Windows 11 will allow administrators to require SMB encryption for all outbound connections, starting with Windows 11 Insider Preview Build 25982 available to Insider users in the Canary Channel.
See also: Windows 11 KB5031354: Released with new features

SMB encryption provides end-to-end data encryption and can be enabled for each share individually for the entire file server or when mapping drives, using Windows Admin Center, Windows PowerShell , or UNC Hardening.
This feature was first introduced with SMB 3.0 in Windows 8 and Windows Server 2012, and introduced support for AES-256-GCM cipher suites with Windows 11 and Windows Server 2022.
By requiring that all destination servers support SMB 3.x and encryption, Windows administrators can ensure that clients can only establish a connection if these conditions are met to protect against eavesdropping and man-in-the-middle attacks.
“You can now configure the SMB client to always require encryption, regardless of the server, shared folder, UNC mount, or mapped drive,” said Ned Pyle, Principal Program Manager at Microsoft.
“This means that an administrator can globally force a Windows computer to use SMB encryption – and therefore SMB 3.x – on all connections and refuse to connect if the SMB server does not support either.“
The new option can be configured using PowerShell or Group Policy to “Require encryption” under Computer Configuration\Administrative Templates\Network\Lanman Station.
See also: Windows 11 Insiders: Microsoft officially retires Cortana
Starting with Windows 11 Insider Preview Build 25951, administrators can configure Windows systems to automatically block sending NTLM data over SMB on remote outbound connections to prevent pass-the-hash, NTLM relay , or password cracking.

When enabled, it prevents the user's hashed password from being sent to remote servers, effectively preventing these attacks.
With the release of Windows 11 Insider Preview Build 25381 in the Canary Channel, Microsoft also began requiring SMB signing by default for all connections to defend against NTLM relay attacks. SMB signing technology, introduced in Windows 98 and 2000, has been upgraded in Windows 11 and Windows Server 2022 to enhance protection and performance by significantly increasing the speed of data encryption.
These improvements are part of a broader effort to strengthen the security of Windows and Windows Server, as highlighted by previous announcements last year. In April 2022, Microsoft reached a milestone by revealing the final phase of disabling the ancient SMB1 file sharing protocol for Windows 11 Home Insiders. Building on this progress, the company also strengthened its resistance against brute-force by introducing an SMB authentication rate limiter, which reduces the impact of failed inbound NTLM authentication attempts.
See also: Godeal24 Software Big Sale: Windows 11 (tiny11) version 23H2 for only €11.69!
What are the benefits and challenges of SMB encryption in Windows 11?
SMB encryption in Windows 11 offers many benefits. One of the main ones is increasing the security of data exchanged between devices. Encryption prevents data from being intercepted and monitored by unwanted users or malware, providing a layer of protection against potential threats.
Additionally, SMB encryption improves data privacy by making it more difficult for unauthorized users to access it. This is especially important for businesses and organizations that handle sensitive data, such as personal or confidential customer information.
However, implementing SMB encryption can face some challenges. Encryption burdens system performance, as it requires additional computing resources for the data encryption and decryption process. This can lead to a slight decrease in data transfer speed.
Additionally, SMB encryption can create compatibility issues, especially when different versions of the SMB protocol are used on different devices. This may require additional customization and configuration to ensure the protocol works properly and data is encrypted effectively.
Source: bleepingcomputer
