Windows Security Baseline & Protocol Hardening
Legacy protocols and fallback name-resolution services can increase exposure, but their state varies by Windows release and organization policy. Clean installations of current Windows 11 and Windows Server 2019 or later do not include SMBv1 by default. Inventory the effective settings and check application dependencies before disabling LLMNR or NetBIOS across a fleet.
Step 1: Disable Insecure Legacy SMBv1
Disable SMBv1 Protocol & Deprecated Driver
File SharingCheck whether the SMBv1 optional feature and SMB server component are present and enabled. Disable only an enabled feature; the optional-feature change may require a restart. Test legacy file-sharing dependencies before removing it.
# Check the SMB server component and optional-feature state firstGet-SmbServerConfiguration | Select-Object EnableSMB1Protocol$Smb1Feature = Get-WindowsOptionalFeature -Online -FeatureName 'SMB1Protocol'$Smb1Feature | Select-Object FeatureName, State
# Disable SMB1 on the server component only if it is enabledif ((Get-SmbServerConfiguration).EnableSMB1Protocol) { Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force}
# Remove the optional feature only if it is enabled; schedule any required restartif ($Smb1Feature.State -eq 'Enabled') { Disable-WindowsOptionalFeature -Online -FeatureName 'SMB1Protocol' -NoRestart} else { Write-Host 'The SMB1 optional feature is not enabled.'}⯠View Expected Console Output
Review the returned State and RestartNeeded values. If RestartNeeded is True, restart during the approved maintenance window before considering the change complete.

Figure 1: Windows Features with SMB 1.0/CIFS File Sharing Support disabled.
Step 2: Disable LLMNR (Link-Local Multicast Name Resolution)
Block LLMNR via Local Group Policy Registry
Name ResolutionWhen DNS resolution fails, Windows may use LLMNR multicast queries over UDP 5355. Disable this policy only after checking legacy name-resolution dependencies. A domain Group Policy can override a local registry setting.
# Create DNSClient policy key if missing and disable LLMNR$regPath = "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient"if (-not (Test-Path $regPath)) { New-Item -Path $regPath -Force | Out-Null}
Set-ItemProperty -Path $regPath -Name "EnableMulticast" -Value 0 -Type DWord⯠View Expected Console Output
(EnableMulticast policy value set to 0. Verify the effective policy and client behavior; a domain policy may overwrite the local value.)

Figure 2: Local Group Policy Editor with the DNS Client policy to turn off multicast name resolution enabled.
Step 3: Disable NetBIOS over TCP/IP (NBT-NS)
Deactivate NetBIOS on All Active Network Adapters
Network ProtocolSimilar to LLMNR, NetBIOS Name Service (NBT-NS) uses UDP 137. Review the active adapters and dependencies before disabling it on physical or virtual interfaces:
# Set NetBIOS options to 2 (Disabled) on active IPv4 interfaces.# Review every listed adapter and confirm legacy applications do not depend on NetBIOS.$adapters = @(Get-CimInstance -ClassName Win32_NetworkAdapterConfiguration | Where-Object { $_.IPEnabled -eq $true })$adapters | Select-Object Description, TcpipNetbiosOptions | Format-Table -AutoSizeif ($adapters.Count -eq 0) { throw 'No active IPv4 adapters were found.'}if ((Read-Host 'Type DISABLE only after reviewing every active adapter') -cne 'DISABLE') { throw 'NetBIOS changes cancelled.'}
foreach ($adapter in $adapters) { Invoke-CimMethod -InputObject $adapter -MethodName SetTcpipNetbios -Arguments @{ TcpipNetbiosOptions = 2 } | Select-Object @{Name='Adapter'; Expression={$adapter.Description}}, ReturnValue}
# Confirm the configured value: 2 means NetBIOS is disabled.Get-CimInstance -ClassName Win32_NetworkAdapterConfiguration | Where-Object { $_.IPEnabled -eq $true } | Select-Object Description, TcpipNetbiosOptions⯠View Expected Console Output
Adapter ReturnValue
Intel(R) Ethernet Controller I225-V 0 vEthernet (WSL) 0
Description TcpipNetbiosOptions
Intel(R) Ethernet Controller I225-V 2 vEthernet (WSL) 2
Step 4: Set a Script Policy and Enable Script Block Logging
Harden PowerShell Engine & Enable Audit Trails
PowerShellSet the local machine execution policy to RemoteSigned and enable Script Block Logging (Event ID 4104). Group Policy can override the local execution policy. Script Block Logging is useful for investigation, but event records can contain sensitive command content; configure access and retention accordingly.
# 1. Set the local machine execution policySet-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope LocalMachine -Force
# 2. Enable PowerShell Script Block Logging in Group Policy registry$psLogPath = "HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging"if (-not (Test-Path $psLogPath)) { New-Item -Path $psLogPath -Force | Out-Null}
Set-ItemProperty -Path $psLogPath -Name "EnableScriptBlockLogging" -Value 1 -Type DWord⯠View Expected Console Output
(Local execution policy set to RemoteSigned. Script Block Logging enabled).

Figure 3: Local Group Policy Editor with PowerShell Script Block Logging enabled.