The following video demonstrates how to:
●● Disable SMB 1.0.
●● Configure SMB encryption.
The main steps in the process are:
1. Create AD DS environment. Create a single-domain AD DS forest with a domain member configured as a file server.
2. Enable SMB 1.0 on the member server. Explicitly enable SMB 1.0 by using the Enable-WindowsOptionalFeatureWindows PowerShell cmdlet.
3. Detect whether SMB 1.0 is enabled. Enable auditing of SMB 1.0 connections.
4. Audit the use of SMB 1.0. Use the command-line tools to transfer the operations master roles back to the first domain controller.
5. Disable SMB 1.0. Disable SMB 1.0 by using the Disable -WindowsOptionalFeature Windows PowerShell cmdlet.
6. Configure SMB encryption. Enforce the use of SMB encryption.
Ещё видео!