AWS DataSync Enhanced Mode Adds HDFS, Azure Blob, Self-Managed Object Storage, and Hyper-V Support
Cloud

AWS DataSync Enhanced Mode Adds HDFS, Azure Blob, Self-Managed Object Storage, and Hyper-V Support

AWS DataSync Enhanced mode now supports transfers with HDFS, Microsoft Azure Blob Storage, and self-managed object storage, and agents can now run on Microsoft Hyper-V; note that transfers between Azure Blob and Amazon S3 using Enhanced mode do not require an agent.

3 min read
Back to News
TL;DR
  • -AWS DataSync Enhanced mode now supports transfers with HDFS, Microsoft Azure Blob Storage, and self-managed object storage; agents can also run on Microsoft Hyper-V, though transfers between Azure Blob and Amazon S3 using Enhanced mode do not require an agent.
  • -HDFS support includes high-availability NameNode configurations and Transparent Data Encryption with Kerberos; Azure Blob transfers need correctly scoped SAS tokens; self-managed object storage requires S3 API compatibility.
  • -Before piloting, verify Kerberos and TDE readiness for HDFS, check SAS token permissions for Azure Blob, and audit S3 API coverage for self-managed object storage.

New Location Types in Enhanced Mode

AWS expanded Enhanced mode in DataSync on July 28, 2026. Three location types now qualify: Hadoop Distributed File Systems (HDFS), Microsoft Azure Blob Storage, and self-managed object storage. Separately, DataSync agents can now be deployed on Microsoft Hyper-V.

The capability is available in all AWS Regions where DataSync is offered.

Using a DataSync agent, teams can transfer data to and from these locations with the parallelism, unlimited file counts, and detailed metrics that Enhanced mode provides.

What Each Location Type Requires

HDFS. Enhanced mode HDFS support includes multiple NameNode configurations for high availability and Transparent Data Encryption (TDE) with Kerberos authentication. AWS describes this as enabling organizations in regulated industries to securely migrate petabyte-scale encrypted Hadoop data without sacrificing availability. If your cluster uses Kerberos, verify realm reachability from the agent host before configuring a transfer. If TDE is enabled, confirm that keys are accessible to the agent.

Microsoft Azure Blob Storage. DataSync authenticates to Azure Blob using a shared access signature (SAS) token. The permissions the token must carry depend on its scope and the direction of transfer.

One important exception applies before discussing token requirements: transfers between Azure Blob and Amazon S3 using Enhanced mode do not require an agent. Most other Azure Blob transfer paths require a DataSync agent.

For account-level tokens, transfers from Azure Blob require Allowed services – Blob and Allowed resource types – Container, Object; omitting these prevents DataSync from transferring object metadata, including object tags. The token also needs Read and List permissions. If you want DataSync to copy object tags, add Read/Write blob index permissions.

For transfers to Azure Blob using an account-level token, Read, Write, and List are required at minimum; also require Allowed services – Blob and Allowed resource types – Container, Object, since omitting these prevents DataSync from transferring object metadata. Add Delete if you want DataSync to remove objects absent from the source, and Read/Write blob index permissions if you want tags copied.

For container-level tokens, transfers from Azure Blob require Read and List permissions at minimum; add Tag permission if you want DataSync to copy object tags. Transfers to Azure Blob need Read, Write, and List at minimum; add Delete (if you want DataSync to remove files that aren't in your transfer source) and Tag (if you want DataSync to copy object tags).

Not having the correct permissions can cause your transfer to fail. Also confirm that your SAS token does not expire before the transfer completes. If it expires mid-transfer, DataSync loses access to the location; update your location with a new SAS token and restart your DataSync task.

Azure Blob transfer locations can be created in any AWS Region that DataSync supports.

Self-managed object storage. Transferring data to or from on-premises object storage requires a DataSync agent. There is also a compatibility prerequisite: your object storage system must support a specific set of Amazon S3 API operations for DataSync to connect. That list includes AbortMultipartUpload, CompleteMultipartUpload, CopyObject, CreateMultipartUpload, DeleteObject, DeleteObjects, DeleteObjectTagging, GetBucketLocation, GetObject, GetObjectTagging, HeadBucket, HeadObject, ListObjectsV2, PutObject, PutObjectTagging, and UploadPart. Any gap in your storage vendor's supported operations blocks the transfer.

Pull the full list from the DataSync documentation and check it against your vendor's API surface before provisioning.

Hyper-V agents. The announcement confirms agent support on Hyper-V but does not state specific version requirements or minimum resource allocations. Confirm those details in the DataSync documentation before provisioning a Hyper-V host.

Checks Before a Pilot

Infrastructure, cloud, and data platform leaders should address three areas before committing resources.

For HDFS, if your cluster uses Kerberos, test realm reachability from the agent host. If TDE is active, verify key access. Also review the documentation for supported NameNode high-availability variants.

For Azure Blob, audit SAS token scope and permissions against the transfer direction before scheduling any task. A misscoped token can cause the transfer to fail. If you are moving data between Azure Blob and Amazon S3 under Enhanced mode, note that no agent is required for that path.

For self-managed object storage, map your storage vendor's supported S3 API operations against the DataSync prerequisite list. Find any gaps before the pilot begins.

Start in the AWS DataSync console and review the documentation for each new location type before provisioning agents or scheduling production transfers.

Sources and supporting resources
Previous
OpenAI Evaluation Escaped Its Sandbox Through a Trusted Package Proxy and Reached Hugging Face
Next
Amazon Links axios, debug, chalk, and typo-crypto NPM Compromises to DPRK Group SAPPHIRE SLEET

Get Business Technology Updates

Problem-led guidance on manufacturing operations, integration, portals, analytics, automation, custom software, trusted records, and fit-for-purpose engineering.

No spam. Unsubscribe anytime.