Configure SMB v1 client driver

Information

Configures the SMB v1 client driver's start type.
To disable client-side processing of the SMBv1 protocol, select the 'Enabled' radio button, then select 'Disable driver' from the dropdown.
WARNING: DO NOT SELECT THE 'DISABLED' RADIO BUTTON UNDER ANY CIRCUMSTANCES!
For Windows 7 and Servers 2008, 2008R2, and 2012, you must also configure the 'Configure SMB v1 client (extra setting needed for pre-Win8.1/2012R2)' setting.
To restore default SMBv1 client-side behavior, select 'Enabled' and choose the correct default from the dropdown:
* 'Manual start' for Windows 7 and Windows Servers 2008, 2008R2, and 2012;
* 'Automatic start' for Windows 8.1 and Windows Server 2012R2 and newer.
Changes to this setting require a reboot to take effect.
For more information, see https://support.microsoft.com/kb/2696547

Solution

Policy Path: MS Security Guide
Policy Setting Name: Configure SMB v1 client driver

See Also

https://blogs.technet.microsoft.com/secguide/2019/05/23/security-baseline-final-for-windows-10-v1903-and-windows-server-v1903/

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Windows

Control ID: 5450031ed1ebfd0e29b0633c47d5a69df29325514fa8bd5ad187198e10e2acf8