GPO policy: "Mandate the minimum version of SMB" under Computer Configuration > Administrative Templates > Network > Lanman Server. Controls the minimum SMB dialect the LanmanServer service will accept from clients. Raising the minimum dialect blocks older, less-secure SMB versions. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\LanmanServer:MinSmb2Dialect (REG_DWORD). Note: this policy does not prevent SMB 1 if that component is still installed and enabled separately. Reference: Detect, enable and disable SMBv1, SMBv2, and SMBv3
Values
| Enum Value | Description |
|---|---|
|
|
SMB 2.0.2 minimum (registry value 514 / 0x202). Lowest dialect; allows all SMB2+ clients. |
|
|
SMB 2.1.0 minimum (registry value 528 / 0x210). Blocks SMB 2.0.2-only clients. |
|
|
SMB 3.0.0 minimum (registry value 768 / 0x300). Requires SMB3 support (adds encryption capability). |
|
|
SMB 3.0.2 minimum (registry value 770 / 0x302). Requires SMB 3.0.2+. |
|
|
SMB 3.1.1 minimum (registry value 785 / 0x311). Most secure; requires the latest SMB3 dialect. |
|
|
No specific minimum SMB version enforced by policy. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"SMB_2_0_2"