An SMB signing Group Policy setup makes Windows clients and servers sign every SMB packet, so an attacker in the middle cannot alter traffic or relay credentials to a file share. Windows 11 24H2 and Windows Server 2025 changed the defaults, and many admins first meet this topic when an old NAS or scanner stops working. This guide explains the defaults, the four signing policies and their registry values, how to keep third-party storage working, how guest access fits in, and how to audit and remove SMBv1 across the domain.
Short answer: In a GPO linked to your computer OUs, enable Computer Configuration » Policies » Windows Settings » Security Settings » Local Policies » Security Options » "Microsoft network client: Digitally sign communications (always)" and “Microsoft network server: Digitally sign communications (always)”. Only the (always) settings matter for SMB 2 and 3. Check with Get-SmbClientConfiguration | Format-List RequireSecuritySignature, and before rollout confirm every NAS and Linux share supports signing.
Table of Contents
What changed in Windows 11 24H2 and Windows Server 2025
| System | Outbound (client) signing | Inbound (server) signing |
|---|---|---|
| Windows 11 24H2 and later: Enterprise, Pro, Education | Required | Required |
| Windows 11 24H2 Home | Not required | Not required |
| Windows Server 2025 | Required | Not required (domain controllers: see below) |
| Domain controllers, all versions | Per OS default | Required by the Default Domain Controllers Policy |
Windows 11 24H2 and Windows Server 2025 also block insecure guest logons to SMB shares by default.
So on a fresh Windows 11 24H2 Pro machine, signing is already required even without any GPO. An SMB signing Group Policy object is still useful: it makes the setting explicit for Windows 10 and older servers, prevents local changes, and gives you one place to create exceptions.
Why signing matters
Without signing, an attacker who can sit between a client and a server, for example through a spoofed name response on the local network, can relay the user’s NTLM authentication to another server or change the data in transit. Signing adds a cryptographic signature to each message using a key from the session’s authentication, so tampered or relayed messages are rejected. It does not encrypt the data; that is a separate option covered later. Requiring signing is one of the most effective controls against NTLM relay, which is why Microsoft made it the default and why an SMB signing Group Policy baseline belongs next to your NTLM reduction work.
Which method to use
| Method | Scope | Pros | Cons |
|---|---|---|---|
| GPO Security Options | All domain-joined machines | Central, reportable, covers old OS versions | Needs an exception GPO for legacy storage |
Set-SmbClientConfiguration / Set-SmbServerConfiguration | One machine or a script | Instant; good for testing | A GPO overwrites it on refresh |
Registry (RequireSecuritySignature) | Images, workgroup servers | No tools needed | Easy to leave behind |
| Intune Settings catalog (Local Policies Security Options) | Cloud-managed devices | Same setting without AD | Do not set it in both places |
Prerequisites
- A list of every SMB server your clients use: Windows file servers, NAS devices, Linux Samba servers, printers and scanners with scan-to-folder, backup appliances and old applications.
- A list of SMB clients that connect to your Windows servers, such as copiers, Linux hosts and old embedded systems.
- A pilot OU with at least one machine that uses each type of storage.
- Rights to edit and link GPOs, and PowerShell 5.1 or later on the machines you test.
Method 1: Require SMB signing with a GPO
The four policies
| Policy (Security Options) | Registry value | Effect on SMB 2/3 |
|---|---|---|
| “Microsoft network client: Digitally sign communications (always)” | HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters\RequireSecuritySignature | Client requires signing |
| “Microsoft network server: Digitally sign communications (always)” | HKLM\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters\RequireSecuritySignature | Server requires signing |
| “Microsoft network client: Digitally sign communications (if server agrees)” | ...\LanmanWorkstation\Parameters\EnableSecuritySignature | Ignored (SMB1 only) |
| “Microsoft network server: Digitally sign communications (if client agrees)” | ...\LanManServer\Parameters\EnableSecuritySignature | Ignored (SMB1 only) |
Microsoft documents that EnableSecuritySignature is ignored for SMB 2 and later. A connection is signed if either side requires it: client required and server not, or the reverse, both result in signing. Only when both sides have RequireSecuritySignature = 0 is the session unsigned.
Steps
- Create a GPO such as SEC – SMB Hardening and link it to the pilot OU (both workstations and member servers).
- Go to
Computer Configuration » Policies » Windows Settings » Security Settings » Local Policies » Security Options. - Set “Microsoft network client: Digitally sign communications (always)” to Enabled.
- Set “Microsoft network server: Digitally sign communications (always)” to Enabled.
- Run
gpupdate /forceon a test machine and open a share on each type of storage in your list. New sessions use the new setting; reconnect existing mapped drives or sign out and in.
Performance impact on current hardware is small. Windows 11 and Windows Server 2022 and later use AES-128-GMAC signing with SMB 3.1.1, which is much faster than the older signing algorithms.
