# Set SMB dialect ranges separately for client and server roles

> Which SMB client and server dialect ranges should an approved connection negotiate?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-137-set-smb-dialect-ranges-separately-for-client-and-server-roles/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:54+00:00
- Modified: 2026-09-08T18:23:27+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which SMB client and server dialect ranges should an approved connection negotiate?

## Potentially affected

Administrators managing SMB dialect restrictions on supported Windows releases.

## DSE recommendation

Write the intended client range and server range separately.

## Article

## Source facts

Microsoft documents separate minimum and maximum SMB dialect settings for client and server roles, configured through Group Policy or PowerShell. The documented prerequisites include Windows Server 2025 or Windows 11 version 24H2 or later, with the appropriate administrative permissions. Microsoft also describes examining a network capture to see the dialects requested and negotiated by the endpoints. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/storage/file-server/manage-smb-dialects).

## Applicability

Inventory the actual client and server releases and the devices that must connect. Review the peer capabilities and every required application path before proposing a narrower negotiation range.

## DSE recommendation

Write the intended client range and server range separately. Ask the file-service owner to identify peers that might fall outside either range, including appliances and occasional maintenance clients. Preserve the current settings and define an explicit rejection test for an unsupported peer.

## Verification

Reconnect representative clients under controlled conditions and record the negotiated dialect at both ends. Test the excluded case and confirm the result matches the approved policy. Keep failed connections visible as compatibility findings and resolve unexpected exclusions before applying the restriction to a wider server group.

## Official references

[Microsoft Learn: Manage SMB dialects in Windows and Windows Server 2025](https://learn.microsoft.com/en-us/windows-server/storage/file-server/manage-smb-dialects). Source reviewed September 8, 2026.

## Primary reference

- Name: Manage SMB dialects in Windows and Windows Server 2025
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/storage/file-server/manage-smb-dialects
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Set SMB dialect ranges separately for client and server roles,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-137-set-smb-dialect-ranges-separately-for-client-and-server-roles/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
