Removes the SMBv1 attack surface that WannaCry used, in both places it lives: the SMB server configuration and the optional Windows feature that carries the client and server components. The setting is read back for verification, and the run ends with the reminder that matters — check for legacy NAS boxes, printers and scanners before rolling this out widely.
powershell
# Disable SMBv1 Protocol
# Single use case: remove the legacy SMBv1 attack surface (WannaCry vector)
#-----------------------------------------------------------------
function Write-Log {
param($Message)
Write-Host "<WRITE-LOG = `"*$Message*`">"
}
$server = Get-SmbServerConfiguration -ErrorAction SilentlyContinue
if ($null -eq $server) { Write-Log "Could not read SMB server configuration!"; return }
if (-not $server.EnableSMB1Protocol) {
Write-Log "SMBv1 server protocol is already disabled."
} else {
Set-SmbServerConfiguration -EnableSMB1Protocol $false -Confirm:$false
Write-Log "SMBv1 server protocol DISABLED."
}
# Remove the optional feature as well (server + client components)
$feature = Get-WindowsOptionalFeature -Online -FeatureName SMB1Protocol -ErrorAction SilentlyContinue
if ($feature -and $feature.State -eq "Enabled") {
Write-Log "Removing SMB1Protocol optional feature..."
Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol -NoRestart -ErrorAction SilentlyContinue | Out-Null
Write-Log "SMB1Protocol feature disabled (a reboot completes the removal)."
} elseif ($feature) {
Write-Log "SMB1Protocol optional feature already $($feature.State)."
}
$server = Get-SmbServerConfiguration
Write-Log "Verification - EnableSMB1Protocol: $($server.EnableSMB1Protocol)"
Write-Log "SMBv1 hardening complete. Note: verify no legacy devices (old NAS/printers/scanners) still need SMBv1."Run it across your fleet
This script runs as-is on a single host. Paste it into ServerEngine to schedule it, run it on a whole server group in parallel, and keep the credentials out of the file — see the scripts documentation and the credential store.
More in Security & Auditing
Enable the Windows Firewall with PowerShell
2026-08-17Check Windows Firewall Status with PowerShell
2026-08-17Enforce TLS 1.2 in the Registry with PowerShell
2026-08-17Enable RDP Network Level Authentication with PowerShell
2026-08-17Audit the Local Administrators Group with PowerShell
2026-08-17Audit Failed Logons (Event 4625) with PowerShell
2026-08-17Ready when you are.
Try ServerEngine free for 7 days.