Information
This policy settings controls the minimum version of Server Message Block (SMB) protocol that can be used on the system.
The recommended state for this setting is: 3.1.1.
Note: This group policy setting does not prevent the use of SMBv1 if it is installed and enabled on the system. If the following recommendations are configured as prescribed in this benchmark, SMBv1 will be disabled on the system: Configure SMB v1 client driver and Configure SMB v1 server.
The newer, more modern version of SMB (v3) is supported and available on all currently supported Microsoft Windows OSes. SMBv1 is no longer enabled by default due to its security risks, and although SMBv2 is more robust than v1, it does not support encryption like its successor.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to 3.1.1 :
Lanman Workstation\Min Smb2 Dialect
Impact:
If older legacy (unsupported) Windows OSes that do not support SMB v3.1.1 are present in the environment, this setting may affect backward compatibility with them. For example, Windows 8.1 and Windows Server 2012 R2 and older. This setting may also affect connecting to third-party devices and appliances that do not support SMB v3.1.1.