % above used capacity, up to a ceiling entered in the Less than field. Auto-scale increases the share only up to this maximum, to prevent uncontrolled growth.
Performance
Read-only display
Shows the minimum and maximum performance characteristics that result from the configured size range. These values are calculated by Azure from the provisioned size and cannot be configured directly:
-
IO/S: baseline IOPS, calculated as 3,000 + 1 per provisioned GiB, up to a maximum baseline rate of 100,000 IO/s.
-
Burst IO/S: the greater of 10,000 IO/s or 3× the baseline IO/s rate. Unused baseline IO accumulates as burst credits (up to a limit) that are drawn down when demand exceeds the baseline rate, up to a maximum burst rate of 100,000 IO/s.
-
Egress Rate: allowed network egress per second, calculated as 60 + (share quota × 0.06 MiByte/s).
-
Ingress Rate: allowed network ingress per second, calculated as 40 + (share quota × 0.04 MiByte/s).
Note
Billing rates for provisioned size, IOPS, and throughput vary by region and other parameters. See Azure Files Pricing for details.
UI Element
Type
Description
Quota unit
Drop-down list
Select the unit used for Minimum size and Maximum size: Relative (%), a percentage of currently used capacity, or Absolute (GiB), a fixed value in GiB.
Minimum size
Text field
The smallest size auto-scale will maintain, entered in GiB or % above used capacity. The minimum is 32 GiB, and cannot be set smaller than the share's current used capacity.
Maximum size
Text field
The largest size auto-scale will grow the share to, entered in GiB or % above used capacity, up to a ceiling entered in the Less than field (maximum 262,144 GiB). Auto-scale increases the share only up to this maximum, to prevent uncontrolled growth.
Provisioned IOPS
Text fields (from / to)
The range auto-scale keeps provisioned IOPS within. Provisioned V2 caps IOPS at 5× the value Microsoft recommends for the share's current size, and never above the tier's absolute maximum (102,400 IOPS on this tier).
The cap rises as the share grows — for example, at 32 GiB the ceiling is 15,160 IOPS, rising to 102,400 IOPS at the configured maximum of 262,144 GiB. Auto-scale does not grow the share purely to reach a higher IOPS cap; raising the Minimum size is what lifts the cap sooner.
Provisioned throughput (MiB/s)
Text fields (from / to)
The range auto-scale keeps provisioned throughput within. Provisioned V2 caps throughput at 5× the value Microsoft recommends for the share's current size, and never above the tier's absolute maximum (10,340 MiB/s on this tier).
The cap rises as the share grows — for example, at 32 GiB the ceiling is 520 MiB/s, rising to 10,340 MiB/s at the configured maximum of 262,144 GiB. Auto-scale does not grow the share purely to reach a higher throughput cap; raising the Minimum size is what lifts the cap sooner.
-
-
Optionally, toggle Scheduled Quota Increase (Provisioned V1) or Scheduled Performance Increase (Provisioned V2) to On. This commits to a temporary increase during a recurring window — for example, if you have days with predictable peak demand. While the schedule is active, the scheduled values are held and latency-based scaling rules do not apply to them. Refer to the table that matches your share's generation, and enter the settings listed.
Note
Provisioned size (quota) can be decreased only 24 hours after the last quota increase. The quota is increased at the beginning of the scheduled period and decreased to the minimum size only at the end of it.
UI Element
Type
Description
Days
Drop-down list
Select the range of days the schedule applies to.
Hours
Time range and drop-down list
Set the start and end time of the scheduled window, and select the time zone it applies in.
Set provisioned size (quota) to
Text field
The quota, above current used capacity, that the share is set to for the duration of the scheduled window.
Note
Provisioned IOPS and throughput can each be decreased only 24 hours after their own last increase. Both are increased at the beginning of the scheduled period and decreased to their minimum values only at the end of it.
UI Element
Type
Description
Days
Drop-down list
Select the range of days the schedule applies to.
Hours
Time range and drop-down list
Set the start and end time of the scheduled window, and select the time zone it applies in.
Set provisioned IOPS to
Text field
The provisioned IOPS value the share is held at for the duration of the scheduled window.
Set provisioned throughput (MiB/s) to
Text field
The provisioned throughput value the share is held at for the duration of the scheduled window.
-
These conditions determine when auto-scale increases or decreases the provisioned values: any rule proposing an increase causes an increase, and a decrease is applied when a rule proposes one. Refer to the table that matches your share's generation, and enter the Scaling Logic settings listed.
Note
Provisioned size (quota) can be decreased only 24 hours after the last quota increase.
Provisioned V1 supports up to two rules, both targeting size (quota): one for scale-out, one for scale-in.
