AZ-802 storage and file services explained

Updated September 29, 2026

Manage storage and file services is worth 15–20% of AZ-802 and has more objectives than any other domain. It covers three areas: Azure Files and Azure File Sync, Windows Server file shares, and the Windows Server storage stack from disks to encryption. Questions are about choosing the right feature for a requirement and knowing its prerequisites: what a feature needs, what it cannot do, and which edition or file system it works with.

Azure Files and Azure File Sync

Azure file shares

An Azure file share is an SMB share in a storage account. Access is layered:

LayerControlsSet with
Share-levelWho can mount the shareAzure RBAC roles such as Storage File Data SMB Share Contributor, or a default share-level permission
Directory and file levelWhat they can do insideWindows ACLs (NTFS permissions)

For identity-based access, the storage account is joined to your AD DS domain (or uses Microsoft Entra Kerberos for hybrid identities). Clients then connect over port 445 with their domain credentials. Many ISPs block 445, which is a common reason a share cannot be mounted from outside.

Azure File Sync

File Sync keeps Windows file servers and an Azure file share in sync.

ComponentRole
Storage Sync ServiceThe Azure resource that holds sync groups
Registered serverA server with the agent, registered to one Storage Sync Service
Sync groupOne cloud endpoint (an Azure file share) and its server endpoints
Server endpointA path on a registered server

Cloud tiering keeps frequently used files local and replaces the rest with pointers, recalled on access. It is set per server endpoint by volume free space and a date policy, and cannot be used on a system volume. Monitor sync health in the Storage Sync Service and in Azure Monitor metrics.

Migrating from DFS Replication: replace the DFS-R replication group with a sync group, add each server as a server endpoint, and remove DFS-R from those folders. File Sync and DFS-R must not replicate the same folder. To move shares into Azure Files outright, tools include Robocopy, AzCopy and File Sync itself.

Windows Server file shares

  • Access: share permissions and NTFS permissions combine, and the most restrictive wins. Access-based enumeration hides folders a user cannot open.
  • FSRM: quotas (hard or soft, by folder), file screens (active to block, passive to monitor), file management tasks, classification and storage reports.
  • DFS Namespaces present shares from several servers under one path; DFS Replication keeps folder copies in sync between servers.
  • SMB over QUIC lets clients reach file shares over UDP 443 with TLS 1.3, without a VPN. It needs a certificate on the file server whose subject name clients use, and client access control can be limited by certificate.
  • SMB settings: signing, encryption per share or server, and disabling SMB 1.0.

Windows Server storage

Storage Spaces and Storage Spaces Direct

Storage Spaces pools disks on one server into virtual disks with simple, mirror or parity resiliency. Storage Spaces Direct (S2D) pools the local disks of the nodes in a failover cluster, requires Datacenter edition, and presents Cluster Shared Volumes. Two-way mirror tolerates one failure; three-way mirror tolerates two and needs at least three nodes.

Replication, efficiency and performance

FeatureWhat it does
Storage ReplicaBlock-level volume replication, synchronous or asynchronous, server-to-server, cluster-to-cluster or stretch cluster
Data DeduplicationStores repeated chunks once; usage types for general file servers, virtualisation and backup
SMB DirectSMB over RDMA network adapters, for low latency and low CPU use
Storage QoSMinimum and maximum IOPS policies for VM disks on CSV storage

Storage Replica needs log volumes on both sides, and the destination volume is not accessible while it replicates. Deduplication cannot run on system or boot volumes.

File systems and iSCSI

NTFSReFS
Boot volumeYesNo
EFS and disk quotasYesNo
Integrity streams and block cloningNoYes
Best forGeneral useHyper-V, S2D and backup targets

iSCSI Target Server exposes virtual disks as LUNs over the network. Initiators are identified by their IQN, and CHAP authenticates them. MPIO gives redundant paths.

BitLocker

BitLocker encrypts volumes with protectors such as the TPM, a PIN, a startup key or a recovery password. Back up recovery passwords to AD DS with Group Policy before you need them. Network Unlock lets domain-joined servers with a TPM boot unattended on the corporate network. Tools: manage-bde, the BitLocker cmdlets, and repair-bde to recover data from a damaged volume.

Sample questions

Question 1. A branch file server holds 4 TB of documents, but only a few hundred gigabytes are used in any month. The server has 1 TB of local disk. All files must stay available to branch users through the same share. What should you implement?

  • A. DFS Replication to a larger hub server
  • B. Data Deduplication on the data volume
  • C. Azure File Sync with cloud tiering on the server endpoint
  • D. Storage Replica to an Azure VM
Show answer

Answer: C

Azure File Sync with cloud tiering keeps frequently used files on the server and the rest in the Azure file share, recalling them on access, so a small local disk can serve a large dataset through the same share. DFS Replication needs a full copy on each server. Deduplication saves space but cannot shrink 4 TB of mostly unique documents enough. Storage Replica replicates whole volumes.

Want more questions like this? Full AZ-802 practice tests →

Question 2. Remote staff must reach internal file shares without a VPN. Outbound TCP 445 is blocked on most home networks, and the company wants TLS 1.3 protection. What should you configure?

  • A. SMB over QUIC with a certificate on the file server
  • B. SMB Direct on the file server
  • C. SMB encryption on the shares
  • D. Azure File Sync to an Azure file share
Show answer

Answer: A

SMB over QUIC carries SMB over UDP 443 with TLS 1.3, which suits clients on the internet without a VPN. SMB Direct is for RDMA networks in the datacenter. SMB encryption protects traffic but still needs port 445. Azure File Sync does not change how remote clients connect to on-premises shares.

Want more questions like this? Full AZ-802 practice tests →

Question 3. Users must be blocked from saving video files to a departmental share, and you want an email to the administrator when someone tries. What should you configure?

  • A. A passive file screen
  • B. A hard quota on the share
  • C. Access-based enumeration on the share
  • D. An active file screen with an email notification
Show answer

Answer: D

An FSRM active file screen blocks the listed file groups, such as video files, and can send an email notification. A passive screen only monitors. A hard quota limits size, not file type. Access-based enumeration hides folders but does not filter file types.

Want more questions like this? Full AZ-802 practice tests →

What to practise

Mount an Azure file share with AD DS authentication, then register a lab server with File Sync and turn on cloud tiering. Build a DFS namespace with two targets, add an FSRM quota and file screen, and enable SMB over QUIC with a self-signed certificate on a test server. Finally, create a mirrored storage space, enable deduplication on a data volume, connect an iSCSI LUN from another server, and encrypt a volume with BitLocker while backing up its recovery password to AD.