Skip to main content
Version: 2.2.1-preview

AD-DC-03 - SMBv3.1.1 enabled count should be retrievable

Overviewโ€‹

SMBv3.1.1 is the latest version of the Server Message Block protocol and includes important security enhancements:

  • Pre-authentication integrity: Prevents man-in-the-middle attacks
  • AES-128-GCM encryption: Stronger encryption for SMB traffic
  • Secure dialect negotiation: Prevents downgrade attacks
  • Required for Windows 11: Modern Windows versions prefer SMBv3.1.1

Having SMBv3.1.1 enabled ensures your domain controllers can support the most secure SMB communications.

Security Recommendationโ€‹

Enable SMBv3.1.1 on all domain controllers running Windows Server 2016 or later to ensure maximum SMB security.

To verify SMBv3.1.1 status:

Get-SmbServerConfiguration | Select-Object EnableSMB3_1_1Protocol

How the Test Worksโ€‹

This test queries the SMB server configuration on each domain controller to check if SMBv3.1.1 protocol is enabled. It reports the count and names of DCs with this protocol enabled.

  • Test-MtAdDcSmbv1EnabledCount - SMBv1 protocol status (should be disabled)
  • Test-MtAdDcSmbSigningEnabledCount - SMB signing configuration

Test Metadataโ€‹

FieldValue
Test IDAD-DC-03
SeverityInfo
SuiteActive Directory
CategoryAD.DomainController
PowerShell testTest-MtAdDcSmbv311EnabledCount
TagsAD, AD-DC-03, AD.DomainController

Sourceโ€‹

  • Pester test: tests/ad/domaincontroller/Test-MtAdDcSmbv311EnabledCount.Tests.ps1
  • PowerShell source: powershell/public/ad/domaincontroller/Test-MtAdDcSmbv311EnabledCount.ps1