UI Element
Type
Description
Select auto-scale trigger
Drop-down list
The latency metric that drives scaling: Success Server Latency (avg) (default) or Success Server Latency (max) — the average or maximum time Azure Storage takes to process a successful request.
Increase quota (scale out) by
Text field (%)
The step size to increase the quota by (in the unit set under Quota unit) each time the scale-out condition below is met. While the latency threshold is exceeded, the system keeps scaling out until it either reaches the configured maximum size or the latency drops back under the threshold.
if Success Server Latency exceeds
Text field (ms)
The latency threshold, in milliseconds, that triggers a scale-out.
for … Minutes (scale-out)
Drop-down list
The measurement window the scale-out latency threshold must be sustained for: 5, 15, 30, or 60 minutes.
Decrease quota (scale in) by
Text field (%)
The step size to decrease the quota by each time the scale-in condition below is met.
if Success Server Latency drops below
Text field (ms)
The latency threshold, in milliseconds, that triggers a scale-in.
for … Minutes (scale-in)
Drop-down list
The measurement window the scale-in latency threshold must be sustained for: 5, 15, 30, or 60 minutes.
Note
Provisioned IOPS and throughput can each be decreased only 24 hours after their own last increase.
Provisioned V2 supports up to four rules — a scale-out and a scale-in rule for each of Provisioned IOPS and Provisioned throughput. Select + to add a rule and choose which value it targets.
UI Element
Type
Description
Type
Drop-down list
-
Provisioned IOPS: this rule scales provisioned IOPS.
-
Provisioned throughput: this rule scales provisioned throughput (MiB/s).
Each rule targets one value in one direction. Up to four rules can exist at once: scale-out and scale-in, for each of IOPS and throughput.
Select auto-scale trigger
Drop-down list
The latency metric that drives scaling — the average or maximum time Azure Storage takes to process a successful request. The options available depend on the Type selected above:
-
Type: Provisioned IOPS — both Success Server Latency (avg) (default) and Success Server Latency (max) are available.
-
Type: Provisioned throughput — only Success Server Latency (max) is available.
Increase provisioned IOPS / throughput (scale out) by
Text field (IOPS or MiB/s)
The step size to increase the value selected under Type by, each time the scale-out condition below is met. The increase is bounded by the value's cap (see Provisioned IOPS / Provisioned throughput in the previous step).
if Success Server Latency exceeds
Text field (ms)
The latency threshold, in milliseconds, that triggers a scale-out.
for … Minutes (scale-out)
Drop-down list
The measurement window the scale-out latency threshold must be sustained for: 5, 15, 30, or 60 minutes.
Decrease provisioned IOPS / throughput (scale in) by
Text field (IOPS or MiB/s)
The step size to decrease the value selected under Type by, each time the scale-in condition below is met.
if Success Server Latency drops below
Text field (ms)
The latency threshold, in milliseconds, that triggers a scale-in.
for … Minutes (scale-in)
Drop-down list
The measurement window the scale-in latency threshold must be sustained for: 5, 15, 30, or 60 minutes.
-
-
Once you have entered all the desired information, select Save or Save & close.
The configured file share appears in the list of shares on the Azure Files list.
Related Topics
The auto-scale history visualization helps you understand auto-scale behavior and how it impacts your deployment.
The following are important auto-scale history features.
-
Time Range: At the top of the window, select the desired time range to display.
-
Show: At the top of the window, select the desired graph(s) to display.
-
Savings: At the top of the window, you can view auto-scale savings.
-
Zoom In: For the Quota (GiB) graph only, click and drag the mouse over the section of the graph you wish to zoom in on. When you are zoomed in, select Zoom-out to restore the full graph.
-
Hover: You can hover over any part of any graph to see its details. For example:
-
Action Points:
-
Scale Out: This action point indicates that a scale-out event took place. (Red indicates that the scale-out event is costing money.)
-
Scale In: This action point indicates that a scale-in event took place. (Green means that the scale-in event is saving money.)
-
Azure Issue: This indicates that there was a problem communicating with Azure. If this occurs frequently, please contact Nerdio Manager technical support.
-
-
At the bottom of any graph, select the data set name to toggle on/off the display line associated with that information. For example, select Peak Quota to suppress that line on the graph. Select it again to display it.
To view auto-scale history for an Azure Files share:
-
Navigate to Cloud Desktops > Storage > Azure Files.
-
Locate the file share you wish to work with.
-
From the action menu, select Auto-scale > History.
-
Select the desired time range and the specific graphs to display.
-
Quota (GiB): The Quota graph displays the following information about the file share quota:
-
Peak Quota: The maximum size of the quota.
-
Actual Quota: The actual quota size as it is currently configured.
-
Used Capacity: The actual storage used.
