18.6.8.6 (L1) Ensure 'Mandate the minimum version of SMB' is set to 'Enabled: 3.1.1'

Information

This policy settings controls the minimum version of Server Message Block (SMB) protocol that can be used on the system.

The recommended state for this setting is: Enabled: 3.1.1

Note: This group policy setting does not prevent the use of SMBv1 if it is installed and enabled on the system. If the following recommendations are configured as prescribed in this benchmark, SMBv1 will be disabled on the system:

Configure SMB v1 client driver

and

Configure SMB v1 server

.

The newer, more modern version of SMB (v3) is supported and available on all currently supported Microsoft Windows OSes. SMBv1 is no longer enabled by default due to its security risks, and although SMBv2 is more robust than v1, it does not support encryption like its successor.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: 3.1.1 :

Computer Configuration\Policies\Administrative Templates\Network\Lanman Workstation\Mandate the minimum version of SMB

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template LanmanWorkstation.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

If older legacy (unsupported) Windows OSes that do not support SMB v3.1.1 are present in the environment, this setting may affect backward compatibility with them. For example, Windows 8.1 and Windows Server 2012 R2 and older. This setting may also affect connecting to third-party devices and appliances that do not support SMB v3.1.1.

See Also

https://workbench.cisecurity.org/benchmarks/21318

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 3ac5d93003078022f830c4fc4e2b9f077b2c03b2487be6f9c9ccb2e6b4461981