Policy
Require Encryption
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows11, WindowsServer2022
This policy controls whether the SMB client will require encryption. If you enable this policy setting, the SMB client will require the SMB server to support encryption and encrypt the data. If you disable or do not configure this policy setting, the SMB client will not require encryption. However, SMB encryption may still be required; see notes below. Note: This policy is combined with per-share, per-server, and per mapped drive connection properties, through which SMB encryption may be required. The SMB server must support and enable SMB encryption. For example, should this policy be disabled (or not configured), the SMB client may still perform encryption if an SMB server share has required encryption. Important: SMB encryption requires SMB 3.0 or later
Registry values
How enabled and disabled states update the registry.
| Registry location | Type | Enabled value | Disabled value |
|---|---|---|---|
| HKLM\Software\Policies\Microsoft\Windows\LanmanWorkstation\RequireEncryption | REG_DWORD | 1 | 0 |
Policy elements
Inputs and configuration options exposed by this policy.
This policy has no additional user input fields.
Other policies in this category
Explore related policies at the same level.
- ComputerAlternative Port MappingsAt least Windows Server 2025, Windows 11
- ComputerAudit insecure guest logonAt least Windows Server 2025, Windows 11
- ComputerAudit server does not support encryptionAt least Windows Server 2025, Windows 11
- ComputerAudit server does not support signingAt least Windows Server 2025, Windows 11
- ComputerBlock NTLM (LM, NTLM, NTLMv2)At least Windows Server 2025, Windows 11
- ComputerBlock NTLM Server Exception ListAt least Windows Server 2025, Windows 11
- ComputerCipher suite orderAt least Windows Server 2016, Windows 10
- ComputerDisable SMB compressionAt least Windows Server 2022, Windows 11
- ComputerDisabled SMB over QUIC Server Exception ListAt least Windows Server 2025, Windows 11
- ComputerEnable Alternative PortsAt least Windows Server 2025, Windows 11
- ComputerEnable insecure guest logonsAt least Windows Server 2016, Windows 10
- ComputerEnable remote mailslotsAt least Windows Server 2025, Windows 11