@prasantc For considering direct cloud access vs. VPN to corpnet, I’d consider not only network speed, but also ease of connectivity and cost. If you have already has their end users setup to VPN into corpnet that might be the easiest thing to do and it avoids some egress costs because they can read from the AFS cache.
If they are doing creative stuff with Adobe, using WVD is probably the best approach such that the storage is located near compute and they can be sure they get great performance.
“can I use file sync after the all the file share data has been migrated to the cloud?”. Yes, they can use file sync after the data is migrated. You should keep in mind that if you are doing direct cloud access in combination with file sync that there is a delay syncing direct cloud changes to the file sync endpoints. You can avoid that delay by using a file sync running in IaaS if they need immediate sync everywhere.
Also here are some additional details on working from home/anywhere with Azure Files:
Working from home with Azure file shares.
There are several ways to connect to Azure Files from home.
For this article we will assume that you want to use Active Directory to secure access to files and your machine is AD joined. You could also connect using a shared storage account key as described here.
There are three primary options to consider
- VPN into your corporate network.
- Point to Site (P2S) VPN to connect your home PC to Azure
- MyWorkDrive (3rd party product) to eliminate the need for VPN and access your files via a web browser or mapped drive client.
You may even consider a combination of these access methods for different end users.
VPN Into Corporate Network
Many corporations have VPN connectivity into their corporate network already setup. If the customer has already setup access to Azure files shares from corpnet, this I the most straightforward method. How to connect to Azure files from corporate network.
Point to Site VPN to connect home PC to Azure
In order to use AD, the users machine will need network access to both an Active Directory domain controller and Azure file share.
Running an AD server in IaaS is the most common method. Syncing AD credentials to AAD is not enough, you must have a domain controller accessible to the home computer.
Rather than running AD in Azure, it would also be possible to setup a Site to Site VPN or Expressroute connection from the corporate network where AD is running to Azure. This way when the user does a P2S VPN connection to Azure they can connect to AD through the always-on connectivity between their corporate network and Azure.
How to setup P2S VPN with Azure Files.
My Work Drive
MyWorkDrive eliminates the need for the client machine to use VPN and also eliminates the need for the client machine to be AD joined. Need to access files from the family computer, no problem! MyWorkDrive even includes integration with Office365 online so you can edit your documents right in the web browser.
My Work Drive allows three modes of accessing files
(1) Web Browser. This requires no software installation and can be accessed from anywhere including mobile devices.
(2) Mapped Drive Agent. This requires installation of an agent on your machine and will make your files appear as a drive on your computer. No VPN required because the mapped drive client works over HTTPs.
(3) Mobile App for iPhone and Android.
MyWorkDrive is installed on a Windows Server and connected to an Azure file share. It can be run in on-premises and connected to an Azure File Sync instance or could be run in Azure. In either case, MyWorkDrive will need connectivity to an Active Directory Domain Controller.
How to Setup MyWorkDrive with Azure Files
Kindly let us know if the above helps or you need further assistance on this issue.
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Please don’t forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.