Create a GPO That Enables SMB Signing
First, let’s analyze which machines on the network have SMB Signing disabled:
└─# crackmapexec smb --gen-relay-list smb_targets.txt 172.16.0.0/255.255.255.240

We can see that the host PC01 is joined to the domain and has signing disabled. So now let’s create our GPO.
Open Group Policy Management:
- On the domain server, open “Group Policy Management” (Group Policy Management Console, or GPMC).
- You can access GPMC by clicking “Start” and searching for “gpmc.msc”.
Create a New GPO:
- In the console tree, expand your domain.
- Right-click the Organizational Unit (OU) or the domain where you want to apply the policy and select “Create a GPO in this domain, and Link it here…”.

- Give the new GPO a meaningful name, for example, “Enable SMB Signing”.

Edit the GPO:
- Right-click the newly created GPO and select “Edit”.
- This will open the Group Policy Management Editor.

Configure SMB Signing:
- In the Group Policy Management Editor, navigate to:
- Computer Configuration
- Policies
- Windows Settings
- Security Settings
- Local Policies
- Security Options
- Local Policies
- Security Settings
- Windows Settings
- Policies
- Computer Configuration

In the right-hand pane, locate the following settings and modify them as needed:
- Microsoft network client: Digitally sign communications (always):
- Enable this setting.

- Microsoft network server: Digitally sign communications (always):
- Enable this setting.

Apply and Update the GPO:
- After making the changes, close the Group Policy Management Editor.
- The new GPO will be applied automatically during the next policy refresh for AD computers and users. To apply it immediately, you can force an update by running the command
gpupdate /forcein a command prompt on the target computers.

Verify GPO Application:
- To ensure the policy was applied correctly, you can run the command
gpresult /rin a command prompt on the target computers to verify the applied group policies. - In addition, you can review the event logs in “Event Viewer” under “Applications and Services Logs -> Microsoft -> Windows -> GroupPolicy -> Operational” to confirm that the group policies were applied.
Finally, using Kali again, we can test the initial command:

Conclusion
With this GPO configured, all SMB communications between clients and servers in the domain will have digital signing enabled, increasing network security. Remember to test the policy in a lab or staging environment before applying it in production to ensure it does not cause service disruptions.
📚 Read also
💜 Enjoyed this content? Support the blog with USDT (TRC20):
TX7obcjHQbDUXb4mGqoASEu1QFTKT2CFGG
