Glossary
SMB signing
SMB signing adds a cryptographic signature to every SMB message so tampering and NTLM relay against file and admin shares are detected and rejected.
SMB signing attaches a message authentication code, derived from the session key established at authentication, to each SMB packet. The receiving side verifies it and drops any message that has been altered or that comes from a session the relaying party cannot sign. Signing can be "enabled" (used if both sides agree) or "required" (connections without signing are refused); only "required" provides protection. Domain controllers have required it for years; Windows 11 24H2 now requires it by default for both outbound and inbound connections, and Windows Server 2025 requires it for all outbound connections.
It matters because NTLM relay to SMB is a classic path to remote code execution: an attacker captures authentication from one host and replays it to another where the victim is a local administrator. When signing is required, the attacker cannot produce valid signatures and the relay fails. Require signing through Group Policy on all clients and servers, disable SMBv1 entirely, and verify third-party NAS and appliances support it. The performance cost on modern hardware is small.
See Requiring SMB signing across the domain and Stop NTLM relay.