Configure Azure Files

Create an Azure Files group that will contain the file shares and files you want to manage and back up.

Note

Only StorageV2 (GPv2) storage accounts are supported. Storage (GPv1) accounts must be migrated to GPv2. See Microsoft documentation.

Before You Begin

  1. From the Command Center navigation pane, go to Explore > Service catalog.

Choose Azure Files

  1. On the Object Storage tile, click Configure.

  2. Select Azure File.

    The Select Access Node page of the wizard appears.

Configure Permissions

  1. You can choose to use either the hosted infrastructure provided by Commvault or your own configured access nodes for backups.

    • Use hosted infrastructure: Select this option to use the hosted infrastructure provided by Commvault for backups. Then, select the region where the Azure File data is hosted, and then click Next.

    • Use your access nodes for backups: Select this option to use an existing access node or create your own access nodes for performing backups.

      When using your own access nodes, ensure that the Cloud Apps package is installed for object storage operations.

      Note

      • If the MSP has configured a workload resource pool in a single region and no access node is configured by the tenant, this step will not appear. Access nodes configured in the workload resource pool are selected automatically.
      • If the Azure storage account has Enabled from selected virtual networks and IP addresses selected in Security + networking > Networking settings and also has a private endpoint enabled, add the access node's VNet/Subnet to the storage account's allowed virtual networks list.
  2. From the Credential list, select an existing credential or create a new credential.

    • If you have an existing Azure app, add a new credential.

      Steps to add a new credential
      1. Beside Credential, click the add button add/plus button - gray - no border.

        The Add credential dialog box appears.

      2. From the Account type list, verify that Cloud Account is selected.

      3. From the Vendor type list, verify that Microsoft Azure is selected.

      4. In Credential name, enter a descriptive name for the credentials.

      5. In Directory (tenant) ID, enter the tenant ID for the Azure account.

      6. In Application (client) ID, enter application ID for the tenant.

      7. In Application secret, enter the secret key value that is generated for the application.

      8. From the Environment list, verify that AzureCloud is selected.

      9. To view and modify Azure endpoint URLs that Commvault will use to connect to Azure during VM onboarding, enable the Show endpoints toggle key. If your environment requires custom endpoints (for example, Azure Government or other sovereign cloud environments), you can modify the following endpoints:

        • Authentication endpoint: Used to verify identity and obtain access tokens from Azure.

        • Storage endpoint: Used to access Azure storage resources.

        • Management endpoint: Used to communicate with Azure Resource Manager (ARM) for managing VM resources.

      10. In Description, enter a description of the credentials.

      11. From the Key Rotation Reminder Interval list, select a suitable interval to receive reminder to rotate the credential.

      12. Click Save.

    • If you want to add a new Azure application and a credential, follow the steps below.

      Steps to add a new Azure application
      1. Beside Credential, click the add button add/plus button - gray - no border.

        The Add credential dialog box appears.

      2. From the Account type list, verify that Cloud Account is selected.

      3. From the Vendor type list, verify that Microsoft Azure is selected.

      4. In Credential name, enter a descriptive name for the credentials.

      5. Under Application ID, expand How to get your Application ID, on the Create a new application tab, do the following:

        1. Under step 3, click the link to open Azure Cloud Shell.

        2. Follow the instructions that appear and select Bash or PowerShell.

        3. Return to the Command Center window, in the Application name box, enter a name for the Azure application.

        4. In the Subscription ID box, enter your Azure subscription ID. Click Get Subscription ID if you need to get the ID using the command.

        5. Copy the PowerShell or Bash commands to deploy the application in the selected subscription and get the application details.

          If you have the application ID, tenant ID, and secret key, enter them. Otherwise, run the commands to get these details.

        6. At the Azure Cloud Shell command prompt, paste the commands.

        The commands run to create a new Azure application, and then the Tenant ID, Application ID, and Application secret for the application are displayed.

        1. Copy Tenant ID, Application ID, and Application Secret from the shell.
      6. Switch to Add credentials dialog box, and then paste the Tenant ID, Application ID, and Application secret to create the credential.

      7. From the Environment list, verify that AzureCloud is selected.

      8. To view and modify Azure endpoint URLs that Commvault will use to connect to Azure during VM onboarding, enable the Show endpoints toggle key. If your environment requires custom endpoints (for example, Azure Government or other sovereign cloud environments), you can modify the following endpoints:

        • Authentication endpoint: Used to verify identity and obtain access tokens from Azure.

        • Storage endpoint: Used to access Azure storage resources.

        • Management endpoint: Used to communicate with Azure Resource Manager (ARM) for managing VM resources.

      9. In Description, enter a description of the credentials.

      10. From the Key Rotation Reminder Interval list, select a suitable interval to receive reminder to rotate the credential.

      11. Click Save.

  3. If you want to assign required roles to your Azure application, follow the steps below.

    Steps to assign a role to the Azure application
    1. Click Assign Role.

    2. In the Assign role dialog box, do the following:

      1. Copy the PowerShell or Bash commands into a text editor.

      2. Replace ROLE_NAME with the name of your role.

      3. In the information box shown at the top, click Open Azure Cloud Shell.

    3. Follow the instructions that appear and select Bash or PowerShell.

    4. At the Azure Cloud Shell command prompt, paste the commands.

      The commands runs to assign the required role.

    5. Switch to Assign role dialog box, and then click Close.

  4. To define a custom role, follow the steps below.

    Steps to define a custom role
    1. Log on to the public Azure portal with service administrator credentials.

    2. Use CommvaultAzureFiles.json and assign it to back up Azure Blob Storage.

      For more information about creating a custom role, go to Custom roles for Azure resources on the Microsoft Azure documentation website.

    3. On the Access Control (IAM) tab, click Add, and then select Add role assignment.

      The Add role assignment pane appears.

    4. Specify the following:

      1. From the Role list, select the custom role that you created.

      2. From the Assign access to list, select User, group, or service principal.

      3. In the Select box, enter the application name, and then select the application.

    5. Click Save.

  5. Click Next.

Access Node

  1. Do any of the following:

    • For backups using Commvault hosted infrastructure, select the region where the backup data is available.

    • For backups using your own access nodes, select the existing access node or create your own access nodes.

  2. Click Next.

Plan

  1. Select an existing backup plan or create a new backup plan to associate with Azure File.

  2. Click Next.

Cloud Account

  1. Select an existing cloud account or create a new cloud account for object storage.

Backup Content

  1. Select the backup content you want to protect, such as file shares and files.

  2. Click Next.

Summary

  1. Review your selections, and then click Finish to complete the configuration.

To discover the storage accounts in an Azure subscription for backups, see Discovering Azure File Storage Accounts On Demand.

×

Loading...