NAS Users: Windows 11 24H2 Security Rules Update

NAS users may face access issues due to new security rules in Windows 11 24H2. Stay informed and prepared.
NAS Users: Windows 11 24H2 Security Rules Update

Table of Contents

Digital enthusiasts know that Microsoft has now released the Windows 11 24H2 preview version, and the official Windows 11 24H2 version will be coming soon. This is a very important version update, and many people are paying close attention to it.

Of course, the most noteworthy aspect of Windows 11 24H2 is the new AI features and improvements, with reports stating that Microsoft will deeply integrate Copilot. However, AI is not the topic of this article. This article aims to introduce readers to two new security rule changes in the Windows 11 24H2 version, which may affect some NAS users.

Accessing a 3-party NAS with SMB in Windows 11 24H2 may fail
⬆️ Accessing a 3-party NAS with SMB in Windows 11 24H2 may fail (Image Credit: Microsoft)

Specifically, in the Windows 11 24H2 version, Microsoft will change two important network access rules:

  1. By default, all connections will require SMB signing. This rule can enhance security by preventing network tampering and blocking relay attacks that send credentials to malicious servers.
  2. Microsoft will disable insecure guest logins in Windows 11 24H2 Professional (and later versions). This rule enhances user security when connecting to untrusted devices.

Previously, guest accounts allowed users to connect to SMB servers without entering a username or password, which was convenient but posed significant security risks. It could lead to users’ devices being tricked by attackers into connecting to malicious servers, stealing or maliciously encrypting user data for ransom.

NAS
⬆️ NAS (Image Credit: Internet)

Adjusting these two security rules can significantly improve security, but every advantage has its downside, and this could also lead to some negative consequences. Some NAS devices are designed based on previous security rules, and when users update to Windows 11 24H2, the new security rules might cause errors and make these NAS devices unusable.

If a user’s NAS device does not support SMB signing, they might encounter various error prompts, including but not limited to:

0x00a000, -1073700864, Invalid Signature (STATUS_INVALID_SIGNATURE), Encrypted Signature Invalid (STATUS_INVALID_SIGNATURE), etc.

Cybersecurity cover
⬆️ Cybersecurity cover (Image Credit: Internet)

If a user’s NAS device requires support for insecure guest logins, they might receive error messages such as:

“You cannot access this shared folder because your organization’s security policies block unauthenticated guest access. These policies help protect your PC from unsafe or malicious devices on the network,” 0x80070035, 0x800704f8, “The network path was not found,” “System error 3227320323 has occurred,” etc.

Microsoft network client
⬆️ Microsoft network client

If users encounter the above problems after updating to Windows 11 24H2, they can temporarily resolve them through the following two methods:

  1. Disable the SMB client signing requirement

In the “Start” menu search, enter gpedit and launch the “Edit Group Policy” application (Local Group Policy Editor), select “Computer Configuration” > “Windows Settings” > “Security Settings” > “Local Policies” > “Security Options,” double-click “Microsoft Network Client: Digitally sign communications (always),” finally select “Disabled” > “OK.”

  1. Enable insecure guest logins

In the “Start” menu search, enter gpedit and launch the “Edit Group Policy” application (Local Group Policy Editor), select “Computer Configuration” > “Administrative Templates” > “Network” > “Lanman Workstation,” double-click “Enable insecure guest logons,” finally select “Enabled” > “OK.”

It needs to be emphasized that these two solutions are only temporary measures and carry significant security risks. Microsoft will urge NAS device manufacturers to update their product’s firmware and software to comply with Windows 11 24H2’s new network security rules.

Therefore, NAS device users should closely monitor official announcements from Microsoft and NAS device manufacturers shortly, and promptly update the relevant firmware and software. This is the most reliable and secure approach.

Related:

  1. NAS in 2024: Essential or Optional?
  2. NAS Getting Started Guide (I): What is NAS?
End-of-DiskMFR-blog

Disclaimer: This article is created by the original author. The content of the article represents their personal opinions. Our reposting is for sharing and discussion purposes only and does not imply our endorsement or agreement. If you have any objections, please get in touch with us through the provided channels.

DiskMFR Field Sales Manager - Leo

It’s Leo Zhi. He was born on August 1987. Major in Electronic Engineering & Business English, He is an Enthusiastic professional, a responsible person, and computer hardware & software literate. Proficient in NAND flash products for more than 10 years, critical thinking skills, outstanding leadership, excellent Teamwork, and interpersonal skills.  Understanding customer technical queries and issues, providing initial analysis and solutions. If you have any queries, Please feel free to let me know, Thanks

Please let us know what you require, and you will get our reply within 24 hours.









    Our team will answer your inquiries within 24 hours.
    Your information will be kept strictly confidential.

    • Our team will answer your inquiries within 24 hours.
    • Your information will be kept strictly confidential.

    Let's Have A Chat

    Learn How We Served 100+ Global Device Brands with our Products & Get Free Sample!!!

    Email Popup Background 2