Method 2: PowerShell and registry
Set-SmbClientConfiguration -RequireSecuritySignature $true -Force
Set-SmbServerConfiguration -RequireSecuritySignature $true -Force
Get-SmbClientConfiguration | Format-List RequireSecuritySignature, EnableInsecureGuestLogons
Get-SmbServerConfiguration | Format-List RequireSecuritySignature, EnableSMB1Protocol
The equivalent registry change, for example in a build image:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v RequireSecuritySignature /t REG_DWORD /d 1 /f
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters" /v RequireSecuritySignature /t REG_DWORD /d 1 /f
On domain members, prefer the GPO: an SMB signing Group Policy setting overwrites the local value on each refresh anyway.
NAS, Samba and other third-party storage
Microsoft notes that non-Microsoft file servers may not work with required signing and that you may need to relax the requirement for them. In practice:
- Linux Samba. Current Samba versions support signing for SMB 2 and 3. Check that
server signinginsmb.confis not set todisabled;autoormandatoryboth work with Windows clients that require signing. - NAS devices. Update the firmware first. Many NAS web consoles have an SMB signing or “SMB security” option; enable it and set the minimum protocol to SMB 2 or later.
- Scanners and copiers that save to a Windows share act as SMB clients. If they cannot sign, they fail against a server that requires signing. Update firmware, switch them to scan-to-email or SFTP, or keep one file server without the server-side requirement.
- Guest shares. Guest sessions cannot be signed. A share that only works as a guest stops working when signing is required (see the next section).
If a device cannot be fixed, do not remove the SMB signing Group Policy setting for the whole domain. Use a narrow exception, described below.
Guest access and AllowInsecureGuestAuth
Windows 11 24H2 and Windows Server 2025 block insecure guest logons by default, and required signing blocks them as well, because guest sessions cannot be signed. Users see a message that security policies block unauthenticated guest access. The policy is Computer Configuration » Policies » Administrative Templates » Network » Lanman Workstation » "Enable insecure guest logons", stored as AllowInsecureGuestAuth under HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanWorkstation.
The right fix is a user account on the NAS and saved credentials on the client (cmdkey or a mapped drive with credentials). Re-enabling guest access means turning on insecure guest logons and removing the client signing requirement, which exposes users to spoofed servers. If you must, limit it to the few machines that need it with a filtered GPO. The client logs guest logon events in Microsoft » Windows » SMBClient » Security: 31017 (guest logon rejected), 31018 (insecure guest auth enabled warning) and 31022 (guest logon allowed).
Disable SMBv1
SMBv1 is not installed by default on Windows 11 or on Windows Server 2019 and later, but upgraded machines and old images may still have it. Audit first, then remove it.
Way 1: Audit and turn off the SMBv1 server
Set-SmbServerConfiguration -AuditSmb1Access $true -Force
Get-WinEvent -LogName 'Microsoft-Windows-SMBServer/Audit' -MaxEvents 50 | Where-Object Id -eq 3000
Get-SmbServerConfiguration | Select-Object EnableSMB1Protocol
Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force
Event 3000 records each SMBv1 client that connects, with its address. Leave auditing on for a few weeks on file servers and domain controllers before you disable anything.
Way 2: Remove the feature
Get-WindowsOptionalFeature -Online -FeatureName SMB1Protocol
Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol -NoRestart
Uninstall-WindowsFeature -Name FS-SMB1
The first two lines are for Windows 10 and 11; Uninstall-WindowsFeature is for Windows Server. Both need a restart. Removing the feature is the cleanest option because it removes the SMBv1 client and server components together. Run it with a startup script or your deployment tool.
Way 3: Registry value through Group Policy Preferences
For servers where you cannot remove the feature yet, create a GPP registry item under Computer Configuration » Preferences » Windows Settings » Registry: action Update, key HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters, value SMB1, type REG_DWORD, data 0. Restart to apply. Before you link it to domain controllers, use a WMI filter to leave out any legacy system that still reads SYSVOL over SMBv1.
Optional: SMB encryption
Signing protects integrity; encryption also hides the data. It needs SMB 3.0 or later on both sides. Enable it on shares that hold sensitive data, or on the whole server:
Set-SmbShare -Name Finance -EncryptData $true -Force
Set-SmbServerConfiguration -EncryptData $true -Force
Get-SmbServerConfiguration | Select-Object EncryptData, RejectUnencryptedAccess
Leave RejectUnencryptedAccess at its default of $true, so clients that cannot encrypt are refused rather than silently served in clear text. Expect a noticeable CPU cost on busy servers without AES hardware acceleration.
Exceptions and targeting
- Exception GPO. Create SEC – SMB Signing Exception that sets the client policy to Disabled, link it above the main GPO (or give it a higher link order) and filter it to a group such as SMB-Legacy-Clients. See GPO security filtering.
- Server exception. If a copier must write to one file server, disable only the server policy on that server, not the client policy everywhere.
- Precedence. Security Options follow normal GPO precedence; see Group Policy processing order.
