Policy
Cipher suite order
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows10, Windows10RT, Windows11, WindowsServer2016
This policy setting determines the cipher suites used by the SMB client. If you enable this policy setting, cipher suites are prioritized in the order specified. If you enable this policy setting and do not specify at least one supported cipher suite, or if you disable or do not configure this policy setting, the default cipher suite order is used. SMB 3.11 cipher suites: AES_128_GCM AES_128_CCM AES_256_GCM AES_256_CCM SMB 3.0 and 3.02 cipher suites: AES_128_CCM How to modify this setting: Arrange the desired cipher suites in the edit box, one cipher suite per line, in order from most to least preferred, with the most preferred cipher suite at the top. Remove any cipher suites you don't want to use. Note: When configuring this security setting, changes will not take effect until you restart Windows.
Registry values
How enabled and disabled states update the registry.
No explicit registry values are set for enabled or disabled states.
Policy elements
Inputs and configuration options exposed by this policy.
| Element | Type | Registry mapping | Constraints & behavior |
|---|---|---|---|
MultiText_CipherSuiteOrder ID MultiText_CipherSuiteOrder | list | HKLM\Software\Policies\Microsoft\Windows\LanmanWorkstation\CipherSuiteOrder Type REG_MULTI_SZ | None |
Other policies in this category
Explore related policies at the same level.
- ComputerAlternative Port MappingsAt least Windows Server 2025, Windows 11
- ComputerAudit insecure guest logonAt least Windows Server 2025, Windows 11
- ComputerAudit server does not support encryptionAt least Windows Server 2025, Windows 11
- ComputerAudit server does not support signingAt least Windows Server 2025, Windows 11
- ComputerBlock NTLM (LM, NTLM, NTLMv2)At least Windows Server 2025, Windows 11
- ComputerBlock NTLM Server Exception ListAt least Windows Server 2025, Windows 11
- ComputerDisable SMB compressionAt least Windows Server 2022, Windows 11
- ComputerDisabled SMB over QUIC Server Exception ListAt least Windows Server 2025, Windows 11
- ComputerEnable Alternative PortsAt least Windows Server 2025, Windows 11
- ComputerEnable insecure guest logonsAt least Windows Server 2016, Windows 10
- ComputerEnable remote mailslotsAt least Windows Server 2025, Windows 11
- ComputerEnable SMB over QUICAt least Windows Server 2025, Windows 11