Digitally sign communications

Glenn Maxwell 11,621 Reputation points
2024-09-21T17:30:47.9933333+00:00

The policy below is currently disabled in our environment. I have a request from our security team to enable this policy.Could there be any issues with SMB, given that I have DFS shares and file servers? Additionally, I have Windows shares mounted on Linux VMs

Computer Configuration--Policies--Windows Settings--Security Settings--Local Policies--Security Options--Microsoft network client: Digitally sign communications (always)

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,809 questions
Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,529 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,289 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,678 questions
Windows Server Infrastructure
Windows Server Infrastructure
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Infrastructure: A Microsoft solution area focused on providing organizations with a cloud solution that supports their real-world needs and meets evolving regulatory requirements.
553 questions
0 comments No comments
{count} votes

Accepted answer
  1. Yanhong Liu 12,735 Reputation points Microsoft Vendor
    2024-09-23T08:18:51.47+00:00

    Hello,

    Enabling the policy "Microsoft network client: Digitally sign communications (always)" will require all SMB communications to be digitally signed. This enhances the security of file transfers between clients and servers but can also have implications on the performance and compatibility of your network.

    Here are a few things to consider:

    1.Performance Impact: Enabling digital signatures on SMB communications can introduce a performance overhead. This is because each packet needs to be signed and verified, which can slow down data transfer rates, especially on busy networks.

    2.Compatibility with DFS and File Servers: If your file servers and DFS (Distributed File System) shares support SMB signing, they should be compatible with this policy. However, it's crucial to test this in a controlled environment before rolling it out network-wide to ensure that there are no unforeseen issues.

    3.Linux Compatibility: For Windows shares mounted on Linux VMs, the compatibility will depend on the SMB client that the Linux system is using. Modern SMB clients like smbclient from the Samba suite support SMB signing. Ensure that your Linux systems are configured correctly to handle SMB signing. You may need to update your Samba configuration (smb.conf) to enable signing.

    4.Legacy Systems: If you have any older systems or devices that do not support SMB signing, they will not be able to communicate with the servers once this policy is enabled. This could potentially disrupt services or connections for those devices.

    It is recommended that you thoroughly test this policy in a controlled environment to observe any performance impact or compatibility issues before enabling it across your entire environment.

    For more information, see: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/microsoft-network-client-digitally-sign-communications-always

    I hope the information above is helpful.

    Best Regards,

    Yanhong Liu

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.