-
-
Latency (ms): The Latency graph displays the following information:
-
Server Latency (avg): The average time used to process a successful request by Azure Storage. This value does not include the network latency specified in the End-to-End Latency.
-
End-to-End Latency (avg): The average end-to-end latency of successful requests made to a storage service or the specified API operation. This value includes the required processing time within Azure Storage to read the request, send the response, and receive acknowledgment of the response.
-
-
Transactions: The Transactions graph displays the number of transactions.
-
Savings%: The Savings graph displays the savings percentage.
-
Related Topics
Note
This feature is only available in the Nerdio ManagerPremium edition.
The Azure NetApp Files page contains a list of all the configured and linked Azure NetApp files shares. You can perform various actions on the files shares such as creating or managing files shares.
You must link the Azure subscription and resource group where the Azure NetApp Files resides to Nerdio Manager before you can proceed to the next steps.
To link the Azure subscription to resource group to Nerdio Manager:
-
Navigate to System > Settings > Azure.
-
Expand Azure Subscriptions.
-
Select either Link using currently logged in user or Link using app credentials to link the Azure subscription.
-
Expand Linked Resource Groups.
-
Select Link to link the resource group.
You can link to an existing Azure NetApp Files share.
To link to an existing Azure NetApp Files share:
-
Navigate to Cloud Desktops > Storage > Azure NetApp Files.
-
Select Link ANF Volume.
-
From the drop-down list, select the NetApp Files Account.
-
Select OK.
After a few moments, the Azure NetApp Files file share is added to Nerdio Manager.
You can create and Azure files and/or storage account.
Create an Azure files and/or storage account.
Note
Before proceeding, verify that ANF is available in your Azure region and that your Azure subscription is whitelisted for this service.
-
Navigate to Cloud Desktops > Storage > Azure NetApp Files.
-
Select Add ANF Volume.
-
Enter the following information:
-
Active directory: From the drop-down list, select the active directory.
-
Resource group: From the drop-down list, select the resource group.
-
Network: From the drop-down list, select the network.
-
Subnet: From the drop-down list, select the subnet.
-
AD-aware DNS Server: Type the address of the AD-aware DNS server.
-
-
Once you have entered all the desired information, select Next.
-
Enter the following information:
-
Resource group for ANF account: From the drop-down list, select a resource group to contain the Azure NetApp Files account objects.
-
Account name: Type the ANF account name or leave it blank for it to be automatically generated.
-
SMB server prefix: Type the prefix of the computer objects that are to be joined to the AD domain and used for the UNC path. For example: \\SMB-PREFIX-random\volume\share\folder.
-
Volume name: Type the volume name to be created on the SMB server specified above.
Note
There can be multiple volumes in the same ANF account.
-
Capacity (TiB): Type the capacity in TiB.
Note
The minimum capacity of an ANF capacity pool is 4 TiB.
-
Performance Tier: From the drop-down list, select the performance tier of the new capacity pool and volume.
Note
Performance tiers vary in price and throughput (IOPS). See the following Microsoft document for details.
-
-
Once you have entered all the desired information, select Add.
Related Topics
Note
This feature is only available in the Nerdio ManagerPremium edition.
In Azure storage NetApp files, you have an ANF account that can have multiple capacity pools. Capacity pools are created with a service level (Standard, Premium, Ultra) that determines performance. Within each capacity pool you can have one or more volumes that, in aggregate, cannot exceed the size of this capacity pool. The cost of the ANF storage is determined by the size of the capacity pool, with the minimum size of 4 TiB. You can grow and shrink a capacity pool in increments of 1 TiB, but not smaller than the sum of the volumes that are contained within that capacity pool.
The throughput limit of the ANF storage system is determined by a combination of the quota assigned to the volume and the service level selected.
Storage auto-scaling with ANF is required when you need to dial-up the performance of a particular volume during times of high demand on the storage system, and then dial it back down, on a scheduled basis, when that performance is no longer needed. For example, during sign in/sign out storms from Azure VD machines. Or it could be needed when there is heavy activity on the storage system in the middle of the day and the latency of that volume is detected to be high.
Storage auto- scaling with ANF can also be used to maintain a specified headroom to avoid running out of space on the volume or capacity pool.
To configure and manage auto-scale for Azure NetApp files:
-
Navigate to Cloud Desktops > Storage > Azure NetApp Files.
-
Locate the ANF you want to manage.
-
From the action menu, select Auto-scale > Configure.
-
Toggle the Auto-Scale option to On.
-
Enter the Provisioned Size settings.
Note
If the volume free space drops below the Min, the system tries to grow the volume. If it cannot grow the volume within the current capacity pool, the capacity pool is always expanded by 1 TiB, and the volume grows at least for 1 TiB.
The volume won't grow beyond the configured maximum size.
