45.2 Ensure 'Audit Client Does Not Support Signing' is set to 'Enabled'

Information

This policy setting determines whether the Server Message Block (SMB) server will log events when the SMB client doesn't support signing.

Enabling this will create event log entries in Applications and Services Logs\Microsoft\Windows\SMBClient\Audit, with Event ID 31999.

The recommended state for this setting is: Enabled.

Organizations should be aware of all unsigned SMB traffic in their environment. Older SMB protocols that do not use signing can make an environment susceptible to many types of attacks, including SMB interception attacks.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled :

Lanman Server\Audit Client Does Not Support Signing

Impact:

All SMB traffic that is unsigned will be logged as an event.

See Also

https://workbench.cisecurity.org/benchmarks/27282