Troubleshooting: Does SecureAuth IdP Require SMB to Be Enabled on the Appliance?

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    The Server Message Block (SMB) protocol is the network protocol Microsoft Windows uses to let computers share files and printers over a network. This article explains whether the SecureAuth Identity Provider (IdP) requires SMB to be enabled on the appliance.
     
     

    Cause

    The SecureAuth IdP itself does not share files over the network and does not require SMB to be enabled on the server. Administrators may still use network connections to copy files to and from the IdP server, but doing so does not require SMB specifically.
     
     

    Resolution

    It is safe to disable the SMB protocol on a SecureAuth IdP appliance using Group Policy, a Registry configuration change, or the steps in the Microsoft article linked below. The one case where SMB is required on an IdP appliance is when the SecureAuth FileSync service is used to replicate configuration between SecureAuth appliances — FileSync depends on SMB to share those configuration files.


     

    Special Considerations

    SMB has multiple protocol versions. SMBv1 is legacy and known to be insecure, so Microsoft recommends disabling it specifically — see Microsoft's Stop Using SMB1 article — even on servers where later SMB versions remain enabled. Microsoft's Detect, enable, and disable SMBv1, SMBv2, and SMBv3 article covers how to check which versions are active and disable the ones that are not needed. Microsoft also maintains a list of known applications that still require SMBv1, in case a third-party dependency on the server needs it kept enabled: see the SMB1 Product Clearinghouse.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.