Microsoft recommends that admins disable the SMBv1 network communication protocol on Exchange servers to prevent malware attacks.
Microsoft encourages administrators to disable the SMBv1 protocol on Exchange servers as a mitigation against malware threats such as TrickBot and Emotet.
“To ensure your Exchange organization is better protected from the latest threats (for example the malware Emotet, TrickBot or WannaCry) we recommend disabling SMBv1 if it is enabled on your Exchange (2013/2016/2019) server”. advises Microsoft.
The SMBv1 protocol is a network communication protocol for providing shared access to files, printers, and serial ports between nodes on a network. It also provides an authenticated mechanism for inter-process communication.
Exchange highlights the need to disable the exchange servers SMBv1on.
“You do not need to run the nearly 30-year-old SMBv1 protocol when Exchange 2013/2016/2019 is installed on your system. SMBv1 is insecure and you lose the essential protections offered by later versions of the SMB protocol. If you want to learn more about SMBv1 and why you should stop using it, I would recommend reading this blog post published and updated by Ned Pyle,” Microsoft continues.
“Microsoft publicly rejected the SMBv1 protocol in 2014 and thus we stopped installing it by default when using Windows Server 2016 1709 (RS3).
In 2017, the Shadow Brokers hacking group released a collection of NSA exploits and hacking tools targeting Microsoft's Windows operating system, some of which were developed to exploit the SMBv1 protocol and execute commands on vulnerable servers with administrator privileges.
Two of the most popular exploits implemented in many malware strains today are EternalBlue and EternalRomance. The list of malware including exploits is long and includes Emotet, TrickBot, WannaCry, Retefe, NotPetya , and Olympic Destroyer.
SMBv1 is no longer installed by default on Windows 10 version 1709 and Windows Server version 1709, while the latest versions of operating systems use SMBv3.

To check if SMBv1 is enabled on a Windows server, you can run the following PowerShell commands depending on the Windows Server version.
Windows Server 2008 R2: By default, SMBv1 is enabled on Windows Server 2008 R2. Therefore, if the following command does not return value SMB1 or value SMB1 1, then it is enabled. If it returns value SMB1 0, then it is disabled.
Get-Item HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters | ForEach-Object {Get-ItemProperty $_.pspath}
Windows Server 2012: If the command returns false, SMBv1 is not enabled.
Get-SmbServerConfiguration | Select EnableSMB1Protocol
Windows Server 2012 R2 or later: If the command returns false, SMBv1 is not enabled.
(Get-WindowsFeature FS-SMB1).Installed
Get-SmbServerConfiguration | Select EnableSMB1Protocol
If SMBv1 is enabled on the admin's server, it can be disabled using the above commands.
Windows Server 2008 R2:
Set-ItemProperty -Path “HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters” -Name SMB1 -Type DWORD -Value 0 –Force
Windows Server 2012:
Set-SmbServerConfiguration -EnableSMB1Protocol $false -force
Windows Server 2012 R2 or newer version:
Disable-WindowsOptionalFeature -Online -FeatureName smb1protocol
Set-SmbServerConfiguration -EnableSMB1Protocol $false
