Can Azure AD-Joined PCs Access On-Premises File Servers?
Question details
The organization needs to maintain access to legacy on-premises file servers from PCs that are joined directly to a cloud-only Azure AD environment.

- Product
- Azure Active Directory
- Device & OS
- not provided
- Scenario
- Migrating from a hybrid Active Directory to a cloud-only environment while still relying on local on-premises file servers.
- Observed behavior
- Users are looking for the correct authentication methods and configurations required to seamlessly access local shares from cloud-joined devices.
Ensure that your organization's Azure AD Connect is actively synchronizing identities between your on-premises Active Directory and Azure Entra ID (Azure AD), as seamless access relies on these synchronized identities.
Utilize Identity Synchronization and Network Line-of-Sight
Configure identity synchronization so cloud-joined PCs can obtain the necessary Kerberos tickets for on-premises file server access.
Even if a Windows PC is strictly joined to Azure AD, it can still authenticate against on-premises resources that use traditional Active Directory authentication. This works seamlessly if the user signing into the PC has a hybrid identity (synchronized from the local AD).
The primary requirement for this to function is that the Azure AD-joined device must have a network line-of-sight to your on-premises Domain Controllers.
Confirm with your IT administrator that Azure AD Connect is running and successfully syncing your local Active Directory user accounts to the cloud.
Ensure the Azure AD-joined PC is connected to the corporate network either via direct internal Ethernet/Wi-Fi or a secure VPN connection.
Open File Explorer and type the UNC path of your on-premises file server (e.g., \\ServerName\ShareName). Windows will automatically request a Kerberos ticket in the background and grant access without additional prompts.

Consult Microsoft Q&A for Complex Decommissioning Scenarios
If your organization plans to completely shut down the on-premises Active Directory, you will need specialized architectural guidance.
Manage Your Documents Seamlessly Across Cloud and Local Storage
While your IT team configures advanced network and server access for your cloud migration, ensure your employees have a fast, reliable, and cost-effective office suite. WPS Office is a highly compatible alternative that works beautifully on Azure AD-joined devices, allowing users to open, edit, and save files directly to on-premises servers or cloud storage.
- 1. Download the Installer: Visit the official WPS Office website and download the installer package to your Azure AD-joined PC.
- 2. Install WPS Office: Run the installer. The lightweight design ensures it installs in seconds, ready for immediate use.
- 3. Access Network Documents: Open WPS Office and navigate to your mapped on-premises network drives or UNC paths to open and edit legacy documents natively.

Frequently Asked Questions
Do I need a VPN for an Azure AD-joined PC to access on-premises file servers?
Yes, if the device is operating remotely. An Azure AD-joined PC requires network line-of-sight to the on-premises Domain Controller to authenticate. If the device is not physically on the corporate network, a VPN connection is mandatory.
Will file server access work if we completely turn off our on-premises Active Directory?
No. If the on-premises Active Directory is fully decommissioned, legacy file servers that rely on Kerberos or NTLM will not function properly for user authentication. You would need to migrate the file server data to cloud solutions like Azure Files or SharePoint.
Can cloud-only Azure AD users access the on-premises local servers?
No. Only users whose identities are actively synchronized from the on-premises Active Directory (hybrid identities) can seamlessly access legacy on-premises file servers. Cloud-only users lack the required on-premises Security Identifiers (SIDs).




