Active Directory SMB signing not enforced on domain controller

High
Active Directory
Credential Access Lateral Movement Privilege Escalation
v15

Signature Identity

Threat ID
15
Version
IOE
Indicator Type

Threat Description

SMB signing helps protect SMB traffic from tampering and relay-style abuse. When SMB signing is not required through Group Policy, a threat actor may exploit this vulnerability to use man-in-the-middle, relay, or reflection techniques against SMB-based systems, especially domain controllers and other critical infrastructure. Recent public research and vulnerability disclosures, including CVE-2025-33073, show that a weak SMB signing posture can increase exposure to modern SMB abuse. Requiring SMB signing through Group Policy is an effective mitigation because it applies the control consistently and reduces the risk of configuration drift on critical systems.

MITRE ATT&CK: Attack Tactics

Credential Access Lateral Movement Privilege Escalation

D3FEND: Defend Tactics

Credential Hardening

Remediation

  1. Open Group Policy Management (gpmc.msc).
  2. Create or edit a GPO that applies to the Domain Controllers OU.
  3. Go to Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options.
  4. Enable Microsoft network client: Digitally sign communications (always).
  5. Enable Microsoft network server: Digitally sign communications (always).
  6. Run gpupdate /force or wait for Group Policy to refresh.
  7. Verify that the settings are applied as intended.
  8. Apply the same policy to other Tier 0 assets and other critical systems that handle administrative, authentication, or sensitive file-sharing traffic.

Frequently Asked Questions

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Infrastructure Privileged Access Management
Attack Tactics
Credential Access Lateral Movement Privilege Escalation
Defend Tactics
Credential Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical