Adding Blob storage as a Cloud Provider in eShare
This Document will provide the admin with a step-by-step guide to create a Blob storage account, add it in eShare web portal and create a sharing policy for this Blob storage.
Creating the Blob Storage Account
To add a blob storage account in eShare we will first need to create one in Azure.
- In the Azure Portal, go to All services > the Storage category > Storage accounts.
- Under Storage accounts, select Add.
- In the Subscription field, select the subscription in which to create the storage account.
- In the Resource group field, select an existing resource group or select Create new, and enter a name for the new resource group.
- In the Storage account name field, enter the name for the account. Note the following guidelines:
- The name must be unique across Azure.
- The name must be between three and 24 characters long.
- The name can include only numbers and lowercase letters.
- In the Location field, select a location for the storage account, or use the default location.
6. Click Next for all other options, leaving them as default, and then select Create.
Creating Mail-enabled security group
Once we have created our Blob storage, we will need to create a Mail-enabled Security group to access it.
- As an Organization Administrator log in to MS 365 admin center and navigate to Teams & Groups>Active teams & groups>Security Groups>Add mail-enabled security group.
- Type the name of the Mail-enabled Security group and select Next.
- Assign the owners to manage the group and then select Next.
- Add members that can access the group.
- Create a group email address that will be referenced when adding the group to eShare, and then select Next to proceed.
- Review the final settings and membership, then finalize and create the group.
Creating a container
Once the Blob storage creation is complete, a container will need to be created as a location for data to land in.
- Navigate to the newly created Blob storage and create a container.
Adding Blob storage in Cloud Web Portal
Once we have created our Blob storage, we will need to add it in the eShare Web Portal so users can begin utilizing the new storage account.
- As an Organization Administrator log in to the eShare web Portal and navigate to Admin Console tab.
- Navigate to Azure Blob Settings and select Add Blob Storage.
- Here you will need to add the information for the Blob storage account we created earlier in Azure.
- The Name* field is the name the storage account will have in eShare.
- The Account name* is the name you assigned to your Blob storage during its creation in Azure
- The Account key* required for the Blob Storage, is located in Azure under Security + networking > Access Keys.
- Once you have verified all the fields are populated correctly go ahead and click save account. The new blob storage should appear in the list and be ready for use.
In the case of having multiple blob storage accounts and a different account is in use already, you will need to disable the account in use by selecting it and clicking the disable button.
(Note: Only ONE Azure Blob storage account can be active at any time).
Adding the user group to access the Blob storage.
Once we have added our Blob storage in CWP, we will need to add the user group that we want to have access to the Blob storage.
- As an Organization Administrator log in to the eShare web portal and navigate to Admin Console tab.
- Navigate to Azure AD User Group and select Add Group.
- Select Add Group > Search Org for Groups >Type the name of the group> Select Cloud Provider – Blob > Add Group.
Creating a sharing policy for the Azure Blob
Organization’s administrator will need to set a sharing policy that will be used with the new endpoint. They can set the options that would like to use for the TS, e.g. download, view, login and/or pin required and expiration. An Azure icon denotes that this policy will be used as the blob policy.
Depending on the needs, the options can be set accordingly. Download or view options and expiration duration are mandatory. This type of shares does not support the upload, delete and secure conversation options.
Assigning the Blob policy to the newly added group.
- As an Organization Administrator log in to CWP and navigate to Admin Console tab.
- Navigate to Azure AD User Group, select the group, under Actions click on the 3-dot menu and select Assign Sharing Policy.
- Select the Blob Sharing Policy and click on Save.
Activating Blob Storage as a Cloud Provider
To add the Blob storage as a Cloud provider, go to Azure Blob Settings > Select the Blob Storage account and select Enable Cloud Provider.
Once the Blob is activated, users will see the storage as a Cloud Provider upon next login. Only users who are designated as members of the Security group will be able to access the Azure Blob container as a Storage provider. Users will only be able to see the Blob Storage from the Cloud Provider page within the eShare portal.
If you would like to use the Share-With-Me link functionality with the Blob, you will need to enable it by going to Azure Blob Settings > Select the Blob Storage account and select Enable SWM.
Ensure you have created a container within the Azure Blob Storage Account called sharewithme.
Once enabled, the Share-With-Me link URL will be https://<eshare_url>/bme/<emailaddress> (ex. https://secure.aerospacerocks.com/bme/tim@aerospacerocks.com).