AD-DC-02 - SMBv1 should be disabled on all domain controllers
Overviewβ
SMBv1 (Server Message Block version 1) is an outdated protocol with significant security vulnerabilities:
- EternalBlue exploit: Used in WannaCry and NotPetya ransomware attacks
- No encryption: SMBv1 traffic is not encrypted
- No integrity checks: Vulnerable to man-in-the-middle attacks
- Deprecated by Microsoft: Microsoft strongly recommends disabling SMBv1
Domain controllers with SMBv1 enabled pose a critical security risk as they are high-value targets for attackers.
Security Recommendationβ
Disable SMBv1 on all domain controllers immediately.
To disable SMBv1 on a domain controller:
#### Check current status
Get-SmbServerConfiguration | Select-Object EnableSMB1Protocol
#### Disable SMBv1
Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force
#### Disable SMBv1 feature (requires restart)
Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol
How the Test Worksβ
This test queries the SMB server configuration on each domain controller to check if SMBv1 protocol is enabled. It reports:
- Number of DCs with SMBv1 enabled
- Names of affected DCs
- Overall security status
Related Testsβ
Test-MtAdDcSmbSigningEnabledCount- SMB signing configurationTest-MtAdDcSmbv311EnabledCount- SMBv3.1.1 protocol status
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-DC-02 |
| Severity | Unknown |
| Suite | Active Directory |
| Category | AD.DomainController |
| PowerShell test | Test-MtAdDcSmbv1EnabledCount |
| Tags | AD, AD-DC-02, AD.DomainController |
Sourceβ
- Pester test:
tests/ad/domaincontroller/Test-MtAdDcSmbv1EnabledCount.Tests.ps1 - PowerShell source:
powershell/public/ad/domaincontroller/Test-MtAdDcSmbv1EnabledCount.ps1