-
Mode: From the drop-down list, select the mode:
-
Volume only: Auto-scales the volume without the capacity pool that contains it. The volume is limited to the available free space within the capacity pool, and the capacity pool does not increase automatically.
-
Volume and capacity pool: Auto-scales the volume and the capacity pool that contains it (default).
-
-
For Volume only:
-
Size unit: From the drop-down list, select the unit (Relative % or Absolute GiB). Relative is a percentage of currently used capacity.
-
Minimum size: When scaling down, type the minimum size to maintain on the volume. This is evaluated as the currently used capacity + headroom amount.
Note
If the available space drops below the configured minimum free space, the volume is increased to meet the minimum available space. If exceeding capacity pool size, and capacity pool scaling is enabled, then an additional 1 TiB is added to the capacity pool to increase the volume – up to the configured maximum total size.
-
Maximum size: When scaling out, type the maximum amount the volume should increase. This is evaluated as the currently used capacity + the scaling amount.
-
Less than: Define the Max size the volume may grow in order to prevent the uncontrolled system growth. This is limited by the available capacity pool size.
-
-
-
For Volume and capacity pool:
-
Minimum volume free space: Type the minimum free to maintain on the volume. If the current free space falls below this threshold, the volume automatically grows along with the capacity pool.
-
Maximum volume total size: Type the maximum volume size of the volume in TiBs. The volume and capacity pool combination cannot grow larger than this value.
-
-
Exceeding the limit should trigger an error: Select this option to have the auto-scale process trigger an error if the calculated size exceeds the maximum limit.
Note
This allows you to track these errors using notifications. See Configure Email Notifications for details.
The Size and Performance calculator displays the minimum and maximum configuration values and displays the performance characteristics.
-
-
Optionally, toggle Scheduled-Based ScalingOn and configure the settings.
Note
This is useful if you have peaks in demand on the storage system (for example, when multiple users sign in and sign out during the same time). You can specify more than one period of the peak auto-scaling, after which the system automatically scales down to the Min size. Be sure that the schedules do not overlap.
-
Time Zone: From the drop-down list, select the time zone.
-
Days: From the drop-down list, select the days.
-
Hours: From the drop-down list, select the range of hours.
-
Set provisioned size to: Type the amount of additional capacity to add to the volume, beyond the current capacity.
-
-
Optionally, toggle Latency-Based ScalingOn and configure the settings.
-
Select auto-scale trigger: From the drop-down list, select the trigger.
Note
This is the average or maximum time used to process a successful request by Azure Storage.
-
Increase volume size (scale out): The system increases the volume size by the value that you set if the server latency exceeds the specified threshold.
-
Decrease volume size (scale in): The system decreases the volume size by the value that you set if the server latency drops below the specified threshold.
-
-
Once you have entered all the desired information, select Save or Save & close.
The configured file appears in the list of files on the Azure NetApp Files list.
Related topics
Note
This feature is only available in the Nerdio ManagerPremium edition.
The auto-scale history visualization helps you understand auto-scale behavior and how it impacts your deployment.
The following are important auto-scale history features.
-
Time Range: At the top of the window, select the desired time range to display.
-
Show: At the top of the window, select the desired graph(s) to display.
-
Savings: At the top of the window, you can view auto-scale savings.
-
Zoom In: For the Size (GiB) graph only, click and drag the mouse over the section of the graph you wish to zoom in on. When you are zoomed in, select Zoom-out to restore the full graph.
-
Hover: You can hover over any part of any graph to see its details. For example:
-
Action Points:
-
Scale Out: This action point indicates that a scale-out event took place. (Red indicates that the scale-out event is costing money.)
-
Scale In: This action point indicates that a scale-in event took place. (Green means that the scale-in event is saving money.)
-
Azure Issue: This indicates that there was a problem communicating with Azure. If this occurs frequently, please contact Nerdio Manager technical support.
-
-
At the bottom of any graph, select the data set name to toggle on/off the display line associated with that information. For example, select Peak Size to suppress that line on the graph. Select it again to display it.
To view auto-scale history for an Azure NetApp share:
-
Navigate to Cloud Desktops > Storage > Azure NetApp Files.
-
Locate the file share you wish to work with.
-
From the action menu, select Auto-scale > History.
-
Select the desired time range and the specific graphs to display.
-
Size (GiB): The Size graph displays the following information about the file share size:
-
Peak Size: The maximum size of the file share.
-
Actual Size: The actual size of the file share.
-
Used Capacity: The current capacity used in the file share.
-
-
Latency (ms): The latency graph displays the following information.
-
Read Latency (avg): The average read latency.
-
Write Latency (avg): The average write latency.
-
-
Savings%: The Savings graph displays the savings percentage.
-
Related Topics
Comments (0 comments)