- Retire the exception. Record the device, owner and planned replacement date for every exception.
Rollout plan
- Week 1: inventory and audit. Turn on SMBv1 auditing on file servers and DCs, and list every non-Windows SMB device. Check which Windows 11 machines already run 24H2 or 25H2; they are already signing, so problems you see there tell you which storage will break.
- Week 2: pilot. Link the SMB signing Group Policy object to the pilot OU. Test every NAS, scanner and Linux share from a pilot machine, and every Windows file server from a copier or Linux client.
- Week 3: servers. Link it to member servers. Watch for devices that write to shares (scanners, backup appliances) and fix or except them.
- Week 4: workstations. Link it to all workstation OUs. Keep the exception GPO small and documented.
- Afterwards: SMBv1. Once event 3000 stays empty for a few weeks, disable and remove SMBv1.
For Intune-managed devices, the same two settings are in the Settings catalog under Local Policies Security Options. Configure them in one tool only.
Verify it works
- Confirm the policy applied with
gpresult /h C:\Temp\gp.htmland look under Security Options. - Check the effective configuration:
Get-SmbClientConfiguration | Select-Object RequireSecuritySignature, EnableInsecureGuestLogons
Get-SmbServerConfiguration | Select-Object RequireSecuritySignature, EnableSMB1Protocol, EncryptData - Open a share, then list the live connections and check the
Signedcolumn:Get-SmbConnection | Select-Object ServerName, ShareName, Dialect, Signed, Encrypted - On file servers, confirm no SMBv1 clients appear in event 3000 after the change.
Repeat the connection check against each NAS model in your list; that is where an SMB signing Group Policy rollout usually fails.
Troubleshooting
Most SMB signing Group Policy problems come from storage that cannot sign or from shares that rely on guest access.
| Symptom | Likely cause | Fix |
|---|---|---|
| NAS share fails after 24H2 upgrade | NAS does not sign, or share uses guest access | Update firmware, enable signing on the NAS, use an account |
| “Security policies block unauthenticated guest access” | Insecure guest logons blocked | Create a NAS account; avoid re-enabling guest access |
| Scanner cannot save to share | Device cannot sign; server requires it | Firmware update, or exception on one server |
| Setting reverts after a manual change | GPO reapplies Security Options | Change the GPO or add a filtered exception |
| Old system cannot reach SYSVOL | Uses SMBv1 or cannot sign | Upgrade or isolate it; check event 3000 |
| Slow copies after enabling encryption | CPU cost of encryption | Limit encryption to sensitive shares |
| GPO not applied at all | Link, filtering or replication | See Group Policy not applying |
Roll back or undo
- Set the two (always) policies to Disabled if you need signing off. Setting them to Not Configured does not turn signing off: Security Options values stay as last applied, and on Windows 11 24H2 and Server 2025 the built-in default requires signing anyway. Run
gpupdate /forceand reconnect shares. - To return SMBv1 temporarily on a server, run
Set-SmbServerConfiguration -EnableSMB1Protocol $true(if the feature is still installed) or reinstall the feature, and plan to remove it again. - Remove GPP registry items by setting their action to Delete and letting them apply once before you unlink the GPO.
- Turn off share encryption with
Set-SmbShare -Name Finance -EncryptData $false.
Keep the SMB signing Group Policy object in place for everything that works, and treat every exception as temporary.
SMB signing Group Policy at a glance

Official documentation: Control SMB signing behavior, Enable insecure guest logons in SMB2 and SMB3, Detect, enable and disable SMBv1, SMBv2 and SMBv3.
Related guides: Audit and disable NTLM in Active Directory · File server share vs NTFS permissions and ABE · Map Network Drives Group Policy: 2026 Item-Level Targeting Made Easy.
Frequently asked questions
Is SMB signing required by default in Windows 11 24H2?
Yes for Enterprise, Pro and Education: Windows 11 24H2 requires outbound and inbound SMB signing by default. Windows 11 24H2 Home does not require it, and Windows Server 2025 requires outbound signing only, apart from domain controllers.
Which Group Policy settings enable SMB signing?
“Microsoft network client: Digitally sign communications (always)” and “Microsoft network server: Digitally sign communications (always)” in Security Options. The “if server agrees” and “if client agrees” settings only affect SMB1.
Why can’t Windows 11 24H2 open my NAS share any more?
Usually the NAS does not support signing or the share relies on guest access, which 24H2 blocks and which cannot be signed. Update the NAS firmware, enable SMB signing on it and use a named account instead of guest.
How do I find computers still using SMBv1?
Run Set-SmbServerConfiguration -AuditSmb1Access $true on file servers and domain controllers, then check event 3000 in the Microsoft-Windows-SMBServer/Audit log, which records each SMBv1 client.
Does SMB signing slow down file transfers?
The impact on current hardware is small. Windows 11 and Windows Server 2022 and later use AES-128-GMAC signing with SMB 3.1.1, which is much faster than older signing algorithms.