18.3.2 Ensure 'Configure SMB v1 client' is set to 'Enabled: Bowser, MRxSmb20, NSI'

Information

This setting configures the dependencies for the Lanman Workstation service - since disabling the Server Message Block version 1 (SMBv1) protocol is recommended, therefore the MRxSmb10 dependency, which is used only by SMBv1, should no longer be configured.

The recommended state for this setting is: Enabled: Bowser, MRxSmb20, NSI.

Note: Do not, under any circumstances, configure this setting as Disabled, as doing so will delete the underlying registry entry altogether, which will cause serious problems.

Rationale:

Since September 2016, Microsoft has strongly encouraged that SMBv1 be disabled and no longer used on modern networks, as it is a 30 year old design that is much more vulnerable to attacks then much newer designs such as SMBv2 and SMBv3.

More information on this can be found at the following links:

Stop using SMB1 | Storage at Microsoft

Disable SMB v1 in Managed Environments with Group Policy - 'Stay Safe' Cyber Security Blog

Disabling SMBv1 through Group Policy - Microsoft Security Guidance blog

Impact:

Some legacy OSes (e.g. Windows XP, Server 2003 or older), applications and appliances may no longer be able to communicate with the system once SMBv1 is disabled. We recommend careful testing be performed to determine the impact prior to configuring this as a widespread control, where possible, remediate any incompatibilities found. Microsoft is also maintaining a thorough (although not comprehensive) list of known SMBv1 incompatibilities at this link: SMB1 Product Clearinghouse | Storage at Microsoft

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Bowser, MRxSmb20, NSI:

Computer Configuration\Policies\Administrative Templates\MS Security Guide\Configure SMB v1 client

Note: This Group Policy path does not exist by default. An additional Group Policy template (SecGuide.admx/adml) is required - it is available from Microsoft at this link.

Default Value:

Windows Server 2012 (non-R2) and older: Enabled: Bowser, MRxSmb10, MRxSmb20, NSI

Windows Server 2012 R2 and newer: Enabled: Bowser, MRxSmb20, NSI

See Also

https://workbench.cisecurity.org/files/4022