CTD-000200

Active Directory SMB signing not enforced on domain controller

High
Active Directory
Credential Access Lateral Movement Privilege Escalation
v15

Signature Identity

CTD-000200
Threat ID
15
Version
IOE
Indicator Type

Threat Description

SMB signing helps protect SMB traffic from tampering and relay-style abuse. When SMB signing is not required through Group Policy, a threat actor may exploit this vulnerability to use man-in-the-middle, relay, or reflection techniques against SMB-based systems, especially domain controllers and other critical infrastructure. Recent public research and vulnerability disclosures, including CVE-2025-33073, show that a weak SMB signing posture can increase exposure to modern SMB abuse. Requiring SMB signing through Group Policy is an effective mitigation because it applies the control consistently and reduces the risk of configuration drift on critical systems.

MITRE ATT&CK: Attack Tactics

Credential Access Lateral Movement Privilege Escalation

D3FEND: Defend Tactics

Credential Hardening

Remediation

  1. Open Group Policy Management (gpmc.msc).
  2. Create or edit a GPO that applies to the Domain Controllers OU.
  3. Go to Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options.
  4. Enable Microsoft network client: Digitally sign communications (always).
  5. Enable Microsoft network server: Digitally sign communications (always).
  6. Wait for Group Policy to refresh, or apply the GPO immediately by running the following command: gpupdate /force

    Important: Before validating the result, ensure that another policy is not overriding the configured GPO. If multiple GPOs are linked to the Domain Controllers OU or at the domain level, another GPO may configure the same NTLM settings and overwrite the expected values.
    Check the GPO link order, confirm that the GPO is enabled, and verify security filtering. To review the effective policy on the domain controller, run:

    gpresult /h C:Tempgpresult.html /scope computer /f
  7. Verify that the settings are applied as intended.
  8. Apply the same policy to other Tier 0 assets and other critical systems that handle administrative, authentication, or sensitive file-sharing traffic.

Frequently Asked Questions

What does Active Directory SMB signing not enforced on domain controller mean?

When the Group Policy setting requiring SMB signing is not applied to your domain controllers, it means that SMB traffic is not protected against tampering and relay-style attacks. This configuration weakness allows an attacker to exploit vulnerabilities in SMB-based systems.

Active Directory SMB signing not enforced on domain controller is rated high severity because it enables attackers to bypass authentication and access sensitive data, especially on critical infrastructure like domain controllers. This can lead to serious compromise of SMB traffic.

An attacker can exploit vulnerabilities in SMB-based systems to tamper with or relay SMB traffic, allowing them to bypass authentication and access sensitive data. This can be done through man-in-the-middle, relay, or reflection techniques.

Cayosoft Guardian continuously monitors the Group Policy settings across the Active Directory environment and detects when SMB signing is not required through Group Policy. This allows Guardian to flag this as a security issue so administrators can take corrective action.

Cayosoft Guardian alerts administrators to apply the Group Policy setting requiring SMB signing, ensuring that your domain controllers and other critical infrastructure are protected from tampering and relay-style attacks. This provides visibility into potential security issues and supports investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Infrastructure Privileged Access Management
Attack Tactics
Credential Access Lateral Movement Privilege Escalation
Defend Tactics
Credential Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical