18.6.8.2 (L1) Ensure 'Audit server does not support encryption' is set to 'Enabled'

Information

This policy setting determines whether the Server Message Block (SMB) client will log events when the SMB server doesn't support encryption.

Enabling this will create event log entries in Applications and Services Logs\Microsoft\Windows\SMBServer\Audit with Event ID 3021

The recommended state for this setting is: Enabled

Organizations should be aware of all unencrypted SMB traffic in their environment. Older SMB protocols that do not use encryption can make an environment susceptible to many types of attacks, including SMB interception attacks.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Network\Lanman Workstation\Audit server does not support encryption

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template LanmanWorkstation.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

All SMB traffic that is unencrypted will be logged as an event.

See Also

https://workbench.cisecurity.org/benchmarks/21318