AzureHow-To & HardeningRetrospectives

How to Disable SMBv1 and Enforce Patch Compliance on Azure VMs

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from May 2017, written in 2026 with the benefit of hindsight.

SMBv1 is a decades-old file-sharing protocol with known critical flaws, and it was the doorway for WannaCry and NotPetya. Here is how to remove it from Azure virtual machines and keep patching under control.

Step 1: Find where SMBv1 is enabled

On Windows Server, check with PowerShell:

Get-WindowsFeature FS-SMB1
Get-SmbServerConfiguration | Select EnableSMB1Protocol

At scale, use Azure Policy guest configuration or Microsoft Defender for Cloud recommendations to report on machines with insecure protocols.

Step 2: Check for dependencies

Very old devices — multifunction printers, legacy NAS appliances, old applications — may still need SMBv1. Enable SMB1 auditing for a few weeks to see whether any clients use it before you remove it.

Step 3: Disable and remove

Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force
Uninstall-WindowsFeature -Name FS-SMB1

Modern Windows versions ship with SMBv1 removed or disabled by default, but images built years ago and upgraded in place may still have it.

Step 4: Enforce patch compliance

  • Use Azure Update Manager to assess and schedule updates across Azure VMs and Arc-enabled servers.
  • Define maintenance windows and track compliance in a dashboard.
  • Set a target: critical security updates within 14 days, sooner for exploited vulnerabilities.

Step 5: Lock down the network

  • Block TCP 445 from the internet with network security groups.
  • Restrict SMB between subnets to the servers that actually need it.

Verify

Rerun the assessment monthly. Any server that reappears with SMBv1 enabled means an image or build process needs fixing.

disable smbv1 azureWannaCry2017

More on this story