▰FilvoriAZURE FILE WORKSPACESLet’s talk
THE DETAILS BEHIND THE WORKSPACE

Built for your
environment.

Explore migration, access and security before we scope your deployment.

Discuss your requirements
CONNECTED TO WHAT YOU ALREADY HAVE

The workspace fits you.
You don’t fit the workspace.

STORAGE

Files in your Azure

Your Azure Files share remains the authoritative library. Search indexes and optional preview caches are configured as part of the agreed deployment.

IDENTITY

Your Microsoft sign-in

Connect the portal to your Entra tenant. Configure file access separately for the identity-based or storage-key method suited to your environment.

WORKFLOW

Your applications, connected

Keep File Explorer and installed desktop applications. Our custom portal and Windows helper connect file discovery to that familiar workflow.

04 / THE MIGRATION IS PART OF THE SOLUTION

Your folders have history.
We keep it intact.

Moving a file server is more than copying data. We plan access, validate the transfer and coordinate rollout so your team can keep working.

FROM LEGACY STORAGE TO AZURE

Move the infrastructure.
Preserve the workflow.

  • Multi-terabyte migration planning
  • Existing folder structure preserved
  • Integrity checks and delta copies
  • Agreed cutover and minimal disruption
  • Optional after-hours cutover
Discuss your migration
01

Discovery

Understand storage, permissions, devices and dependencies.

02

Architecture

Design Azure storage, identity, networking and access.

03

Initial migration

Transfer the existing file library and folder hierarchy.

04

Delta sync

Copy changes made while the team continues working.

05

Validation

Check integrity, file counts, paths and user access.

06

User rollout

Deploy drive access and the desktop helper.

07

Cutover

Switch access in an agreed change window.

08

Post-cutover support

Resolve issues and monitor the new workspace.

05 / SAME DRIVE LETTER. NEW FOUNDATION.

Mixed devices?
No problem.

Choose the access method that fits your Microsoft environment. Kerberos is preferred where supported; a controlled mapper is an alternative when it’s impractical.

PREFERRED WHERE SUPPORTED

Entra Kerberos mapping

Identity-based Azure Files access for supported Microsoft-managed environments.

  • No shared storage key exposed to users
  • Share-level RBAC and file/folder ACL enforcement
  • Familiar Windows mapped drives
  • Intune, GPO or script deployment
  • Environment compatibility assessed in discovery
CONTROLLED FALLBACK OPTION

Secure storage-key mapper

A deployment option for mixed Windows devices and environments where Kerberos is unsuitable.

  • Central credential handling and key rotation
  • Keys kept out of hardcoded user scripts
  • Automatic reconnect and controlled rollout
  • User, device and mapping timestamp audit options

Storage-key mapping bypasses individual user RBAC and file/folder ACL restrictions. Credential handling and audit do not provide per-user file permissions.

EXPLORER INTEGRATION

Search in the browser.
Work in File Explorer.

Open a file in its native application, open its folder or select it in Explorer. A deployed Windows helper handles the browser handoff, with allowed paths restricted as part of the deployment.

S:\Legal\Agreements\2026
06 / DESIGNED AROUND BUSINESS ACCESS

Control belongs
in the architecture.

Identity, permissions and recovery are designed together. Security controls and audit scope are agreed for each deployment.

01 / IDENTITY

Microsoft sign-in

Entra ID controls portal sign-in. Portal access is separate from permissions on the underlying files.

02 / PERMISSIONS

Permissions depend on access

Identity-based SMB access uses share-level permissions and file/folder ACLs. Storage-key mapping grants broad access; it does not enforce individual user permissions.

03 / VISIBILITY

Auditable activity

Mapper logs, user and device activity, and reporting options for the selected service scope.

04 / RESILIENCE

A recovery plan

Snapshots, previous versions, monitoring and recovery procedures tailored to your workspace.

Portal sign-in does not automatically restrict individual search results or previews. Any per-file permission filtering must be separately scoped and validated, along with indexing freshness and recovery objectives.

08 / THE PRACTICAL QUESTIONS

Before you
make the move.

Every environment is different. Discovery establishes what fits yours.

Can we keep our folders and drive letters?

Yes. Preserving your folder hierarchy and familiar drive letters is a core migration goal. Path-dependent applications are reviewed before cutover.

Can users keep File Explorer and their desktop applications?

Mapped drives keep the desktop workflow available. Files open in their installed native applications, subject to application compatibility, file locking and network performance checks.

Do we need Kerberos on every device?

No. We assess Kerberos suitability first. A controlled storage-key mapper can be scoped for mixed devices or fallback access, with credential and audit controls.

Can you migrate multiple terabytes and search a million files?

The solution can be architected for large repositories. Storage, search capacity, networking and indexing are sized for your file count and change rate. Performance is validated rather than assumed.

What files can be previewed?

The preview service generates image and first-page PDF thumbnails. AI, EPS, CDR, PSD and Office files receive type icons; native document rendering is not included.

Can search open a file or show it in its folder?

Yes, with the Windows Explorer integration helper installed and the source path accessible. The helper registers a browser protocol and handles open, folder and select-file actions. Copying paths does not require the helper.

How is access secured?

Entra protects portal sign-in. Identity-based SMB access uses share-level permissions and file/folder ACLs; storage-key mapping does not enforce individual user permissions. Search results and previews need their own permission enforcement, which is not established by portal sign-in alone.

What about remote access and blocked port 445?

Direct Azure Files SMB access needs network connectivity over TCP 445. If a network or ISP blocks it, we assess VPN or hybrid access options. Connectivity and application performance are checked during discovery before deployment.

Can deployment use Intune or GPO?

Yes. Drive mapping and the desktop helper can be packaged for managed rollout. The deployment method depends on device ownership, join status and your management tooling.

What happens when files change or keys rotate?

Continuous indexing is configured for the agreed freshness requirement. Preview cache keys include the file path and modified time. Mapper key rotation and reconnect behaviour are planned and tested for your environment.

Can you handle cutover and ongoing support?

Yes. Migration, cutover, monitoring and ongoing support can be included in your proposal. After-hours work and extended coverage are agreed before delivery.