Home icon

Enhance your SMB file transfer security with Kerberos and AWS DataSync

Storage Blog



This article discusses how to enhance SMB file transfer security using Kerberos authentication with AWS DataSync, especially as Microsoft is deprecating NTLM authentication.

  • DataSync now supports Kerberos authentication for SMB locations
  • Kerberos provides enhanced security and mutual authentication without transmitting passwords
  • The configuration requires creating a Service Principal Name, generating a keytab file, and configuring a Kerberos configuration file
  • Key steps include: - Assigning a Service Principal Name - Creating a krb5.conf file - Configuring the DataSync SMB location with Kerberos
  • Prerequisites include network connectivity, DNS resolution, and time synchronization

The walkthrough provides a step-by-step guide to implementing Kerberos authentication with AWS DataSync, helping organizations move away from the deprecated NTLM protocol.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jan 28
2025
AWS DataSync adds support for Kerberos authentication
Dec 12
2025
AWS DataSync increases scalability and performance for on-premises file transfers
Oct 1
2025
AWS DataSync now supports VPC endpoint policies
Sep 16
2025
Building a Unified Customer 360 Solution for SMB Growth on AWS

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.