How-to guides · The SMB signing default change described in Microsoft's What's new in Windows 11, version 24H2, and the mechanism and non-Microsoft file server wording in Overview of SMB signing (read 2026-09-21)

NAS shares stopped opening after 24H2: SMB signing is now required by default

A NAS or a shared folder that worked for years stops opening right after Windows moves to 24H2, with no change to settings or cabling. One explanation that fits is that a Windows default changed. Microsoft states that in Windows 11 version 24H2, on the Home, Pro, Education and Enterprise editions, SMB signing is required by default for all connections. A second document states that with non-Microsoft file servers this can prevent connections from taking effect. This guide was written on 2026-09-21 from those two documents and sets out what changed and what to check. Nothing here was reproduced on a test machine.

Published · Updated · FaultNote editorial policy

NAS shares stopped opening after 24H2: SMB signing is now required by default overview: 1. The default changed in 24H2, 2. What Microsoft says about non-Microsoft file servers, 3. The order to check things in, 4. About disabling the requirement, 5. What this guide does not say
An overview of this guide’s steps and checks, not a screenshot of the app.

Who this guide is for and what to prepare

  • Anyone whose NAS or shared folder stopped opening right after updating to 24H2
  • Anyone looking for why equipment that always worked has stopped, with no setting changed
  • Anyone weighing whether the NAS needs replacing

What you need

  • Check your Windows version (winver, or Settings, System, About)
  • Note whether the unreachable device is a Microsoft server or something else: a NAS, a router's USB share, an older PC
  • Be ready to look up what that device's manufacturer says about SMB signing

1. The default changed in 24H2

Microsoft's What's new in Windows 11, version 24H2 has an entry for this. SMB signing requirement changes : In Windows 11, version 24H2 on the Home, Pro, Education, and Enterprise editions, SMB signing is now required by default for all connections.

Note that the editions are not narrowed to the business ones. Home is in the list.

The same entry explains what SMB signing does. SMB signing ensures every message contains a signature generated using session key and cipher suite. The client puts a hash of the entire message into the signature field of the SMB header. If anyone changes the message itself later on the wire, the hash won't match and SMB knows that someone tampered with the data. It also confirms to sender and receiver that they are who they say they are, breaking relay attacks.

So it establishes that the traffic was not altered in transit and that each side is who it claims to be. Read that before any conversation about turning it off: it is a description of what turning it off gives up.

2. What Microsoft says about non-Microsoft file servers

The sentence closest to this symptom is on the SMB signing overview page. If your environment uses non-Microsoft file servers, your system settings can prevent the default settings and connections from taking effect. In this case, you might need to disable the requirement for SMB signing.

In an environment with non-Microsoft file servers, the system settings can stop the defaults and the connections taking effect, and in that case disabling the SMB signing requirement might be necessary.

Most home and small-office NAS devices are not Microsoft servers, so that sentence is within range of the situation. Microsoft's wording is might need to, and this guide does not go further than the source does.

The same page also states that SMB signing is available in all editions of Windows, that the requirement can apply to outbound traffic from the SMB client and to inbound traffic to the server, and that Windows and Windows Server can be configured to require it on one side, both sides or neither. Available and required are not the same thing.

3. The order to check things in

When a share stops opening, do not start by loosening a security setting. Establish first whether this is even the right explanation.

The first row can end the enquiry. If the version is earlier than 24H2, this default change does not apply and another cause will be found faster.

Scroll horizontally to see the full table →

3. The order to check things in
OrderWhat to look atWhat it tells you
1. The Windows versionWhat winver reportsEarlier than 24H2 means this default change does not apply
2. What kind of device it isNAS, router USB share, older PC, or a Microsoft serverDecides whether the non-Microsoft file server wording is in range
3. Whether the timing matchesDid it stop right after the 24H2 updateIf not, another cause becomes more likely
4. The device's own supportThe NAS maker's firmware updates and any statement about SMB signingA firmware update may resolve it. Look here first
5. If it still is not resolvedMicrosoft's Control SMB signing behavior guidanceThis guide publishes no steps. Read the next section

4. About disabling the requirement

Microsoft points somewhere for this: See Control SMB signing behavior for guidance on how to disable SMB signing. The same overview page also names the policy location (Computer Configuration, Windows Settings, Security Settings, Local Policies, Security Options) and the corresponding registry values.

This site publishes no steps for that change, and the reason is the description quoted in the first section. SMB signing is stated to detect tampering in transit, to confirm that sender and receiver are who they say they are, and to break relay attacks. Disabling it stops those checks.

What can be said as decision material is this. If a firmware update on the device resolves it, that route gives up nothing. If an older device cannot be brought forward, then keeping it or replacing it is a separate decision, and this site does not make it for you.

24H2 carries other SMB changes as well. The same page records that encryption can now be required for all outbound SMB client connections, and that auditing of SMB signing and encryption support can now be enabled, which is described as revealing third-party clients or servers that do not support them.

5. What this guide does not say

It does not say whether a particular NAS works with 24H2. No device was tested here and manufacturer support is not tracked. Check what your own model's maker publishes.

It does not say that this default change is behind every share that will not open. Credentials, network discovery and mapped-drive reconnection are covered in this site's troubleshooting records. If the timing does not match the update, start there instead.

It publishes no procedure for disabling the requirement. Pointing at Microsoft's guidance is where this guide stops.

0

Limitations and requirements

  • Nothing here was reproduced on a test machine. The change and the wording quoted are Microsoft's published documents.
  • No steps for disabling SMB signing are published here. By Microsoft's own description, disabling it stops tamper detection and the confirmation of who the other side is.
  • Check the device's firmware first. If that resolves it, no Windows security setting has to change.
  • Everything quoted here was read on 2026-09-21.

Frequently asked questions

The NAS stopped working right after 24H2. Is that related?

It can be. Microsoft states that in Windows 11 version 24H2 on the Home, Pro, Education and Enterprise editions, SMB signing is required by default for all connections. It is not the only reason a share stops opening, though.

Does this affect the Home edition?

Home is named. The entry lists the Home, Pro, Education and Enterprise editions.

What exactly is the problem with a non-Microsoft NAS?

The SMB signing overview states that in an environment using non-Microsoft file servers, your system settings can prevent the default settings and connections from taking effect, and that in this case you might need to disable the requirement for SMB signing.

Will disabling SMB signing fix it?

This guide publishes no steps and does not claim a fix. By Microsoft's description, disabling it stops tamper detection and the confirmation of the other side's identity. Check the device's firmware updates first.

Is there a way to find out which devices do not support it?

24H2 lists auditing of SMB signing and encryption support as a new capability, described as revealing third-party clients or servers that do not support them. The page states the auditing settings can be modified in Group Policy or through PowerShell.

Sources and verification date

Sources checked: . These sources support the specifications, procedures or prices discussed here. Check each source for applicable conditions and current information.

Related practical guides

How-to guides: browse all guides →