Separate SMBv1 from all file sharing
SMB is used for Windows-style network file access. The old SMBv1 protocol should not be enabled simply because an outdated scanner or NAS needs it. Removing SMBv1 is different from disabling modern SMBv2 and SMBv3, which current file-sharing workflows may require.
Inspect the legacy optional feature
In elevated Windows PowerShell:
Get-WindowsOptionalFeature -Online -FeatureName SMB1ProtocolRead the feature state. On systems with subfeatures, inspect the matching family as well:
Get-WindowsOptionalFeature -Online |
Where-Object FeatureName -like 'SMB1Protocol*' |
Select-Object FeatureName, StateAn absent feature or different layout should be investigated against that Windows version's documentation rather than treated as a universal command failure.
Check the business dependency
List shared folders, older NAS devices and scan-to-folder workflows. Confirm the versions those devices support. Where a device requires SMBv1, plan a supported replacement or a secure alternative workflow. Do not expose SMB to the internet while solving a local compatibility problem.
Remove it when the dependency is resolved
After a backup and planned maintenance window, use the supported optional-feature process. For Windows versions exposing this feature:
Disable-WindowsOptionalFeature -Online -FeatureName SMB1ProtocolRead the result and complete any required restart. This command intentionally changes the system. Do not run it on a business device without assessing the workflows above.
Verify after restart
Repeat the feature query and confirm the expected disabled state. Test normal modern file shares and the scanner or application workflows that matter. A successful Windows sign-in does not verify network file-sharing compatibility.
Common mistakes
Re-enabling SMBv1 as a permanent quick fix leaves the original legacy dependency unresolved. Disabling every SMB protocol breaks legitimate services unnecessarily. A share working by IP but not by name may be a DNS or name-resolution issue rather than a protocol-version problem.
Record the exception honestly
If a legacy dependency prevents removal today, document the device, owner and remediation plan. Do not mark the baseline complete or describe segmentation as eliminating every risk. This is a free built-in configuration check; the cost of replacing unsupported hardware is a separate decision.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.