Skip to content

Windows Security Baseline & Protocol Hardening

Legacy protocols and fallback name-resolution services can increase exposure, but their state varies by Windows release and organization policy. Clean installations of current Windows 11 and Windows Server 2019 or later do not include SMBv1 by default. Inventory the effective settings and check application dependencies before disabling LLMNR or NetBIOS across a fleet.

Step 1: Disable Insecure Legacy SMBv1

01

Disable SMBv1 Protocol & Deprecated Driver

File Sharing

Check whether the SMBv1 optional feature and SMB server component are present and enabled. Disable only an enabled feature; the optional-feature change may require a restart. Test legacy file-sharing dependencies before removing it.

Terminal window
# Check the SMB server component and optional-feature state first
Get-SmbServerConfiguration | Select-Object EnableSMB1Protocol
$Smb1Feature = Get-WindowsOptionalFeature -Online -FeatureName 'SMB1Protocol'
$Smb1Feature | Select-Object FeatureName, State
# Disable SMB1 on the server component only if it is enabled
if ((Get-SmbServerConfiguration).EnableSMB1Protocol) {
Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force
}
# Remove the optional feature only if it is enabled; schedule any required restart
if ($Smb1Feature.State -eq 'Enabled') {
Disable-WindowsOptionalFeature -Online -FeatureName 'SMB1Protocol' -NoRestart
} else {
Write-Host 'The SMB1 optional feature is not enabled.'
}
❯ View Expected Console Output

Review the returned State and RestartNeeded values. If RestartNeeded is True, restart during the approved maintenance window before considering the change complete.

Windows Features dialog showing SMB 1.0/CIFS File Sharing Support unchecked

Figure 1: Windows Features with SMB 1.0/CIFS File Sharing Support disabled.

02

Block LLMNR via Local Group Policy Registry

Name Resolution

When DNS resolution fails, Windows may use LLMNR multicast queries over UDP 5355. Disable this policy only after checking legacy name-resolution dependencies. A domain Group Policy can override a local registry setting.

Terminal window
# Create DNSClient policy key if missing and disable LLMNR
$regPath = "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient"
if (-not (Test-Path $regPath)) {
New-Item -Path $regPath -Force | Out-Null
}
Set-ItemProperty -Path $regPath -Name "EnableMulticast" -Value 0 -Type DWord
❯ View Expected Console Output

(EnableMulticast policy value set to 0. Verify the effective policy and client behavior; a domain policy may overwrite the local value.)

Local Group Policy Editor showing Turn off multicast name resolution enabled

Figure 2: Local Group Policy Editor with the DNS Client policy to turn off multicast name resolution enabled.

Step 3: Disable NetBIOS over TCP/IP (NBT-NS)

03

Deactivate NetBIOS on All Active Network Adapters

Network Protocol

Similar to LLMNR, NetBIOS Name Service (NBT-NS) uses UDP 137. Review the active adapters and dependencies before disabling it on physical or virtual interfaces:

Terminal window
# Set NetBIOS options to 2 (Disabled) on active IPv4 interfaces.
# Review every listed adapter and confirm legacy applications do not depend on NetBIOS.
$adapters = @(Get-CimInstance -ClassName Win32_NetworkAdapterConfiguration |
Where-Object { $_.IPEnabled -eq $true })
$adapters | Select-Object Description, TcpipNetbiosOptions | Format-Table -AutoSize
if ($adapters.Count -eq 0) {
throw 'No active IPv4 adapters were found.'
}
if ((Read-Host 'Type DISABLE only after reviewing every active adapter') -cne 'DISABLE') {
throw 'NetBIOS changes cancelled.'
}
foreach ($adapter in $adapters) {
Invoke-CimMethod -InputObject $adapter -MethodName SetTcpipNetbios -Arguments @{ TcpipNetbiosOptions = 2 } |
Select-Object @{Name='Adapter'; Expression={$adapter.Description}}, ReturnValue
}
# Confirm the configured value: 2 means NetBIOS is disabled.
Get-CimInstance -ClassName Win32_NetworkAdapterConfiguration |
Where-Object { $_.IPEnabled -eq $true } |
Select-Object Description, TcpipNetbiosOptions
❯ View Expected Console Output

Adapter ReturnValue


Intel(R) Ethernet Controller I225-V 0 vEthernet (WSL) 0

Description TcpipNetbiosOptions


Intel(R) Ethernet Controller I225-V 2 vEthernet (WSL) 2

Step 4: Set a Script Policy and Enable Script Block Logging

04

Harden PowerShell Engine & Enable Audit Trails

PowerShell

Set the local machine execution policy to RemoteSigned and enable Script Block Logging (Event ID 4104). Group Policy can override the local execution policy. Script Block Logging is useful for investigation, but event records can contain sensitive command content; configure access and retention accordingly.

Terminal window
# 1. Set the local machine execution policy
Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope LocalMachine -Force
# 2. Enable PowerShell Script Block Logging in Group Policy registry
$psLogPath = "HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging"
if (-not (Test-Path $psLogPath)) {
New-Item -Path $psLogPath -Force | Out-Null
}
Set-ItemProperty -Path $psLogPath -Name "EnableScriptBlockLogging" -Value 1 -Type DWord
❯ View Expected Console Output

(Local execution policy set to RemoteSigned. Script Block Logging enabled).

Local Group Policy Editor showing PowerShell Script Block Logging enabled

Figure 3: Local Group Policy Editor with PowerShell Script Block Logging enabled.

Comments