Windows OS Hub
  • Windows
    • Windows 11
    • Windows 10
    • Windows Server 2025
    • Windows Server 2022
    • Windows Server 2019
    • Windows Server 2016
  • Microsoft
    • Active Directory (AD DS)
    • Group Policies (GPOs)
    • Exchange Server
    • Azure and Microsoft 365
    • Microsoft Office
  • Virtualization
    • VMware
    • Hyper-V
    • Proxmox
  • PowerShell
  • Linux
  • Home
  • About

Windows OS Hub

  • Windows
    • Windows 11
    • Windows 10
    • Windows Server 2025
    • Windows Server 2022
    • Windows Server 2019
    • Windows Server 2016
  • Microsoft
    • Active Directory (AD DS)
    • Group Policies (GPOs)
    • Exchange Server
    • Azure and Microsoft 365
    • Microsoft Office
  • Virtualization
    • VMware
    • Hyper-V
    • Proxmox
  • PowerShell
  • Linux

 Windows OS Hub / Windows 11 / Can’t Access Shared Folders on NAS in Windows 11 24H2

July 17, 2024

Can’t Access Shared Folders on NAS in Windows 11 24H2

Microsoft recently announced that mandatory SMB packet signing for access to shared network folders will be enabled by default in Windows 11 24H2. This may cause problems when accessing shared folders on NAS (Network Attached Storage) devices where SMB signing is not supported or disabled by default.

SMB Signing is one of the security features of the SMB/CIFS file-sharing protocol. If this option is enabled, a digital signature will be added to the header of each SMB message. This signature makes it possible to ensure that the content of the message has not been changed and provides authentication by verifying the identity of the server and client. This helps prevent SMB man-in-the-middle and NTLM relay attacks. Previously, SMB signing was only required to access SYSVOL and NETLOGON shares on AD domain controllers.

SMB signing is required for all outbound SMB connections starting with Windows 11 24H2 (Accessing a third-party NAS with SMB in Windows 11 24H2 may fail). If the SMB server doesn’t support this mode, the Windows client will reject the connection. Other supported versions of Windows will later receive this change.

Important! Implementing mandatory SMB signing will result in additional RAM and CPU usage on both the client and server. It also reduces the speed of file transfers over the network.

If the remote device does not support SMB signing, errors will occur when accessing a shared folder on that device:

  •  0xc000a000
  •  -1073700864
  •  STATUS_INVALID_SIGNATURE
  •  The cryptographic signature is invalid

The default Windows (and Samba) SMB server settings assume that SMB packet signing is only used when requested by one of the parties. Use PowerShell to list the current SMB signing settings on a Windows client:

Get-SmbClientconfiguration | fl EnableSecuritySignature,RequireSecuritySignature

Get-SmbClientconfiguration check if SMB signing is enabled

  • RequireSecuritySignature = False — mandatory use of the SMB signature is not enabled.
  • EnableSecuritySignature = True – the client only uses SMB signing when required by the server.

To disable (or enable) mandatory SMB signing, use the command

Set-SmbClientConfiguration -RequireSecuritySignature $false

Restart the computer after changing the settings.

In the same way, you can enable or disable SMB signing on the server side (host with shared folders):

Get-SmbServerConfiguration | fl *sign*
Set-SmbServerConfiguration -RequireSecuritySignature $true (or $false )

The EnableSecuritySignature option value is ignored if the legacy SMB1 protocol is disabled (this is the default behavior in Windows).

These SMB client and server options can be enabled via the registry. The next set of commands will turn off the mandatory use of SMB signing for both the client and the server:
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters" /v RequireSecuritySignature /t REG_DWORD /d 0 /f
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters" /v EnableSecuritySignature /t REG_DWORD /d 1 /f
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v RequireSecuritySignature /t REG_DWORD /d 0 /f
reg add "HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters" /v EnableSecuritySignature /t REG_DWORD /d 1 /f

The GPO editor can also be used to configure the SMB signing mode for a Windows client. The following options are available in the local Group Policy Editor (gpedit.msc) under Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options

  • Microsoft network client: Digitally sign communication (always)
  • Microsoft network client: Digitally sign communication (if server agrees)

GPO: Microsoft network client: Digitally sign SMB communication

Some NAS models and firmware versions support the SMB signing mode, but it is not enabled by default (for example in Synology, ASUStor, QNAP, and some other devices). For example, in Synology DSM 7+, this option can be found in the Control Panel -> File Services -> SMB -> Advanced Settings. Find the option Enable server signing. Signing is disabled by default. To enable SMB signing when requested by the client, select Client defined from the drop-down menu.

Synology DSM NAS - enable SMB signing

Thus, if you experience problems when accessing NAS shares after upgrading to Windows 11 24H2, you will need to:

  • Enable SMB signing on the NAS device (recommended way)
  • Disable mandatory SMB signing on the Windows client (less secure option)
0 comment
2
Facebook Twitter Google + Pinterest
Windows 11
previous post
Fix: Multiple Connections to a Server or Shared Resources by the Same User
next post
Prevent Users from Changing Their Passwords in Windows

Related Reading

Managing Windows Firewall Rules with PowerShell

March 11, 2024

Create a Custom Windows Image with Pre-installed Apps

February 28, 2024

Fixing ‘The Network Path Was Not Found’ 0x80070035...

August 31, 2023

Upgrading to Windows 11 on Unsupported Hardware

March 6, 2024

Configuring RemoteApps Hosted on Windows 10/11 (without Windows...

January 25, 2025

How to Assign (Passthrough) a Physical GPU to...

June 11, 2024

Installing Language Pack in Windows 10/11 with PowerShell

September 20, 2023

Fix: Your IT Administrator Has Limited Access to...

March 22, 2024

Leave a Comment Cancel Reply

join us telegram channel https://t.me/woshub
Join WindowsHub Telegram channel to get the latest updates!

Recent Posts

  • How to Delete a Windows Service via CMD or PowerShell

    October 16, 2025
  • Resource Fair Sharing in Windows Server Remote Desktop Services (RDS)

    October 6, 2025
  • How to Disable (Enable) Credential Guard in Windows 11

    October 6, 2025
  • Wrong Network Profile on Windows Server after Reboot

    September 30, 2025
  • How to Get Windows 10 Extended Security Updates After End-Of-Life

    September 24, 2025
  • Blocking NTLM Connections on Windows 11 and Windows Server 2025

    September 23, 2025
  • Windows Stucks at ‘Getting Windows Ready, Don’t Turn Off Computer’

    September 15, 2025
  • Clean Up ETL Log Files in ProgramData

    September 9, 2025
  • Fix: Slow Startup of PowerShell Console and Scripts

    September 3, 2025
  • DPI Scaling and Font Size in RDP (RDS) Session

    August 27, 2025

Follow us

  • Facebook
  • Twitter
  • Telegram
Popular Posts
  • How to Allow Multiple RDP Sessions on Windows 10 and 11
  • How to Run Program without Admin Privileges and Bypass UAC Prompt
  • Fixing ‘The Network Path Was Not Found’ 0x80070035 Error Code on Windows
  • How to Delete Old User Profiles in Windows
  • How to Install Remote Server Administration Tools (RSAT) on Windows
  • How to Backup and Copy Local Group Policy Settings to Another Computer
  • How to Fix ‘An Operating System Wasn’t Found’ Error on Windows
Footer Logo

@2014 - 2024 - Windows OS Hub. All about operating systems for sysadmins


Back To Top