Skip to content
Securing SMB Communication with Intune using Digitally Sign Communications Policy

Securing SMB Communication with Intune using Digitally Sign Communications Policy

Written By Anoop C Nair
Last Updated July 14, 2026
Posted In Intune
SHARE

Today we are discussing the Securing SMB Communication with Intune Using Digitally Sign Communications Policy. This policy makes sure that file sharing on Windows computers is always protected. It forces the system to use a security check called digital signing whenever data is sent or received using SMB (file and printer sharing).

This means the computer will not accept or send data unless the connection is secure. SMB is commonly used in offices to share files, folders, and printers. Because this data travels through the network, it can be targeted by attackers if it is not protected.

Without this setting, someone on the same network could try to read or change the data while it is being transferred. By enabling this SMB policy, the computer checks every message it sends or receives. If the message is changed or comes from an untrusted source, the connection is stopped. This helps keep company data safe and prevents misuse.

In Intune, this policy is applied by creating a configuration profile and selecting the setting Microsoft network server: Digitally sign communications (always) from the Security Options. Once enabled and assigned, Intune automatically applies this protection to all selected devices.

Patch My PC

Securing SMB Communication with Intune Using Digitally Sign Communications Policy

After the policy is applied, Windows will only communicate with other computers that also support secure SMB signing. This blocks unsafe or outdated systems that do not follow modern security rules. The biggest benefit of this policy is protection from hacking attempts like session hijacking. It ensures that no one can secretly change data or pretend to be a trusted computer on the network.

Create Profile

To begin, open Microsoft Intune and sign in with your administrator credentials. Once logged in, navigate to the Devices section and select Configuration Profiles. In this section, click on the + Create Policy option to create a new configuration profile.

  • A new window titled Create a Profile will appear.
  • Here, you need to provide some basic details: for the Platform, select Windows 10 and later, and for the Profile Type, choose Settings Catalog.
  • After selecting these options, proceed to create the profile.
Securing SMB Communication with Intune using Digitally Sign Communications Policy- Fig.1
Securing SMSecuring SMB Communication with Intune using Digitally Sign Communications Policy- Fig.1

Importance of Basics

Now, we all know what the Basic tab means for us. If you don’t, it simply refers to the first step in the policy creation process, where you provide the basic details of your policy. In this section, you need to enter important information such as the Name and Description of the policy. You can give the policy any name that helps you easily identify it later in the future.

Basic DetailsInfo
NameEnable SMB Packet Signing
DescriptionMicrosoft Network Server Digitally Sign Communications If Client Agrees
PlatformWindows
Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Table.1
Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.2
Securing SMB Communication with Intune Using Digitally Sign Communications Policy Fig.2

Configuration Settings

Now you are on the Configuration settings page of the profile; here, click on + Add settings to open the Settings picker window, then browse by category and select Local Policies Security Options, find the setting Microsoft Network Server Digitally Sign Communications If Client Agrees, select the checkbox next to it, and close the Settings picker to add the policy to your configuration.

Securing SMB Communication using Intune with the Digitally Sign Communications If Client Agrees Policy- Fig.3
Securing SMB Communication using Intune with the Digitally Sign Communications If Client Agrees Policy- Fig.3

Disabled Policy Mode

After selecting the policy, you can now close the Settings Picker window. You will return to the Configuration Settings page, where you can see that the policy is currently set to Disabled by default. If you want to proceed without making any changes, simply click Next to continue.

Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.4
Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.4

Enable Policy

On the Configuration settings page, locate the policy Microsoft Network Server: Digitally Sign Communications If Client Agrees under Local Policies Security Options, turn the toggle to Enabled, and then click Next to continue with the profile setup.

Securing SMB Communication with Intune Using Digitally Sign Communications Policy Fig.5
Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.5

Scope Tags

The scope tag is not mandatory, so you can skip this section. It functions as a tool for organisation and access management, but assigning it is optional. Click Next if they’re not required for your setup.

Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.6
Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.6

Assignment Section

The Assignment section is very important for policy deployment. In this section, you decide who will receive the policy within the organization. If you want to target specific groups, users, or devices, you can add them here to ensure the policy is applied only to the intended audience.

Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.7
Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.7

Review + Create

Review + Create is the last stage of policy creation. In this step, you will see a summary of all the details, including Basics, Configuration Settings, Assignments, and more. You can review all the information, and if anything needs to be changed, you can go back to the previous steps and edit them easily.

Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.8
Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.8

Monitoring Details

After creating the policy, you might in a thought that whether it was successfully applied or not. It is very important to verify this. To check, you normally need to wait up to 8 hours for the policy to sync automatically. However, if you want faster results, you can manually sync the policy through the Company portal

  • Navigate to Devices > Configuration Policies.
  • In the Configuration Policies list, look for the policy you created.
  • Click on the policy to view its deployment status and details.
Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.9
Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.9

How to Remove Policy

After creating the policy, if you want to remove the group that you previously selected, you can easily do that. First, go to Devices > Configuration policies. In the Configuration policy section, search for the policy, In the policy section When you Scroll down the page, and you will see sections like Basic Details and Assignment Details.

  • In the Assignment section, you will find an Edit option and click on it.
  • When you click Edit, you will enter the Assignment page.
  • Click on Remove, then proceed by clicking Review + Save.
Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.10
Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.10

How to Delete the Policy that you created

To delete a policy in MS Intune, first sign in to the Microsoft Intune Admin Center. Navigate to Devices and then select Configuration. Locate and select the specific policy you want to remove. Once you’re on the policy details page, click the three -dot menu in the top right corner and choose Delete from the available options.

Securing SMB Communication with Intune Using Digitally Sign Communications Policy- Fig.11
Securing SMB Communication with Intune Using Digitally Sign Communications Policy.11

End User Results

After this configuration is applied, end users will not see any noticeable change in their day-to-day work. They can continue to sign in, access files, and use network resources as usual without interruption. The policy works silently in the background and does not affect normal, authenticated user activity.

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows,  Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read