How to Disable SMBv1 and Enforce Patch Compliance on Azure VMs
Retrospective: this article looks back at events from May 2017, written in 2026 with the benefit of hindsight.
SMBv1 is a decades-old file-sharing protocol with known critical flaws, and it was the doorway for WannaCry and NotPetya. Here is how to remove it from Azure virtual machines and keep patching under control.
Step 1: Find where SMBv1 is enabled
On Windows Server, check with PowerShell:
Get-WindowsFeature FS-SMB1
Get-SmbServerConfiguration | Select EnableSMB1Protocol
At scale, use Azure Policy guest configuration or Microsoft Defender for Cloud recommendations to report on machines with insecure protocols.
Step 2: Check for dependencies
Very old devices — multifunction printers, legacy NAS appliances, old applications — may still need SMBv1. Enable SMB1 auditing for a few weeks to see whether any clients use it before you remove it.
Step 3: Disable and remove
Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force
Uninstall-WindowsFeature -Name FS-SMB1
Modern Windows versions ship with SMBv1 removed or disabled by default, but images built years ago and upgraded in place may still have it.
Step 4: Enforce patch compliance
- Use Azure Update Manager to assess and schedule updates across Azure VMs and Arc-enabled servers.
- Define maintenance windows and track compliance in a dashboard.
- Set a target: critical security updates within 14 days, sooner for exploited vulnerabilities.
Step 5: Lock down the network
- Block TCP 445 from the internet with network security groups.
- Restrict SMB between subnets to the servers that actually need it.
Verify
Rerun the assessment monthly. Any server that reappears with SMBv1 enabled means an image or build process needs fixing.
- WannaCry (May 2017): SMBv1, Unpatched Servers and What Cloud Teams Missed Incident Teardowns
- Detecting SMBv1 Exploitation: Defender for Cloud and Sentinel KQL Detection & Response
- CIO Brief: Why Patch Management Is a Board-Level Issue After WannaCry CIO Briefings